Join our Talent Network >

Computer Network Defense/Incident Response (CND/IR) Analyst

This job posting is no longer active.

Job ID: 203135
Location: FORT MEADE, MD, United States
Date Posted: Mar 18, 2020
Category: Cyber
Subcategory: Cyber Sec Analyst
Schedule: Full-time
Shift: Day Job
Travel: Yes, 10 % of the Time
Minimum Clearance Required: TS/SCI with Poly
Clearance Level Must Be Able to Obtain: None
Potential for Teleworking: No

Share: mail

Job Description

Description

The Defense Systems Group of SAIC is seeking a Computer Network Defense / Incident Response Analyst with an active TS/SCI Polygraph to work onsite with our customer at Scott AFB.


The CND Analyst shall identify, collect, and analyze network and host data, and report events or incidents that occur or might occur within a network to mitigate immediate and potential network and host threats.


The individual shall perform computer network defense (CND) incident triage, to include:

  • Determining urgency, and potential impact;
  • Identifying the specific vulnerability; and making recommendations that enable expeditious remediation
  • Perform initial, forensically sound collection of images and inspect to determine mitigation/remediation on enterprise systems;
  • Perform real-time computer network defense (CND) incident handling (e. g., forensic collection, intrusion correlation/tracking, threat analysis, and direct system remediation) task to support Incident Response Teams, receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts, and track and document computer network defense (CND) incidents from initial detection through final resolution
  • Employ defense-in-depth principles and practices, collect intrusion artifacts (e.g., source code, malware, and Trojans) and use discovered data to enable mitigation of potential computer network defense (CND) incidents within the enterprise. 
  • Assist with analysis of actions taken by malicious actors to determine initial infection vectors, establish a timeline of activity and any data loss associated with incidents.
  • Provide expert technical support to enterprise-wide CND technicians to document CND incidents, correlate incident data to identify specific vulnerabilities and to make recommendations enabling remediation.  

          • Qualifications

            REQUIRED EDUCATION AND EXPERIENCE:

            • Minimum of ten (10) years of recent work experience in Computer Network Defense and Incident Response with a Bachelor’s degree in Computer Science/Cyber Security/Computer Information or Information Systems.  Additional years of experience may be considered in lieu of a degree.
            • IAT Level III certification (CISSP, GCED, CASP CE, CCNP Security, CISA, GCIH)
            • Experience using various incident response tools (e.g., Acunetix, Adobe, Cobalt Strike, FireEye, Fluke Networks Air Magnet, F-Response, Encase Guidance Software, IDA Pro, McAfee Advance Threat Defense, Network Miner Pro, Palo Alto, Burp Suite Professional, Metasploit Rapid 7, Red Seal, Splunk, VMWare, Domain Tools, Virus Tools, Microsoft Products, Operating Systems (e.g., Windows OS 2008 and 2012; Linux)
            • Experience with programming tools such as Python, PowerShell and also able to develop Scripts with Scripting languages/tools.
            • Experience monitoring external data sources (e.g., computer network defense vendor sites, Computer Emergence Response Teams, SANS, Security Focus), update the CND threat condition, and determine which security issues may have an impact on the enterprise. 
            • Experience analyzing log files, firewalls, firewall logs, and intrusion detection systems and IDS Logs to identify possible threats to network security, and to perform command and control functions in response to incidents.

            DESIRED EXPERIENCE:

            • Experience on a Cyber Protection Team, DoD/US CERT or other USG Red Team.

            • Experience with Big Data Platform, AI, and or Machine Learning.

            REQUIRED CLEARANCE:

            • Candidate must currently possess and be able to maintain TS/SCI with Polygraph

            Desired Qualifications

             


             



            Overview

            SAIC is a premier technology integrator solving our nation's most complex modernization and readiness challenges. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes high-end solutions in engineering, IT, and mission solutions. Using our expertise in existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions. We are 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. Headquartered in Reston, Virginia, SAIC has pro forma annual revenues of nearly $6.5 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom. For SAIC benefits information, see Working at SAIC. EOE AA M/F/Vet/Disability

            Share: mail

            Similar Jobs

            Senior Systems Security Engineer (VG01175 & VG01177)

            BELTSVILLE, MD, United States
            Cyber

            NASA Cyber Eng/Archt Team Mgr

            GREENBELT, MD, United States
            Cyber

            Offensive Cyber Operation Capability Developer

            FORT MEADE, MD, United States
            Cyber

            Cyber Intelligence Analyst

            FORT MEADE, MD, United States
            Cyber

            Offensive Cyberspace Operations (OCO) Planner

            FORT MEADE, MD, United States
            Cyber

            Computer Network Defense / Incident Response Analyst

            FORT MEADE, MD, United States
            Cyber

            Senior Cyber Security Analyst

            WASHINGTON, DC, United States
            Cyber

            Cyber Manager

            WASHINGTON, DC, United States
            Cyber

            Security Operations Manager/Program Manager

            WASHINGTON, DC, United States
            Cyber

            Security Quality (SQ) Team Lead

            WASHINGTON, DC, United States
            Cyber

            Security Incident Response (IR) Team Lead

            WASHINGTON, DC, United States
            Cyber

            Security Infrastructure (SI) Team Lead

            WASHINGTON, DC, United States
            Cyber

            Security Triage (ST) Team Lead

            WASHINGTON, DC, United States
            Cyber

            IT Auditor - Mid

            WASHINGTON, DC, United States
            Cyber

            Security Specialist

            WASHINGTON, DC, United States
            Cyber

            Cyberspace Joint Operations Planner II

            FORT MEADE, MD, United States
            Cyber

            Cyberspace Joint Operations Planner III

            FORT MEADE, MD, United States
            Cyber

            Security Engineer - Senior

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Senior

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Senior

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Senior

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Senior

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Mid

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Lead

            WASHINGTON, DC, United States
            Cyber

            Security Engineer - Lead

            WASHINGTON, DC, United States
            Cyber

            Provide your information to receive jobs that fit you by keywords, location, and more,
            and then receive great opportunities based on your skills and experience.

            Join our Talent Network >