Unknown Company

Cyber Security Analyst

mc lean, va • Posted 4 days ago
Onsite Full Time General

Cyber Security AnalystLocation: McLean, VA *Clearance: Active TS/SCI w/ Polygraph needed to apply * Company Overview: Cornerstone Defense is the Employer of Choice within the Intelligence, Defense, and Space communities of the U.S. Government. Realizing early on that our most prized assets are our employees, we continually focus our attention on improving the overall work/life experience they have supporting the mission.

Our Team is pushed every day to use their industry leading knowledge to provide end-to-end solutions to combat our nation's toughest and most secure problems. If you are looking for a place to not only be professionally challenged, but encouraged and supported by a company that cares, don't look any further than Cornerstone Defense.Responsibilities include, but are not limited to:Provide strategic and tactical direction to cyber hunters and leadership based on trends and actionable intelligence related to threat capabilitiesCoordinate hunt activities between various internal and external hunt groupsConstruct and exploit threat intelligence to detect, respond, and defeat advanced persistent threats (APTs)Fully analyze network and host activity in successful and unsuccessful intrusions by advanced attackersBuild fly-away kits utilizing an agile approach to identify the appropriate tools and technologies necessary to conduct hunt missionsConduct advanced threat hunt operations using known adversary tactics, techniques and procedures as well as indicators of attack in order to detect adversaries with persistent access to the enterpriseCreate and add custom signatures, to mitigate highly dynamic threats to the enterprise using the latest threat information obtained from multiple sourcesPerform malware analysis on samples obtained during an investigation or hunt operation to create custom signaturesDevelop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issuesPiece together intrusion campaigns, threat actors, and nation-state organizationsManage, share, and receive intelligence on APT adversary groupsGenerate intelligence from their own data sources and share it accordinglyIdentify, extract, and leverage intelligence from APT intrusionsExpand upon existing intelligence to build profiles of adversary groupsLeverage intelligence to better defend against and respond to future intrusionsCorrelate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logsNotify the management team of significant changes in the security threat against the government networks in a timely manner and in writing via established reporting methodsCoordinate with appropriate organizations within the intelligence community regarding possible security incidentsConduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contactReview assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given eventMaintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessaryRequired Qualifications: 2+ years of experience in Computer Science, Cyber Security, Security Engineering or Network Engineering, including cyber security issues and operations, computer incident response, systems architecture, data management Experience with working nation state intrusion sets Experience with and expert level proficiency in one or more of the following disciplines: Windows and/or Linux operating systems Network forensics Expertise at enterprise scale: SysMon or EDR solutions for host-based Cyber Threat Hunting, or Netflow/pcap or NDR solutions for network-oriented Cyber Threat Hunting Malware analysis/reverse engineering Exploit development On-net pursuit/response Incident response, forensics, or threat hunting in AWS or Azure Knowledge of the following classes of enterprise cyber defense technologies: Security Information and Event Management (SIEM) systems Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS) Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS) Network and Host malware detection and prevention (NDR/EDR) Network and Host forensic applications Web/Email gateway security technologies Security Orchestration, Automation, and Response (SOAR) Ability to demonstrate effective interpersonal, organizational, writing, communications, and briefing skills Ability to use advanced level analytical and problem-solving skills to solve complex issues Ability to obtain a CISSP or CEH Certification within 6 months of start date DoD 8570 IAT Level III or CSSP-SPM within 6 months of start date Active/Current TS/SCI with polygraph clearancePreferred Qualifications: Bachelor's Degree in Electrical Engineering, Computer Engineering, Computer Science, or other closely related Information Technology field of studyShifts for this role are: Sunday – Wednesday – 6am – 4pm, noon – 10pm and 9pm – 7am Wednesday – Saturday – same as above

Back to Job Search