Cyber Threat Detection Engineer with Security Clearance
ISYS Technologies - Ashburn, VA
Apply NowJob Description
Minimum Clearance Required Secret Responsibilities ISYS Technologies delivers emerging technology solutions through our diverse and talented employees who are dedicated to our customers'' success. We empower our teams, contribute to our country and operate responsibly. We are a reputable award-winning WOSB providing Engineering and Enterprise Information Technology (EIT) services to the Federal government. Headquartered in Colorado, ISYS serves key national customers throughout the United States with a presence in more than 16 states. * Identify gaps in malicious activity detection capabilities * Create new signatures / rules to improve detection of malicious activity * Test and tune existing signatures / rules to ensure low rate of false positives * Assist in playbook development for alert triage and Incident Response * Define and implement alert and threat detection metrics, statistics, and analytics * Recommend new tools/technologies to improve network visibility * Support Incident Response and Forensic operations as required to include static/dynamic malware analysis and reverse engineering * Author and maintain scripts for threat detection and automation Qualifications Must have one of the following J3 certifications ( Tier 2 Response): * * GCIH - Incident Handler * GCFA - Forensic Analyst * GCFE - Forensic Examiner * GREM - Reverse Engineering Malware * GISF - Security Fundamentals * GXPN - Exploit Researcher and Advanced Penetration Tester * GWEB - Web Application Defender * GNFA - Network Forensic Analyst * OSCP (Certified Professional) * OSCE (Certified Expert) * OSWP (Wireless Professional) * OSEE (Exploitation Expert) * CCFP - Certified Cyber Forensics Professional * CISSP - Certified Information Systems Security * CCNA Security * CCNP Security * CEH - Certified Ethical Hacker * CHFI - Computer Hacking Forensic Investigator * LPT - Licensed Penetration Tester * ECSA - EC-Council Certified Security Analyst * ENSA - EC-Council Network Security Administrator * ECIH - EC-Council Certified Incident Handler * ECSS - EC-Council Certified Security Specialist * ECES - EC-Council Certified Encryption Specialist * EnCE * Windows Forensic Examinations - FTK WFE-FTK * Computer Incident Responders Course - CIRC * Windows Forensic Examination - EnCase - Counter Intelligence (CI) - WFE-E-CI * Forensics and Intrusions in a Windows Environment -FIWE * In-depth knowledge of Firewalls/Proxies/Intrusion Detection Systems/ Domain Name Servers/DHCP/VPN and other network technologies and tools * Experience updating, maintaining, and creating IDS variables within a complex enterprise network * Expert in creating, modifying, tuning IDS signatures/SIEM Correlation Searches/yara rules and/or other detection signatures * Familiarity with disk based forensic methodologies, Windows, and Linux forensic artifacts * Experience with Endpoint Detection and Response (EDR) tools such as Carbon Black, Tanium, Crowdstrike, etc * Able to create, modify, update, and maintain Python and Powershell scripts that enhance endpoint detection capabilities * In-depth knowledge of attacker tactics, techniques, and procedures * Author, test, and maintain automation scripts within SOAR platform * BS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience. * Should have 5 years of experience serving as a digital media analyst or as a computer forensic analyst. * Ability to work independently with minimal direction; self-starter/self-motivated Desired Requirements: One of the following certifications: * * SANS Global Information Assurance Certification (GIAC) Certified Intrusion Analyst (GCIA) * SANS Global Information Assurance Certification (GIAC) Certified Forensic Analyst (GCFA) * SANS Global Information Assurance Certification (GIAC) Certified Network Forensic Analyst (GNFA) * Certified Information System Security Professional (CISSP) Essential Requirements: * US Citizenship is required * Secret with a current or be able to favorably pass a 5 year background investigation (BI) ISYS Technologies is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected Veteran status, or disability status. Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation. While performing the duties of this job, the employee will regularly sit, walk, stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally, movement that requires twisting at the neck and/or trunk more than the average person, squatting/ stooping/kneeling, reaching above the head, and forward motion will be required. The employee will continuously be required to repeat the same hand, arm, or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close, distance, depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress. ISYS Technologies is an Engineering and Information Technology Company focused on providing Services to the Federal and State Government. ISYS offers a competitive compensation program and comprehensive benefits package to our employees.
Created: 2025-09-06