Cyber Network Defense Analysts (CNDA)
MSCCN - Arlington, VA
Apply NowJob Description
The Computer Network Defense Analyst uses information collected from a variety of sources to monitor network activity and analyze it for evidence of suspicious behavior. Monitoring and analysis are performed to identify and report events that occur, or might occur, within the network, in order to protect information, information systems, and networks from threats. CNDAs review data collected to analyze cyber events, and the network environment, to find trends, patterns or anomaly correlations that indicate more serious attacks or future threats. The CNDAs will recommend proactive measures to contain the incident. These proactive measurers include, but are not limited to, identification of intruder local changes/suspect interactions, isolation, in-depth digital media analysis, consultation with law enforcement or counterintelligence organizations, development of signatures to detect this malicious behavior and development and deployment of eradication tools. Responsibilities: The majority of the CNDAu2019s time (75%) will be spent executing the following tasks: u2022 Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources u2022 Coordinate with enterprise-wide cyber defense staff to validate network alerts u2022 Document and escalate incidents (including event's history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment u2022 Perform cyber defense trend analysis and reporting u2022 Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack u2022 Provide daily summary reports of network events and activity relevant to cyber defense practices u2022 Receive and analyze network alerts from various sources within the enterprise and determine possible causes of alerts u2022 Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities u2022 Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity u2022 Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information u2022 Determine tactics, techniques, and procedures (TTPs) for intrusion sets u2022 Examine network topologies to understand data flows through the network u2022 Identify and analyze anomalies in network traffic using metadata u2022 Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings) u2022 Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools u2022 Identify applications and operating systems of a network device based on network traffic u2022 Reconstruct a malicious attack or activity based off network traffic u2022 Identify network mapping and operating system (OS) fingerprinting activities u2022 Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave u2022 Notify designated managers, cyber incident responders, and cybersecurity service provider team members of suspected cyber incidents and articulate the event's history, status, and potential impact for further action in accordance with the organization's cyber incident response plan Approximately 25% of the CNDAu2019s time will be spent executing the following tasks: u2022 Prepare and update manuals, instructions, and operating procedures u2022 Evaluate established methods and procedures and prepare recommendations for changes in methods and practices where appropriate u2022 Plan and carry out difficult and complex assignments and develop new methods, approaches, and procedures u2022 Conduct analyses and recommend resolution of complex issues affecting the specialty area u2022 Ensure optimal use of commercially available products u2022 Prepare and present reports u2022 Evaluate the effectiveness of installed systems and services Required Skills/Clearances: u2022 U.S. Citizenshipu00a0 u2022 Active TS/SCI clearanceu00a0 u2022 Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability u2022 5+ years of direct relevant experience in cyber defense analysis using leading edge technologies and industry standard cyber defense tools- Experience successfully developing and deploying signatures u2022 Experience detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort) u2022 Experience implementing incident handling methodologies u2022 Experience implementing protocol analyzers u2022 Experience collecting data from a variety of cyber defense resources u2022 Experience reading and interpreting signatures (e.g. snort) u2022 Experience performing packet-level analysis u2022 Experience conducting trend analysis Desired Skills: u2022 GSEC (SANS401), Arcsight (or other SEIM solution), Network+, Security+ and Python programming experience would be ideal. u2022 Strong math and science background. u2022 Experience with Carnegie Mellon SiLK tool suite. Required Education:u00a0BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 7-9 years of network investigations experience. Desired Certifications/Education:u00a0u2022 One or more of the following professional certifications: GNFA, GCIH, GCIA, GSEC, CASP+, CySA+, PaLMS, FedVTE Our Company Overview: Business Computers Management Consulting Group, LLC (BCMC) is a small business specializing in Information Technology (IT), Cybersecurity, Information Assurance (IA), SOA, Big Data Management, Program Management, and more for Federal, State, and Local agencies. We possess highly skilled engineers, providing innovative solutions backed by strong past performances. We are ISO 9001:2015, ISO 27001:2013, 20000:2018, and CMMI L3 certified and registered promising highest quality and services o all of our clients. Benefits Extremely competitive salaryu00a0 95% employer paid for employee medical, dental, & vison coveragesu00a0 100% employer paid for employee life, STD & LTD disability coveragesu00a0 401k with company match and profit sharingu00a0 Flexible Spending Account (FSA) for dependent & health careu00a0 11u00a0standard holidays & 3 weeks of annual leave ESS-3350 Host Based Systems Analyst - II - HBA02 Powered by JazzHR
Created: 2025-12-24