Network Forensics Cybersecurity Analyst -Senior
Arlington, Virginia, United States
phia LLC
At phia, trust us to solve the complex challenges of our connected world through top-tier cyber intelligence & threat hunting. Contact us.At phia, our goal is to hire talented and passionate team members who desire to grow their skillsets, as well as the reputation of the company with our partners, clients, and stakeholders. We love to engage with intellectually curious individuals who possess the skill sets that meet our customer’s needs.
We have an opportunity for a highly skilled senior level Network Forensics Cybersecurity Analyst to join the security team of a government organization that is securing the nation’s infrastructure. In this position you will provide remote and onsite advanced technical assistance critical to the customer mission. Job location is in Arlington, VA with temporary telecommuting during COVID-19.
What You'll Do
- Assist the Government lead in coordinating teams in preliminary incident response investigations
- Assist the Government lead with interfacing with the customer while on site
- Determine appropriate courses of actions in response to identified anomalous network activity
- Assess network topology and device configurations, identify critical security concerns, and provide security best practice recommendations
- Assist with the writing and publishing of Computer Network Defense guidance and reports on incident findings to appropriate constituencies
- Collect network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and use discovered data to enable mitigation of potential Computer Network Defense incidents
- Analyze identified malicious network activity to determine weaknesses exploited, exploitation methods, and effects on system and information
- Assist with real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, advise on system remediation) tasks to support onsite engagements
Requirements
Education + Experience
- BS in Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of network investigation experience.
- Must have an active TS/SCI clearance Must be able to obtain DHS Suitability
- 8+ years of directly relevant experience in network investigations
- In depth knowledge of CND policies, procedures and regulations
- In depth knowledge of standard protocols - ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, TCP/IP - In depth knowledge and experience of Wi-Fi networking
- In depth knowledge and experience of network topologies - DMZ’s, WAN’s, etc.
- Substantial knowledge of Splunk (or other SIEM’s)
- Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
- Knowledge of Computer Network Defense policies, procedures, and regulations
- Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
- Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
- Ability to identify and analyze anomalies in network traffic using metadata
- Experience with reconstructing a malicious attack or activity based on network traffic
- Experience examining network topologies to understand data flows through the network
- Must be able to work collaboratively across physical locations
- This position will require U.S. Citizenship
- Must have an active TS/SCI clearance
- Must be able to obtain DHS Suitability
Desired Certifications
- DoD 8140.01 IAT Level II, (CCNA-Security, GICSP, GSEC, Security+ CE, SSCP)
- IASAE II, (CASP+ CE, CISSP or Associate, CSSLP)
- CSSP Analyst, GCIA, GCIH, CSSP Analyst/CSSP Incident Responder, CEH - SANS GIAC GNFA
- A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.
- Intellectually curious with a genuine desire to learn and advance your career.
- An effective communicator, both verbally and in writing.
- Customer service oriented and mission focused.
- Critical thinker with excellent problem-solving skills
If your experience and qualifications aren’t a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.
Benefits
COMPANY OVERVIEW:
Who We Are
phia LLC ("phia") is a Northern Virginia based, 8a certified small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security. we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.
phia values work-life balance and offers the following benefits to full-time employees:
- Comprehensive medical insurance to include dental and vision
- Short Term & Long-Term Disability
- 401k Retirement Savings Plan with Company Match
- Tuition and Professional Development Assistance
- Flex Spending Accounts (FSA)
phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.
Tags: CASP+ CEH CISSP Clearance Computer Science DNS DoD DoDD 8140 Forensics GCIA GCIH GIAC GICSP GNFA GSEC Incident response Network security PCAP SANS Security Clearance SIEM SMTP Splunk SSCP SSH Strategy TCP/IP TS/SCI
Perks/benefits: 401(k) matching Career development Health care Insurance
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Information Security Specialist jobs
- Open Manager Pentest H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Cyber Security Specialist jobs
- Open Product Security Engineer jobs
- Open Principal Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Security Specialist jobs
- Open Senior Information Security Engineer jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open IT Security Engineer jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Java-related jobs
- Open IDS-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs
- Open CEH-related jobs
- Open IPS-related jobs