Cyber Network Defense Analyst

201DU - Customer Site,Herndon, VA

Applications have closed

Secure our Nation, Ignite your Future

Are you interested in defending the most coveted targets in the world? Is advancing today's technology for tomorrow's cyber threats to national security constantly on your mind? Join ManTech and help protect our country against our cyber adversaries while working on innovative projects that offer opportunities for advancement. We encourage our team members to share and grow their skills and expertise while creating robust and cutting-edge solutions. Join a team who protects and defends the largest target in the world.

ManTech is seeking a Cyber Network Defense Analyst in Herndon, VA. As a Cyber Network Defense Analyst on our team, you will use your expertise in Host Based Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS) and specialized network defense to provide innovative and creative solutions to challenging cyber security problems. You will utilize the latest cyber tools available and assist with creating new ones while allowing you to advance the nation's information security posture.

Responsibilities include, but are not limited to:

  • Provide malicious code detection, intrusion detection, and information security tool development and integration.

  • Utilize forensic analysis to identify malware, misuse, and/or unauthorized activity.

  • Investigate and report on virus and malware alerts or incidents to determine root cause, entry point of code and damage risk.

  • Analyze all data sources, including Internet, Intelligence Community (IC) reporting, security events, firewall logs, and other data sources to identify malware, misuse, unauthorized activity or other cyber security related concerns.

  • Track intelligence using open source and classified sources to identify malicious code threats and provide solutions to counteract that threat.

  • Create, edit, and manage signatures, custom rules and filters for specialized network defense systems including but not limited to, Network and host-based IDS, IPS, firewalls and web application firewalls, Security Orchestration, Automation and Response (SOAR), Proxy, and Security Information and Event Management (SIEM) systems

  • Manage and administer the tuning of rules, signatures, and custom content for CND applications and systems.

  • Identify potential conflicts with implementation of any CND tools within the enterprise and develop recommendations to remediate these conflicts

  • Provide logical use case development.

  • Provide and track requirements to engineering partners.

  • Identify gaps in visibility or coverage of cyber defense systems.

  • Prepare data analytics and reporting.

Required Qualifications:

  • 2+ years of experience in Network Defense, Network Operations, Cybersecurity, Network Engineering, Security Engineering, Information Security, Systems Architecture or Data Analysis

  • Experience writing script in programming languages such as Python, JavaScript, Yara or Snort

  • Experience using SIEM tools for case development and application

  • Experience with network security applications, protocols, and associated hardware

  • Knowledge of enterprise cyber defense technologies such as SIEM systems, SysMon, network and host based IDS and IPS, network and host-based malware detection and prevention, Endpoint Detection & Response (EDR) and Network Detection & Response (NDR), Network and Host malware detection and prevention (EDR/NDR) tools, forensics tools and applications, Web/Email gateway security technologies, Security Orchestration, Automation and Response (SOAR) and cloud based platforms such as Azure, AWS, or Google

  • Active TS/SCI with polygraph clearance

Preferred Qualifications:

  • Experience with MITRE ATT&CK

  • Experience with Splunk or Splunk Enterprise Security

  • Ability to demonstrate interpersonal, organizational, writing, communications, and briefing skills

  • Ability to effectively use analytical and problem-solving skills

Clearance requirement: Active/Current TS/SCI with polygraph

Physical Requirements:

  • Must be able to remain in a stationary position 50%

  • Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer

  • The person in this position needs to occasionally move about inside the office

#LI-MT1

SKN.7.23

For all positions requiring access to technology/software source code that is subject to export control laws, employment with the company is contingent on either verifying U.S.-person status or obtaining any necessary license. The applicant will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance with federal law. ManTech may choose not to apply for a license for such individuals whose access to export-controlled technology or software source code may require authorization and may decline to proceed with an applicant on that basis alone.

ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.

If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech's Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech's utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services.

If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click careers@mantech.com and provide your name and contact information.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Analytics Automation AWS Azure Clearance Cloud CND Compliance Cyber defense Data Analytics EDR Firewalls Forensics IDS Intrusion detection Intrusion prevention IPS JavaScript Malware MITRE ATT&CK Network security Open Source Polygraph Python SIEM Snort SOAR Splunk TS/SCI

Perks/benefits: Career development Team events

Region: North America
Country: United States
Job stats:  10  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.