Today
Top Secret/SCI
Unspecified
CI Polygraph
IT - Security
Springfield, VA (On-Site/Office)
Cyber Hunt Engineer
Job Category: Engineering
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
The hunt services team member will proactively search for indicators of compromise on NGA systems through plan and continuous hunt missions. They will use cybersecurity tools and data to identify security incidents that may go undetected by automated security tools. The hunt services team member will develop hunt missions generally based on one of the following methodologies:
• Hypothesis-driven investigation. Hypothesis-driven investigations are driven by a large amount of data that provides insight into threat actors' latest tactics, techniques and procedures (TTP). Hunt services team members use this data to investigate whether those behaviors are present within the organization's current environment.
• IOC-driven investigation. Indicators of compromise (IOC) are found in forensic "artifacts" and identify activities that indicates potential threats. Investigations driven by IOCs use threat intelligence to try to identify the effect threat within the organization's environment. Potential IOCs include network-based artifacts, host-based artificial and authentication-based artifacts.
RESPONSIBILITIES:
• Proactively search and identify indicators of compromise and anomalous behavior that has not met event/incident threshold, or has not been detected by automated security tools
• Collect data from multiple cybersecurity tools, log sources, threat intelligence products, etc. and build hunt missing plans based off of the assessment of these data sources
• Analyze collected data to find potential shortfalls in security controls and work with Advanced Cyber Analytics develop countermeasures to strengthen security
• Study trends in cyber threats to better understand threat actors' behaviors, tactics, and goals.
• Provide findings from hunt missions to Cyber Threat Intelligence team for analysis and possible inclusion in develop intelligence products
• Create, update, and document tickets in the authorized ticketing system
REQUIRED QUALIFICATIONS
• Candidate must have a TS/SCI with ability to obtain a CI Polygraph
• Bachelor's Degree in a technical field
• 5+ years experience in related cyber area
• Certified DoD 8140.01 and 8570.01-M Information Assurance Technical Officer (IAT) Level III
• CSSP-Analyst certification within six months of start date
• Excellent writing skills with the ability to write clear and concise hunt reports
DESIRED QUALIFICATIONS:
• Master's degree
-
_____________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI takes pride in fostering a diverse and accessible culture where every individual feels supported to chart their own path. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
_____________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here .
Since this position can be worked in more than one location, the range shown is the national average for the position.
The proposed salary range for this position is:
$74,600-$156,700
CACI is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
Job Category: Engineering
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
The hunt services team member will proactively search for indicators of compromise on NGA systems through plan and continuous hunt missions. They will use cybersecurity tools and data to identify security incidents that may go undetected by automated security tools. The hunt services team member will develop hunt missions generally based on one of the following methodologies:
• Hypothesis-driven investigation. Hypothesis-driven investigations are driven by a large amount of data that provides insight into threat actors' latest tactics, techniques and procedures (TTP). Hunt services team members use this data to investigate whether those behaviors are present within the organization's current environment.
• IOC-driven investigation. Indicators of compromise (IOC) are found in forensic "artifacts" and identify activities that indicates potential threats. Investigations driven by IOCs use threat intelligence to try to identify the effect threat within the organization's environment. Potential IOCs include network-based artifacts, host-based artificial and authentication-based artifacts.
RESPONSIBILITIES:
• Proactively search and identify indicators of compromise and anomalous behavior that has not met event/incident threshold, or has not been detected by automated security tools
• Collect data from multiple cybersecurity tools, log sources, threat intelligence products, etc. and build hunt missing plans based off of the assessment of these data sources
• Analyze collected data to find potential shortfalls in security controls and work with Advanced Cyber Analytics develop countermeasures to strengthen security
• Study trends in cyber threats to better understand threat actors' behaviors, tactics, and goals.
• Provide findings from hunt missions to Cyber Threat Intelligence team for analysis and possible inclusion in develop intelligence products
• Create, update, and document tickets in the authorized ticketing system
REQUIRED QUALIFICATIONS
• Candidate must have a TS/SCI with ability to obtain a CI Polygraph
• Bachelor's Degree in a technical field
• 5+ years experience in related cyber area
• Certified DoD 8140.01 and 8570.01-M Information Assurance Technical Officer (IAT) Level III
• CSSP-Analyst certification within six months of start date
• Excellent writing skills with the ability to write clear and concise hunt reports
DESIRED QUALIFICATIONS:
• Master's degree
-
_____________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
An environment of trust.
CACI takes pride in fostering a diverse and accessible culture where every individual feels supported to chart their own path. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
Your potential is limitless. So is ours.
Learn more about CACI here.
_____________________________________________________________________________
Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here .
Since this position can be worked in more than one location, the range shown is the national average for the position.
The proposed salary range for this position is:
$74,600-$156,700
CACI is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
group id: caci