Cyber Security Watch Officer

TEKsystems c/o Allegis Group

Yesterday
Top Secret/SCI
Mid Level Career (5+ yrs experience)
$125,000 - $150,000
No Traveling
IT - Security
Fort George G Meade, MD (On-Site/Office)

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms.  If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)

· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)

· Because an active or interim DoD clearance is required, U.S. Citizenship is required

Primary Responsibilities:
• In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies.
• Proficiency with datasets, tools, and protocols that support analysis (e.g., Splunk, CMRS, VDP, passive DNS, Virus Total, TCP/IP, OSI, WHOIS, enumeration, threat indicators, malware analysis results, Wireshark, Arcsight, etc.).
• Experience with Intelligence Community repositories (Pulse, TESTFLIGHT, etc.)
• Experience with various open-source and commercial vendor portals, services and platforms that provide insight into how to identify and/or combat threats or vulnerabilities to the enterprise.
• Proficiency in working with various types of network data (e.g., netflow, PCAP, custom application logs).
• Leverage an array of network monitoring and detection capabilities (including netflow, custom application protocol logging, signature-based IDS, and full packet capture (PCAP) data) to identify cyber adversary activity.
• Support the development of Cyber Fusion standard operating procedures (SOPs), and Cyber Fusion Framework and Methodology based on industry best practice and department of defense instruction, guidance, and policy.
• Identify threats to the enterprise and provide mitigation strategies to improve security and reduce the attack surface.
• Perform analysis by leveraging serialized threat reporting, intelligence product sharing, OSINT, and open-source vulnerability information to ensure prioritized plans are developed.
• Analyze and document malicious cyber actors TTPs, providing recommendations and alignment to vulnerabilities and applicability to the enterprise operational environment.
• Discover adversary campaigns, anomalies and inconsistencies in sensor and system logs, SIEMs, and other data.
• Analyze and track vulnerability disclosure program (VDP) incidents as it relates to intelligence reporting.
• Identify, investigate and rule out system compromises, with the capacity to provide written analytic summaries and attack life cycle visualizations.
• Provide risk assessments and recommendations based on analysis of technologies, threats, intelligence, and vulnerabilities.
• Offer recommendations to adjust enterprise or tactical countermeasures to for threats impacting the DODIN.
• Collect analysis metrics and trending data, identify key trends, and provide situational awareness on these trends.
• Provide guidance regarding the use of OSINT techniques in the pursuit of investigatory requirements.
• Perform quality assurance duties on behalf of JDOC leadership, ensuring that SIGACTs are compliant with JDOC policies, as well as ensuring that all information is captured before closure.

Preferred Qualifications:
• Experience with the DODIN and other DoD Networks.
• Familiarity with DoD portals and tools (RAMs, IKE, JCC2, etc.)
• Experience with proprietary OS Intelligence Sources (Mandiant, Recorded Future, Shodan, etc.)
• Skilled in building extended cyber security analytics (Trends, Dashboards, etc.).
• Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership.
• Experience in intelligence driven defense and/or Cyber Kill Chain methodology.
• IAT Level III or IAM Level II+III Certifications
group id: 10105424
N
Name HiddenRecruiter

Accelerating IT transformation in the public sector

Find TEKsystems c/o Allegis Group on Social Media
Network Employers (24)
Recruiter
Recruiter
Recruiter
Technical Recruiter
Recruiter
About Us
We’re partners in transformation. We help customers activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company.

TEKsystems c/o Allegis Group Jobs


Job Category
IT - Security
Clearance Level
Top Secret/SCI