Source description
About the role
BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 10+ years of network investigations experience.
8+ years of directly relevant experience in network investigations
In-depth knowledge of CND policies, procedures, and regulations
In-depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, TCP/IP
In-depth knowledge and experience of Wifi networking
In-depth knowledge and experience of network topologies, DMZs, WANs, etc.
Substantial knowledge of Splunk (or other SIEMs)
Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
Knowledge of Computer Network Defense policies, procedures, and regulations
Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
Ability to identify and analyze anomalies in network traffic using metadata
Experience with reconstructing a malicious attack or activity based on network traffic
Experience examining network topologies to understand data flows through the network
Must be able to work collaboratively across physical locations
More at ARSIEM
Related open roles
Network Based Systems Analyst III
United States · Onsite
Network Based Systems Analyst III
United States · Onsite
Security Specialist
Remote · United States
Incident Manager III
United States · Onsite
382 - Analytic Developer
United States · Onsite
378 - Information System Security Engineer
United States · Onsite
