Cyber Network Defense Analysts (CNDA) / Host Based Systems Analyst
Location: Dulles, VA
Must have Top Secret Clearance
An onsite incident response, and immediate investigation and resolution using host-based, network-based, and cloud-based cybersecurity analysis capabilities. Team personnel provide front-line response for digital forensics/incident response (DFIR) and proactively hunt for malicious cyber activity.
Node is seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission. The CDNA uses information collected from a variety of sources to monitor network activity and analyze it for evidence of suspicious behavior. Monitoring and analysis are performed to identify and report events that occur, or might occur, within the network, in order to protect information, information systems, and networks from threats.
Responsibilities:
Assist customer with coordinating preliminary incident response investigations
Assist customer interface with external customers
Determine appropriate course of action in response to identified and analyze anomalous network activity
Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations
Collect network intrusion artifacts (e.g., PCAP, domains, URIs, certificates, etc.) and use discovered data to enable mitigation of potential Computer Network Defense incidents
Analyze identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
Collect network device integrity data and analyze for signs of tampering or compromise
Assist customer with real-time CND incident handling (i.e., forensic collections, intrusion correlation, and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagement
Requirements
Required Skills:
U.S. Citizenship
Must have an active TS/SCI clearance
Must be able to obtain DHS Suitability
8+ years of directly relevant experience in network investigations
In-depth knowledge of CND policies, procedures, and regulations
In-depth knowledge of TCP/IP protocols
In-depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
In-depth knowledge and experience of Wifi networking
In-depth knowledge and experience of network topologies - DMZs, WANs, etc.
Substantial knowledge of Splunk (or other SIEM’s)
Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
Knowledge of Computer Network Defense policies, procedures, and regulations
Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
Ability to identify and analyze anomalies in network traffic using metadata
Experience with reconstructing a malicious attack or activity based on network traffic
Experience examining network topologies to understand data flows through the network
Must be able to work collaboratively across physical locations
Desired Skills:
Substantial knowledge of network device integrity concepts and methodologiesExperience with or knowledge of two or more of the following tools: WireShark, Splunk, Snort, Corelight, Suricata, Arkime
Experience with EDR Tools (Crowdstrike, Carbon Black, Etc)
Proficiency with virtualized environments
Proficiency in conducting all-source research.
Proficiency with carving and extracting information from PCAP data
Proficiency with non-traditional network traffic (e.g. Command and Control)
Familiarity with ICS/SCADA protocols
Familiarity with Python or other scripting languages
Required Education:
BS Computer Science, Cybersecurity, Computer Engineering, or related degree; or HS Diploma and 10+ years of network investigation experience
Desired Certifications:
GCFA, GCFE, EnCE, CCE, CFCE, CISSP, IASAE II, GCIA, GCIH, CSSP Analyst, CSSP Incident Responder, CEH, SANS GIAC GNFA preferredCompany Overview:
Node.Digital is an independent Digital Automation & Cognitive Engineering company that integrates best-of-breed technologies to accelerate business impact.
Our Core Values help us in our mission. They include:
OUR CORE VALUES
Identifying theRIGHT PEOPLEand developing them to their full capabilities
Our customer’s “Mission” is our “Mission”. OurMISSION FIRSTapproach is designed to keep our customers fully engaged while becoming their trusted partner
We believe inSIMPLIFYINGcomplex problems with a relentless focus on agile delivery excellence
Our mantra is “SimpleSecureSpeed” in the delivery of innovative services and solutions
Benefits
We are proud to offer competitive compensation and benefits packages to include
Medical
Dental
Vision
Basic Life
Long-Term Disability
Health Saving Account
401K
Three weeks of PTO
10 Paid Holidays
Pre-Approved Online Training