Company

By Light Professional IT Services LLCSee more

addressAddressMaryland, United States
type Form of workFull-Time
CategoryInformation Technology

Job description

This position will support GSM-O II Task Number 07 (TN07), which provides support to Joint Force Headquarters-DoD Information Network (JFHQ-DODIN).  JFHQ-DODIN provides network operations and defensive cyber operations support to the United States Cyber Command in support of the DoD.  The selected candidate shall provide analysis that provides 24 hours per day x 7 days per week x 365 days per year support JFHQ-DODIN Operations Center, providing command, control, and defensive cyber operations (DCO) functions across the Combatant Commands, Service Cyber Components, Agencies, and Field Activities in addition to 24/7 coordination with USCYBERCOM and other partner agencies.


  • Leverage an array of network monitoring and detection capabilities (including netflow, custom application protocol logging, signature-based IDS, and full packet capture (PCAP) data) to identify cyber adversary activity.
  • Support the development of Cyber Fusion standard operating procedures (SOPs), and Cyber Fusion Framework and Methodology based on industry best practice and department of defense instruction, guidance, and policy.
  • Identify threats to the enterprise and provide mitigation strategies to improve security and reduce the attack surface.
  • Perform analysis by leveraging serialized threat reporting, intelligence product sharing, OSINT, and open-source vulnerability information to ensure prioritized plans are developed.
  • Analyze and document malicious cyber actors TTPs, providing recommendations and alignment to vulnerabilities and applicability to the enterprise operational environment.
  • Discover adversary campaigns, anomalies and inconsistencies in sensor and system logs, SIEMs, and other data.
  • Analyze and track vulnerability disclosure program (VDP) incidents as it relates to intelligence reporting.
  • Identify, investigate and rule out system compromises, with the capacity to provide written analytic summaries and attack life cycle visualizations.
  • Provide risk assessments and recommendations based on analysis of technologies, threats, intelligence, and vulnerabilities.
  • Offer recommendations to adjust enterprise or tactical countermeasures to for threats impacting the DODIN.
  • Collect analysis metrics and trending data, identify key trends, and provide situational awareness on these trends.
  • Provide guidance regarding the use of OSINT techniques in the pursuit of investigatory requirements.
  • Perform quality assurance duties on behalf of JDOC leadership, ensuring that SIGACTs are compliant with JDOC policies, as well as ensuring that all information is captured before closure.

  • Bachelor’s degree in related discipline and 8-12 years of related experience.  Additional experience may be accepted in lieu of degree.
  • DoD 8570 IAT Level II Certification (SEC+, CySA, GICSD, etc.).
  • Experience working with members if the Intelligence Community and knowledge and understanding of Intelligence processes.
  • In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies.
  • Proficiency with datasets, tools and protocols that support analysis (e.g. Splunk, CMRS, VDP, passive DNS, Virus Total, TCP/IP, OSI, WHOIS, enumeration, threat indicators, malware analysis results, Wireshark, Arcsight, etc.).
  • Experience with Intelligence Community repositories (Pulse, TESTFLIGHT, etc.)
  • Experience with various open-source and commercial vendor portals, services and platforms that provide insight into how to identify and/or combat threats or vulnerabilities to the enterprise.
  • Proficiency working with various types of network data (e.g. netflow, PCAP, custom application logs).

  • Experience with the DODIN and other DoD Networks.
  • Familiarity with DoD portals and tools (RAMs, IKE, JCC2, etc.)
  • Experience with proprietary OS Intelligence Sources (Mandiant, Recorded Future, Shodan, etc.)
  • Skilled in building extended Cyber Security analytics (Trends, Dashboards, etc.).
  • Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership.
  • Experience in intelligence driven defense and/or Cyber Kill Chain methodology.
  • IAT Level III or IAM Level II+III Certifications

  • Active DoD TS/SCI Clearance and eligible for polygraph.

Refer code: 7630914. By Light Professional IT Services LLC - The previous day - 2024-01-04 00:32

By Light Professional IT Services LLC

Maryland, United States
Jobs feed

Superintendent - WWTP

Gpac Talent Network

Norfolk, NE

Practice Development Manager

Neurostar

Milwaukee, WI

United States, Wisconsin, Milwaukee

Superintendent - WWTP

Gpac Talent Network

Brookings, SD

Agricultural Loan Officer

Gpac Talent Network

Kankakee, IL

Agricultural Loan Officer

Gpac Talent Network

Emporia, KS

Trust Officer

Gpac Talent Network

Emporia, KS

Crop Insurance Farm Management

Gpac Talent Network

Emporia, KS

Steward - Seaward Services - Explorer

Seaward Services

Charleston, SC

Superintendent - WWTP

Gpac Talent Network

Sioux Falls, SD

Share jobs with friends

Related jobs

Cyber Security Fusion Watch Officer

Cyber Security Intern or Co-op

Langan

Parsippany, NJ

8 hours ago - seen

Cyber Security Engineer

Clarivate Analytics Us Llc

United States, Virginia, Alexandria

Alexandria, VA

10 hours ago - seen

Cyber Security Engineer

Clarivate Analytics Us Llc

United States, Arizona, Tempe

Tempe, AZ

10 hours ago - seen

Cyber Security Engineer

Clarivate Analytics Us Llc

United States, Colorado, Denver

Denver, CO

11 hours ago - seen

Cyber Security Engineer

Clarivate Analytics Us Llc

United States, Missouri, Kansas City

Kansas City, KS

11 hours ago - seen

Cyber Security Engineer

Clarivate Analytics Us Llc

United States, Pennsylvania, Philadelphia

Philadelphia, PA

11 hours ago - seen

Cyber Security Engineer SME - Clearance Required

Logistics Management Institute

Remote - United States

15 hours ago - seen

Cyber Security Specialist - (w/ active Secret)

Critical Solutions

Bridgeport, CA

15 hours ago - seen

Cyber Security Engineer

Torc Robotics

Remote - United States

17 hours ago - seen

Senior Cyber Security Specialist

Mantech

Falls Church, VA

17 hours ago - seen

Lead Cyber Security Operations Center (SOC) Analyst

State Street

Quincy, MA

17 hours ago - seen

Cyber Security Engineer

Computer Task Group, Inc

Anchorage, AK

17 hours ago - seen

Cyber Security Intern

Pge

Avila Beach, CA

yesterday - seen

Information Security Cyber Risk Analyst

Intel

Chandler, AZ

2 days ago - seen

Sr Cyber Security Engineer I

Staples

Framingham, MA

2 days ago - seen