Network Based Systems Analyst III
Core
Monitor network activity, identify and report security events, and protect information systems from threats for a US Government client.
Role type
Cyber Network Defense Analyst (IC)
Builds
Cyber defense monitoring, incident response, and threat detection capabilities for government networks
Domain
Cybersecurity / Network Defense
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Network traffic analysis, intrusion detection, incident handling, packet analysis, signature development, trend analysis, protocol analysis, metadata analysis, TTP identification, network topology examination, OS fingerprinting, attack reconstruction, IDS validation
Preferred skills
Python programming, SIEM operations, math and science background, SiLK tool suite usage, advanced security certifications (GSEC, GCIH, GCIA, CASP+, CySA+, PaLMS, FedVTE)
Technologies
Snort, ArcSight, SiLK, packet analyzers, IDS tools
Responsibilities
Characterize and analyze network traffic to identify anomalous activity and potential threats; Coordinate with enterprise-wide cyber defense staff to validate network alerts; Document and escalate incidents; Perform cyber defense trend analysis and reporting; Receive and analyze network alerts from various sources; Utilize cyber defense tools for continuous monitoring; Analyze identified malicious activity to determine weaknesses and effects; Determine tactics, techniques, and procedures (TTPs) for intrusion sets; Examine network topologies to understand data flows; Identify and analyze anomalies in network traffic using metadata; Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools; Identify applications and operating systems of a network device based on network traffic; Reconstruct a malicious attack or activity based on network traffic; Identify network mapping and operating system (OS) fingerprinting activities; Assist in the construction of signatures for cyber defense tools; Notify designated managers and incident responders of suspected cyber incidents; Prepare and update manuals, instructions, and operating procedures; Evaluate established methods and procedures and prepare recommendations for changes; Plan and execute challenging and complex assignments; Conduct analyses and recommend resolutions for complex issues; Ensure optimal use of commercially available products; Prepare and present reports; Evaluate the effectiveness of installed systems and services
Seniority
Mid-Senior level, hands-on IC