Host Based Systems Analyst II
Core
Front-line Cyber Network Defense Analyst providing digital forensics, incident response, and proactive hunting for malicious cyber activity to protect government client networks.
Role type
Cyber Network Defense Analyst (CNDA)
Builds
Cyber defense monitoring, incident response, and threat detection capabilities for government agencies
Domain
Cybersecurity / Government Contracting
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Network traffic analysis, incident handling, signature development, packet-level analysis, IDS validation, TTP identification, network topology examination, anomaly detection, metadata analysis, attack reconstruction, OS fingerprinting detection
Preferred skills
Python programming, SiLK tool suite usage, advanced math/science background
Technologies
Snort, Arcsight, SEIM solutions, protocol analyzers, Carnegie Mellon SiLK
Responsibilities
Characterize and analyze network traffic to identify anomalous activity and potential threats; Coordinate with enterprise-wide cyber defense staff to validate network alerts; Document and escalate incidents including event history, status, and potential impact; Perform cyber defense trend analysis and reporting; Receive and analyze network alerts from various sources to determine possible causes; Provide timely detection, identification, and alerting of possible attacks/intrusions and distinguish them from benign activities; Use cyber defense tools for continual monitoring and analysis of system activity; Analyze identified malicious activity to determine weaknesses exploited and effects on systems; Determine tactics, techniques, and procedures (TTPs) for intrusion sets; Examine network topologies to understand data flows; Identify and analyze anomalies in network traffic using metadata; Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools; Identify applications and operating systems of network devices based on traffic; Reconstruct malicious attacks based on network traffic; Identify network mapping and OS fingerprinting activities; Assist in constructing signatures for cyber defense tools; Notify managers and responders of suspected incidents with event details; Prepare and update manuals, instructions, and operating procedures; Evaluate established methods and prepare recommendations for changes; Plan and carry out complex assignments and develop new methods; Conduct analyses and recommend resolution of complex issues; Evaluate the effectiveness of installed systems and services
Seniority
Mid-Senior level, hands-on IC