Network Based Systems Analyst II
Core
Monitor network activity and analyze it for evidence of suspicious behavior to protect information systems from threats.
Role type
Cyber Network Defense Analyst (CNDA)
Builds
Cyber defense monitoring and analysis services for government clients
Domain
Cybersecurity / Network Defense
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
network traffic analysis, intrusion detection, incident handling, packet analysis, signature development, trend analysis, protocol analysis, metadata analysis, OS fingerprinting, attack reconstruction
Preferred skills
Python programming, SiLK tool suite usage, advanced cyber defense certifications (GNFA, GCIH, GCIA, GSEC, CASP+, CySA+, PaLMS, FedVTE)
Technologies
Snort, Arcsight, SEIM solutions, protocol analyzers, SiLK
Responsibilities
Characterize and analyze network traffic to identify anomalous activity and potential threats; Coordinate with enterprise-wide cyber defense staff to validate network alerts; Document and escalate incidents; Perform cyber defense trend analysis and reporting; Perform event correlation using information from various sources; Provide daily summary reports of network events; Receive and analyze network alerts to determine possible causes; Provide timely detection, identification, and alerting of attacks/intrusions; Use cyber defense tools for continual monitoring and analysis; Analyze identified malicious activity to determine weaknesses and effects; Identify and analyze anomalies in network traffic using metadata; Validate IDS alerts against network traffic using packet analysis tools; Identify applications and operating systems based on network traffic; Reconstruct malicious attacks based on network traffic; Identify network mapping and OS fingerprinting activities; Assist in constructing signatures for cyber defense tools
Seniority
Mid-level, hands-on IC