The Defensive Cyber Operations (DCO) division within the USARCC-SWA is looking for a candidate with strong scripting abilities, experience with systems security administration, and network security technologies. The Cyber Threat Analyst will design, implement, automate, maintain, and optimize measures protecting systems, networks, and information.
Monitor, detect, analyze, and correlate events for potential threat activity utilizing Security Information Event Management (SIEM) systems, Big Data Analytics, and other supporting platforms or applications.
Investigate and identify the cause, source, and methodology of compromises or incidents.
Initiate computer incident handling procedures to isolate and investigate potential network information system compromises.
Perform trend analysis on events and incidents to identify and characterize threats.
Conduct open source research to identify commercial exploits or vulnerabilities (i.e., Zero – Day) requiring response actions.
Prepare formal comprehensive reports and presentations for both technical and executive audiences.
Configure and optimize software and hardware detection and prevention capabilities.
Perform host and network base signature development and standardization for implementation on end-point products or sensor grid.
Develop, document and refine Tactics, Techniques, and Procedures (TTP)
Education / Certifications: One year of related experience may be substituted for one year of education, if degree is required.
Bachelors Degree or equivalent experience preferably in Computer Science or MIS, IS, Engineering or related field.
This position requires candidates to adhere to DoD 8570.01-M.
All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline Environment (BE) certifications cannot also be used as a Computing Environment (CE) certification. The authorized certifications for this job title are listed as follows:
CEH, CFR, CCNA Cyber Ops, CCNA-Security, GCIA, GCIH, GISCP, Cloud+, SCYBER, PenTest+
GCDA (preferred), GCIH, GCIA, GREM, GCFA, GDAT, GCWN, OSCP, OSCE, GSEC
Experience: One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor’s degree in a Business Information Systems discipline for three years general experience.
At least five (5) years of practical experience working with various data (network and system) technologies, with a minimum of two of those years focused on information systems security, cyber threats and SIEM event analysis.
Experience with a customer service oriented company
Skills & Technology Used:
Ability to troubleshoot servers and infrastructure equipment
Ability to assess networking requirements and provide solutions
Ability to make accurate and independent decisions under pressure
Ability to perform comfortably in a fast-paced, deadline-oriented work environment
Ability to successfully execute many complex tasks simultaneously
Visualization of quantitative (numerical) or qualitative information
Excellent interpersonal, organizational, written and verbal communication, and briefing skills
Excellent analytical and problem-solving skills
Threat Intelligence and visualization technologies
Security enclave engineering
We are committed to an inclusive and diverse workplace that values and supports the contributions of each individual. This commitment along with our common Vision and Values of Integrity, Respect, and Responsibility, allows us to leverage differences, encourage innovation and expand our success in the global marketplace. Vectrus is an Equal Opportunity /Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, protected veteran status or status as an individual with a disability. EOE/Minority/Female/Disabled/Veteran.
Top Secret SCI (SSBI) (Tier 5)
Vectrus / Equal Opportunity Employer / JBVTR-19306
Top Secret, CLZTT, SKINT, SKCYB, JBVTR SKUUU, LV_KUWAIT LV_KUWAIT ZCMDKWT ZCMDKZ