The selected candidate will perform robust network security monitoring and proactively identify potential threats across our enterprise infrastructure. This role is critical for defending mission systems, conducting in-depth traffic and vulnerability analysis, and maintaining a strong security posture in support of Department of War (DOW) missions.
The Cyber Defense Analyst (Threat Hunter) is a vital role responsible for performing comprehensive network security monitoring and proactive threat hunting during swing-shift, weekend, and holiday coverage windows. This position focuses on safeguarding the network through continuous traffic analysis, vulnerability and wireless scanning, and leveraging enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Analyst will collaborate with cross-functional IT and security teams to:
- Implement Information Assurance Vulnerability Management (IAVM) programs
- Manage Network Access Control
- Provide insider threat support
- Monitor data at rest
- Review web content filtering
- Maintain and upkeep various cybersecurity applications and tools on servers and workstations to ensure high operational readiness during all covered hours
- Log Analysis & Threat Identification: Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to identify possible security threats (e.g., determine rogue systems, infected systems, unauthorized system changes, and unauthorized hardware connections).
- Policy Enforcement: Ability to identify violations of internet access by reviewing web content filtering logs in accordance with DoD policy, and Standard Operating Procedures (SOPs).
- Task Management: Experience in processing and handling JFHQ DODIN Cyber related tasks to completion.
- Proactive Threat Hunting: Performance of threat hunting activities using DOD approved cyber tools through data hunting, manipulation, and presentation, including generating queries and reports for management and the end-customer.
- Incident Assessment: Validation and confirmation of critical security events and assessing the impact of the event, by incorporating data from multiple tool sources.
- Investigation & Forensics: Identifying evidence of illegal activity involving cybercrime offenses and examining computers that may have been involved in other types of crime or malware infection.
- Malware Analysis: Use of forensic tools and investigative methods to find specific electronic data, namely associated with performing complex malware analysis.
- Process Documentation: Experience developing and maintaining SOPs for security monitoring.
- Reporting: Provide daily/weekly/monthly reports to senior leadership on key indicators of network security.
- Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.