The Newberry Group

The Newberry Group

Cybersecurity Analyst

Full-Time
$95k - $125k/yr
Junior, Mid
Bachelor's
O'Fallon, IL, USA
In Person

On-site at Scott Air Force Base; assigned shift work is required.

No H1B Sponsorship
US Top Secret Clearance Required

About the job

Requirements
  • Hold an active Department of Defense Secret clearance or above.
  • Hold a Department of Defense 8140 Information Assurance Technical level II or higher certification, such as CompTIA Security+ Continuing Education, CompTIA Cybersecurity Analyst+, International Information System Security Certification Consortium Systems Security Certified Practitioner, or SANS Global Information Assurance Certification Security Essentials, before starting.
  • Obtain a Department of Defense 8140 Cybersecurity Service Provider Analyst certification, such as Certified Ethical Hacker, CompTIA Cybersecurity Analyst+, or Global Information Assurance Certification Certified Intrusion Analyst, within 180 days of hire.
  • Have a strong foundation in networking, including packet analysis, common ports and protocols, and traffic flow; knowledge of the Open Systems Interconnection model, defense-in-depth security principles, and common security elements for effective threat detection, analysis, and mitigation as a security operations center security analyst.
  • For Level I, have a Bachelor's degree and at least 1 year of relevant experience, or equivalent work experience or military service in lieu of a degree.
  • For Level II, have a Bachelor's degree and at least 3 years of relevant experience, or equivalent work experience or military service in lieu of a degree.
  • Work effectively independently and as a collaborative team member.
  • Demonstrate continuous learning and self-improvement in cybersecurity through certification pursuit, industry forum participation, and staying current with emerging threats and technologies.
  • Apply problem-solving skills to address complex security challenges, communicate technical information clearly and concisely, build consensus, and drive solutions to completion.
  • Be willing and able to work assigned shifts, including 7 a.m.–3 p.m., 3 p.m.–11 p.m., or 11 p.m.–7 a.m.
  • Be located within a commutable distance of Scott Air Force Base, Illinois.
Responsibilities
  • Investigate alerts generated from endpoints, intrusion detection and prevention systems, NetFlow data, and custom sensors to detect compromises on customer networks.
  • Analyze extensive log files, pivot between diverse datasets, and correlate evidence to support incident investigations, creating detailed technical reports outlining findings.
  • Triage security alerts to rapidly identify malicious actors targeting customer networks.
  • Monitor and analyze Department of Defense and open-source intelligence feeds to identify indicators of compromise and integrate them into security sensors and security information and event management systems.
  • Report security incidents to customers and United States Cyber Command, ensuring timely communication and coordinated response.
Desired Qualifications
  • Hands-on experience analyzing large volumes of logs, network data such as NetFlow and full packet capture, and other attack artifacts during incident investigations.
  • In-depth experience using a security information and event management or security orchestration, automation, and response platform to analyze multiple log types and events across various data points, applying behavioral analysis, statistical analysis, and machine learning to detect and respond to advanced threats.
  • Comprehensive understanding of the network threat lifecycle, attack vectors, and methods of exploitation, including intrusion set tactics, techniques, and procedures.
  • Experience with antivirus, host-based intrusion prevention systems, host-based security systems, intrusion detection and prevention systems, full packet capture, and network forensics tools.
  • Experience or knowledge monitoring, defending, administering, or deploying cloud networks such as Amazon Web Services, Microsoft Azure, or Google Cloud Platform, including cloud-native security tools and strategies for protecting data in cloud environments and identifying and mitigating cloud-specific attacks.
  • Experience managing, defending, administering, or deploying enterprise mobile devices using iOS or Android, including mobile device management, mobile application management, and mobile threat defense.
  • Scripting and programming skills.

About the company

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A