Full-Time

Network Forensics Cybersecurity Analyst 2

Posted on 9/12/2024

Arsiem Corporation

Arsiem Corporation

11-50 employees

IT consulting and cybersecurity for governments

Consulting
Cybersecurity

Junior, Mid

Arlington, VA, USA

This position requires onsite presence in Arlington, VA.

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
Splunk
Requirements
  • BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 4-6 years of network investigations experience.
  • 2+ years of directly relevant experience in network investigations
  • In-depth knowledge of CND policies, procedures, and regulations
  • In-depth knowledge of TCP/IP protocols
  • In-depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
  • In-depth knowledge and experience of Wi-Fi networking
  • In-depth knowledge and experience of network topologies DMZs, WANs, etc.
  • Substantial knowledge of Splunk (or other SIEM’s)
  • Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
  • Knowledge of Computer Network Defense policies, procedures, and regulations
  • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
  • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Ability to identify and analyze anomalies in network traffic using metadata
  • Experience with reconstructing a malicious attack or activity based on network traffic
  • Experience examining network topologies to understand data flows through the network
  • Must be able to work collaboratively across physical locations
  • DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst
  • DoD 8140.01 GCIA, GCIH, CSSP Analyst/CSSP Incident Responder
  • DoD 8140.01 CEH, CSSP Analyst
  • SANS GIAC GNFA preferred
  • Active TS/SCI clearance and the ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability.
Responsibilities
  • Assists the Government lead in coordinating teams in preliminary incident response investigations
  • Assists the Government lead with interfacing with the customer while on-site
  • Determines appropriate courses of action in response to identified and analyses anomalous network activity
  • Assesses network topology and device configurations, identifying critical security concerns and providing security best practice recommendations
  • Assists with the writing and publishing of Computer Network Defense guidance and reports on incident findings to appropriate constituencies
  • Collects network intrusion artifacts (e.g., PCAP, domains, URIs, certificates, etc.) and uses discovered data to enable mitigation of potential Computer Network Defense incidents
  • Analyzes identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Collects network device integrity data and analyzes for signs of tampering or compromise
  • Assists with real-time CND incident handling (i.e., forensic collections, intrusion correlation, and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagements

ARSIEM Corporation provides advanced IT consulting services, specializing in multiple areas including cybersecurity, enterprise architecture and development, and applications development, predominantly for government clients. The firm is distinguished by its deep commitment to cybersecurity and robust IT solutions that ensure enhanced protection and efficient digital infrastructures. This commitment to leveraging cutting-edge technologies in specialized areas of IT makes ARSIEM Corporation an excellent workplace for professionals aiming to actively contribute to significant, high-impact projects within the government sector.

Company Stage

N/A

Total Funding

N/A

Headquarters

Baltimore, Maryland

Founded

2013

Growth & Insights
Headcount

6 month growth

22%

1 year growth

4%

2 year growth

22%
INACTIVE