Join Our Mission-Driven Team as a Cyber Network Defense Analyst (CNDA) with Cloud Forensics Expertise!
At Farfield Systems, we’ve proudly supported the government contracting community for over 23 years, focusing on work that truly matters for our customers' most critical missions. Our success stems from our unwavering commitment to our team members; we believe that when we prioritize our employees, they, in turn, create unparalleled satisfaction for our customers. This philosophy is encapsulated in our motto: “employee driven…customer focused.” We invite you to be part of our dynamic culture and contribute to meaningful work.
Position Overview:
We are on the lookout for passionate Cyber Network Defense Analysts (CNDA) with expertise in Cloud Forensics to join our dedicated team. In this role, you will play a crucial part in providing advanced technical assistance—both remotely and onsite. Your work will involve proactive threat hunting, rapid incident response, and thorough investigation and resolution of cybersecurity challenges, utilizing host-based, network-based, and cloud-based analysis capabilities.
Key Responsibilities:
- Perform forensic acquisition and analysis across on-premises and cloud platforms, including Entra ID/Azure AD, M365, AWS, GCP, and SaaS, to uncover compromise activities, persistence mechanisms, and data exfiltration.
- Investigate and respond to incidents and attacks that target cloud and hybrid identity environments.
- Analyze and correlate cloud control-plane events with network telemetry (such as Azure Activity Logs, AWS CloudTrail, and VPC Flow Logs) to reconstruct attacker timelines, validate Indicators of Compromise (IOCs), and identify post-compromise privilege escalations.
- Develop and implement detection logic and automation leveraging cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting languages (PowerShell, Python, Bash), while integrating threat intelligence feeds and indicators.
- Create comprehensive technical reports and incident documentation, offering containment recommendations that incorporate findings from cloud, identity, and endpoint investigations; assist in the development of incident response playbooks and procedures tailored for cloud and hybrid environments.
- Collaborate on cloud development and automation projects to refine threat emulation, investigative, and hunting capabilities.
- Work closely with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.
If you're ready to take on a challenge that directly contributes to our customers' missions and enhances your professional growth, we encourage you to apply. Join us at Farfield Systems, where your expertise will make a real difference!
Requirements:
Required Skills:
- U.S. Citizenship
- Active TS/SCI clearance
- Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
- 8+ years of experience in cyber forensic investigations with leading tools and techniques.
- Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.
- Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
- Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
- Knowledge of AWS, IAM, and best practices for cloud identity security.
Desired Skills:
- Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
- Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
- Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).
Required Education:
- BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 10+ years relevant experience.
Desired Certifications:
- GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS or Microsoft Cloud/Security certifications.
ECP-1 Position
Security Clearance Required: TS/SCI