These positions do not require a security clearance!
Let's make a positive impact on U.S. National Security!
We are building a World-Class, Cyber Incident Response team - want to be a part of it?
We are bringing cyber defensive measures to the U.S. government, in various organizations.
SecureTech Cyber Defense Analysts make a difference every day. Our Cyber Defense Analyst:
- Uses cyber defense tools to monitor, detect, analyze, categorize, and perform initial triage of anomalous activity.
- Generates cybersecurity event cases (including event’s history, status, and potential impact for further action) and route as appropriate.
- Leverages knowledge of commonly used network protocols and detection methods to defend against related abuses.
- Applies cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Identifies, triages, and reports events that occur in order to protect data, information systems, and infrastructure.
- Conducts analysis to isolate indicators of compromise.
- Finds trends, patterns, or anomaly correlations utilizing security-relevant data.
- Recommends proactive security measures.
- Notifies designated managers, cyber incident responders, and cybersecurity service provider team members of suspected cyber incidents and articulates the event’s history, status, and potential impact for further action in accordance with the organization’s cyber incident response plan.
- Assists in enterprise incident response, threat containment, forensic analysis, and restoration of system security posture.
- Conducts Incident Response in accordance with established procedure.
- Collects intrusion artifacts (e.g., source code, malware,etc.) and correlates incident data to identify specific vulnerabilities.
- Uses discovered data to make recommendations for remediation and enable mitigation of potential future incidents.
- Coordinates with other Enterprise Computer Network Defense organizations/representative as required.
Among other tasks required to make the customer's mission successful!
As a SecureTech Cyber Defense Analyst these are the types of skills and capabilities you might use!
- Use cyber defense tools to monitor, detect, analyze, categorize, and perform initial triage of anomalous activity.
- Generate cybersecurity cases (including event’s history, status, and potential impact for further action) and route as appropriate.
- Leverage knowledge of commonly used network protocols and detection methods to defend against related abuses.
- Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Perform advanced manual analysis to hunt previously unidentified threats.
- Conduct PCAP analysis.
- Identify cyber-attack phases based on knowledge of common attack vectors and network layers, models and protocols.
- Apply techniques for detecting host- and network-based intrusions.
- Working knowledge of enterprise-level network intrusion detection/prevention systems and firewall capabilities.
- Understand the foundations of a hardened windows network and what native services and protocols are subject to abuse (such as RDP, Kerberos, NTLM, WMI, and SMB).
- Familiarity with fragmentation of network traffic and how to detect and evaluate fragmentation related attacks in raw packet captures.
- Conduct network – traffic, protocol and packet-level – and netflow analysis for anomalous values that may be security-relevant using appropriate tools (such as Wireshark, tshark, tcpdump).
- Understand snort filters and how they are crafted and tuned to feed IDS alerting.
- Understand system and application security threats and vulnerabilities to include buffer overflow, SQL injection, race conditions, covert channel, replay and return-oriented attacks, malicious code and malicious scripting.
- Analyze malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
- Familiar with indications of Command and Control (C2) channels and what strategies attackers use to bypass enterprise defenses from a compromised host.
We have multiple levels of opportunity here! We are looking for early career, through the most senior levels of experience.
While entry level requires a BS degree and only two years of IT related experience (or a HS diploma plus six years), with Cybersecurity certification desired, but not required - the highest level requires the BS degree plus ten years of experience (or a HS diploma plus fourteen years), with significant certification required. And we need everything in between!
Don't have cybersecurity certification? Apply anyway! We can work with you!
Why come to the SecureTech family?
- We really do consider employees first in decisions. It is hard enough to work through the personal/social/technical hurdles that come with your position as a cleared defense contractor - no need to fight your own employer's red tape as well.
- We offer a compensation package that is more than just commensurate with this closed contractor community. We offer generous benefits (PTO, training support, etc) in addition to the high salaries. We know that you know - salary isn't everything.
- SecureTech is an Equal Opportunity Employer – we hire the right people for the job - regardless of employment status such as female, minority, protected veterans, individuals with disabilities, etc.
Our concern is that you are qualified for the position, and that you are placed in a position in which you can be successful!
Apply now!
Multiple positions are awaiting your expertise!
Or send resume to [email protected]