2018441 CSA – Cyber Threat Analyst APT Hunt SME 195,000.00

B4CORP - Herndon, VA (30+ days ago)


Position Requires a Top Secret (TS/SCI) Clearance with a Polygraph.

Be the Guru of our elite team of Cyber Hunters who identify and defeat advanced persistent threats (APT’s) and analyze patterns to profile adversary groups to protect and defend the largest intelligence target in the world. Use your expertise of hunting out the Black Hats playbook and identify anomalies and develop scenarios based on real-world cyber threat intelligence and conduct analysis on the associated data sets. You will work with the detection and incident response teams to hunt for adversary behavior and based on findings, develop logic to operationalize future detection by the incident response function. This Herndon based position will be Monday – Friday with Core Hours. You will help protect our national security while working on innovative projects that offer opportunities for advancement.

Responsibilities include, but are not limited to:
Clearance Level: Top Secret SCI++

The CIRT Cyber Threat/APT Hunt Subject Matter Expert (SME) on this Agency-level Cyber Security Operations and Engineering support contract develops and implements an APT Hunt capability for the Government. The selected candidate shall have experience with host-based and network-based APT related commercial technologies.

Duties include but are not limited to:
  • Construct and exploit threat intelligence to detect, respond, and defeat advanced persistent threats (APTs)
  • Fully analyze network and host activity in successful and unsuccessful intrusions by advanced attackers
  • Piece together intrusion campaigns, threat actors, and nation-state organizations
  • Manage, share, and receive intelligence on APT adversary groups
  • Generate intelligence from their own data sources and share it accordingly
  • Identify, extract, and leverage intelligence from APT intrusions
  • Expand upon existing intelligence to build profiles of adversary groups
  • Leverage intelligence to better defend against and respond to future intrusions.
  • Conduct advanced threat hunt operations using known adversary tactics, techniques and procedures as well as indicators of attack in order to detect adversaries with persistent access to the enterprise.
  • Create and add custom signatures, to mitigate highly dynamic threats to the enterprise using the latest threat information obtained from multiple sources
  • Conduct initial dynamic malware analysis on samples obtained during the course of an investigation or hunt operation in order to create custom signatures
  • Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues. Reports shall be produced on a daily, weekly, monthly, and quarterly basis capturing and highlighting status, preparedness, and significant issues.
  • Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs.
  • Notify the management team of significant changes in the security threat against the government networks in a timely manner and in writing via established reporting methods.
  • Coordinate with appropriate organizations within the intelligence community regarding possible security incidents. Conduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contact.
  • Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event
  • Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary
Estimated Salary:
Position Level: Level 2 – Expert
Salary Range: 195,000.00 to 140,000.00

B4Corp Estimated Salary Ranges:
Position Level Max Salary Min Salary
Level 1 – Subject Matter Expert $215,000 $160,000
Level 2 – Expert $195,000 $140,000
Level 3 – Senior $170,000 $110,000
Level 4 – Full Performance $100,000 $60,000

Mandatory Requirements:
Required Experience/SKills:
  • Excellent interpersonal, organizational, writing, communications, and briefing skills
  • Strong analytical and problem solving skills
  • Demonstrated experience working APT-level intrusion sets
  • Minimum of 10 years of progressively responsible experience in Cyber Security, InfoSec, Security Engineering, Network Engineering with emphasis in cyber security issues and operations, computer incident response, systems architecture, data management
Required Tools:
Familiarity with the following classes of enterprise cyber defense technologies:

  • Security Information and Event Management (SIEM) systems
  • Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)
  • Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)
  • Network and Host malware detection and prevention
  • Network and Host forensic applications
  • Web/Email gateway security technologies
Required Certifications:
CISSP or CEH
IAT Level III or CND-SPM

Required Degree:
BS (bachelor’s degree in electrical engineering, computer engineering, computer science, or other closely related IT discipline)

Security Requirements:
TS/SCI with Poly

Optional Requirements:
B4CORP Company Information

B4Corp is a small defense contracting company that focuses on providing an optimum environment for mission-focused, highly-skilled consultants to support the United States of America’s intelligence community and other defense organizations. B4Corp provides a low overhead, highly efficient, high salary environment that allows employees to excel at meeting the client’s needs. B4Corp is looking for information technology professionals that have a high sense of personal responsibility, self-motivation, and mission drive.

B4Corp’s dedication and care for its employees is reflected in the outstanding compensation and benefits B4Corp provides. Our salaries are second to none. B4Corp’s benefits reflect the company’s policy of putting the employees first. Our health insurance demonstrates this with 100% employer coverage and providing employees with a plan that has $0 copay, 0% coinsurance and an HSA that can allow employees to accrue health savings for the future. B4Corp’s maximum flexibility comp / makeup time policy, along with the company’s cafeteria-style benefit plan that allows employees to maximize their benefit dollars, reflects B4Corp’s commitment to its employees.

Compensation:
Outstanding Salaries

Retirement:
Full Vanguard 401k Plan – Featuring a full scope of investment options
– 100% employer matched contribution up to 6% of employee’s salary
– Ability to max out 401k savings ($55,000 per year / $61,000 if over 50)
Employees receive B4Corp phantom stock each year (2-year vesting period)

Insurance 100% Employer-Paid Premiums:
United Health Care Choice Plus HSA POS Gold 1500 w/HSA
– Employer funded HSA to cover 100% health care deductible
– Health insurance: $0 copay, $0 co-insurance. Full scope protection for you and your family!
– 100% employer premium coverage for single and family
Health Equity HSA – B4Corp contributes $1500.00 for single and $3000.00 for family into your Health Equity HSA to cover 100% of your health care deductible.
Mutual of Omaha Dental VSP Vision Insurance Mutual of Omaha short-term disability (60% of salary up to $2,000.00/week)
Mutual of Omaha long-term disability (60% of salary up to $10,000.00/month)
Mutual of Omaha life insurance ($200,000.00)

Employee Referral Bonus:
Refer a friend or a coworker and receive $2,000 per year for every year the person works for B4CORP

Paid Time Off (PTO):
Seven weeks of leave per year (including ten federal holidays)
Ability to purchase 2 additional weeks of vacation
Flexible work schedule with comp time (with customer approval)

Tuition and Training:
Free CBTNuggets Online Training Account
– More than 200 online IT courses on a large variety of topics, including networking, security, virtualization, and the cloud — from trusted vendors such as Cisco, Microsoft, and Google.
– Train anytime, anywhere, and on a variety of devices – even offline!
– Transcender® Practice Exams
– Virtual Labs
Free L inux Academy Online Training Account
Internal Tracking -G96484