- Identify gaps in malicious activity detection capabilities
- Create new signatures / rules to improve detection of malicious activity
- Test and tune existing signatures / rules to ensure low rate of false positives
- Assist in playbook development for alert triage and Incident Response
- Define and implement alert and threat detection metrics, statistics, and analytics
- Recommend new tools/technologies to improve network visibility
- Support Incident Response and Forensic operations as required to include static/dynamic malware analysis and reverse engineering
- Author and maintain scripts for threat detection and automation Basic Qualifications
- In-depth knowledge of Firewalls/Proxies/Intrusion Detection Systems/ Domain Name Servers/DHCP/VPN and other network technologies and tools
- Experience updating, maintaining, and creating IDS variables within a complex enterprise network
- Expert in creating, modifying, tuning IDS signatures/SIEM Correlation Searches/yara rules and/or other detection signatures
- Familiarity with disk based forensic methodologies, Windows, and Linux forensic artifacts
- Experience with Endpoint Detection and Response (EDR) tools such as Carbon Black, Tanium, Crowdstrike, etc
- Able to create, modify, update, and maintain Python and Powershell scripts that enhance endpoint detection capabilities
- In-depth knowledge of attacker tactics, techniques, and procedures
- Author, test, and maintain automation scripts within SOAR platform The candidate must currently possess a Secret Clearance. In addition to clearance requirement, all CBP personnel must have a current or be able to favorably pass a 5 year background investigation (BI).
BS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience.
-
Gridiron IT Solutions Ashburn, United StatesGridiron IT is seeking a Security Engineer local to Ashburn, VA with a active DHS CBP Tier 4 Public Trust or equivalent of DoD Secret and up. Gridiron IT is hiring a Security Engineer to support a federal customer located in Ashburn, VA. Two to three days will be working on site ...
-
Base One Technologies Ashburn, United StatesPrimary Responsibilities · The Cyber Security Engineer will support the full system engineering life-cycle, including requirements analysis, design, development, test, implementation, maintenance, integration, and documentation of SOC infrastructure and SOC tool suite. The Senior ...
-
Base One Technologies Ashburn, United StatesWork location: Ashburn VA · 222 - Senior Security Engineer Must Have One of the Following J3 Certifications Sr. Security Engineer: · CompTIA Advanced Security Practitioner (CASP) · GCIH – Incident Handler · GCWN – Windows Security Administrator · GISF – Security Fundamentals · GI ...
-
Base One Technologies Ashburn, United StatesOur Ashburn VA based client is looking for a Splunk Engineer. If you are interested in this opening. Please forward a copy of your updated resume in word format to Work location: Ashburn VA · 222 - Senior Security Engineer (CBP) Must Have One of the Following J3 Certifications Sr ...
-
Base One Technologies Ashburn, United StatesWork location: Ashburn VA · 222 – Senior Security Engineer Must Have One of the Following J3 Certifications Sr. Security Engineer: · CompTIA Advanced Security Practitioner (CASP) · GCIH – Incident Handler · GCWN – Windows Security Administrator · GISF – Security Fundamentals · GI ...
-
Intern - Cyber Security with Security Clearance
2 weeks ago
Telos Corporation Ashburn, VA, United StatesThe most security-conscious organizations trust Telos Corporation to protect their vital IT assets · The reputation of our company rests on the quality of our solutions and the integrity of our people · Explore what you can bring to our solutions in the areas of cyber, cloud and ...
-
VAT Analyst with Security Clearance
1 day ago
Base One Technologies Ashburn, United StatesPrimary Responsibilities · Perform research on current threats and vulnerabilities. Will be responsible for authoring security advisories. Manage enterprise vulnerability compliance and will conduct vulnerability assessments of IT systems. This position location is Ashburn, Virgi ...
-
Base One Technologies Ashburn, United StatesPrimary Responsibilities · Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies. · Perform web app pentests · Perform vulnerability risk assessment · Perform physical pentests and social engineering · Perform cyber inc ...
-
Systems Engineer with Security Clearance
1 day ago
Base One Technologies Ashburn, United StatesOur Ashburn VA based client is looking for a Systems Engineer. If you are qualified for this position, please email your updated resume in word format to Primary Responsibilities · Perform research on current threats and vulnerabilities. Will be responsible for authoring security ...
-
Anonymous Employer Ashburn, United StatesPrimary Responsibilities · • Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies. · • Perform web app pentests · • Perform vulnerability risk assessment · • Perform physical pentests and social engineering · • Perform ...
-
Splunk Engineer with Security Clearance
1 day ago
Anonymous Employer Ashburn, United StatesThe candidate should have experience deploying and configuring Universal Forwarders and possess demonstrable knowledge of data collection methods such as Syslog, JDBC, or API. This position requires solid experience developing Splunk search queries, and dashboards and reports. Ni ...
-
Splunk Engineers with Security Clearance
1 day ago
Base One Technologies Ashburn, United StatesOur Ashburn VA based client is looking for Splunk Engineers. All Applicants must be US CITIZENS with active Secret /Top Secret Clearance. If you are qualified for these openings, please forward a copy of your updated resume in word format to Work location: Ashburn VA Must Have On ...
-
Base One Technologies Ashburn, United StatesPrimary Responsibilities · • Identify gaps in malicious activity detection capabilities · • Create new signatures / rules to improve detection of malicious activity · • Test and tune existing signatures / rules to ensure low rate of false positives · • Assist in playbook developm ...
-
Penetration Tester with Security Clearance
2 weeks ago
Leidos Ashburn, United StatesYou will need to login · before you can apply for a job. · Penetration Tester with Security Clearance · R– Description The Leidos Digital Modernization Team is seeking a Penetration Tester to join the Enterprise Security Operations Center team. The Department of Homeland Securi ...
-
Splunk Engineer with Security Clearance
1 day ago
Base One Technologies Ashburn, United StatesOur Ashburn VA based client is looking for Splunk Engineers. If you are qualified for this position, please email your updated resume in word format to Primary Responsibilities · The candidate should be proficient with recognizing and on-boarding new data sources into Splunk, ana ...
-
Project Manager with Security Clearance
2 weeks ago
Agile Defense, Inc. Ashburn, VA, United StatesAt Agile Defense we know that action defines the outcome and new challenges require new solutions · That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next · Our vision is to bring adaptive innovation to sup ...
-
Cloud Architect with Security Clearance
2 weeks ago
Booz Allen Hamilton Ashburn, United StatesJob Number: R Cloud Architect · The Opportunity: Everyone is trying to "harness the cloud," but not everyone knows how. As a cloud computing application architect, you know how to create a cloud-based technical architecture that meets client needs and takes advantage of cloud cap ...
-
Georgian Linguist with Security Clearance
1 week ago
The KACE Company, LLC Ashburn, United StatesTITLE: Georgian Linguist LOCATION: Nationwide TDY; Ashburn, VA; El Paso, TX SCHEDULE: Varied About KACE: When you make the decision to join KACE, you are choosing to work alongside talented professionals that have one thing in common; the passion to make a difference KACE employe ...
-
Base One Technologies Ashburn, United StatesOur Ashburn VA based client is looking for a Detection Engineer. If you are qualified for this position. Please email me your updated resume in word format to Work location: Ashburn VA Detection Engineer · Primary Responsibilities · • Identify gaps in malicious activity detection ...
-
Splunk SME with Security Clearance
1 day ago
Base One Technologies Ashburn, United StatesPrimary Responsibilities · • The selected candidate will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk ...
Detection Engineer with Security Clearance - Ashburn, United States - Base One Technologies
Description
Required Education/ExperienceBS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience.
Should have 5 years of experience serving as a digital media Primary ResponsibilitiesAbility to work independently with minimal direction; self-starter/self-motivated Requirement Certifications
CCFP – Certified Cyber Forensics Professional
CHFI – Computer Hacking Forensic Investigator
CISSP – Certified Information Systems Security
ECSA – EC-Council Certified Security Analyst
EnCE
GCFA – Forensic Analyst
GCFE – Forensic Examiner
GCIH – Incident Handler
GISF – Security Fundamentals
GREM – Reverse Engineering Malware
GXPN – Exploit Researcher and Advanced Penetration Tester
LPT – Licensed Penetration Tester
OSCE (Certified Expert)
OSCP (Certified Professional)
OSEE (Exploitation Expert)
OSWP (Wireless Professional)
CIRC
FIWE
WFE-E-CI
FTK-WFE-FTK Preferred Qualifications
One of the following certifications:
SANS Global Information Assurance Certification (GIAC) Certified Intrusion Analyst (GCIA) SANS Global Information Assurance Certification (GIAC) Certified Forensic Analyst (GCFA)
SANS Global Information Assurance Certification (GIAC) Certified Network Forensic Analyst (GNFA)
Certified Information System Security Professional (CISSP)