- Acquire/collect computer artifacts and logs in support of onsite and remote engagements
- Triage electronic devices and assess evidentiary value
- Correlate forensic findings to network events in support of developing an intrusion narrative
- Collect and document system state information (e.g. running processes, network connections) prior to imaging, as required
- Perform forensic triage of an incident to include determining scope, urgency and potential impact
- Track and document forensic analysis from initial participation through resolution
- Collect, process, preserve, analyze and present computer related evidence
- Coordinate with Government staff and customer personnel to validate/investigate alerts or additional preliminary findings
- Conduct analysis of forensic images, and available evidence in support of forensic write-ups for inclusion in reports and written products
- Support cloud development and automation projects to enhance threat emulation capabilities
- Assist to document Computer Network Defense (CND) guidance and create reports pertaining to incident findings
- U.S. Citizenship - Active TS/SCI clearance
- Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
- 10+ years of direct relevant experience in cyber forensic investigations using leading edge technologies and industry standard forensic tools
- In depth understanding of SaaS, PaaS and IaaS in the Cloud Environment
- Ability to create forensically sound duplicates of evidence (forensic images)
- Ability to author cyber investigative reports documenting digital forensics findings
- Proficiency with analysis and characterization of cyber attacks
- Knowledge of cloud development and automation tools such as Terraform, Kubernetes, AWS CloudFormation, Azure Resource Manager, and Docker.
- Skilled in identifying different classes of attacks and attack stages
- Understanding of system and application security threats and vulnerabilities
- Understanding of proactive analysis of systems and networks, to include creating trust levels of critical resources
- Knowledge of strategies/architectures involved in implementing M365/Azure authentication, how these relate to a federated identity solution, and a fundamental understanding of how threat actors would target identity to compromise an environment
- Advanced experience and proficiency across various aspects of IT operations (e.g. networking, virtualization, identity, security, business continuity, disaster recovery, data management, governance)
- Experience and understanding in acquisition, processing and analysis of digital evidence from onsite enterprises and cloud native platforms
- Fundamental understanding of APIs and proficiency with PowerShell/PowerShell modules leveraged to conduct API queries as they relate to Azure/M365
- Proficiency with scripting languages (e.g. Bash, Python, PowerShell, JS) for automation of hunt tools used in commercial cloud environments
- Ability to develop tools, architecture and configurations in Azure environment to support identifying threat actor activity.
- Understanding of how Azure/M365 platform protection is implemented and security operations available
-
Defense Analyst
1 week ago
US Congressional Budget Office Washington, United States**Duties**: · The following are among the analyst's responsibilities: · - Prepare multiyear spending projections for veterans' health care benefits and for facilities of the Department of Veterans Affairs; · - Prepare cost estimates for legislation involving changes to veterans' ...
-
Cyber Network Defense Analysts
1 week ago
BCMC Arlington, United StatesBCMC provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line resp ...
-
Osd Program Analyst-missile Defense
1 week ago
Systems Planning and Analysis, Inc. Arlington, United StatesOverview: · Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US ...
-
Cyber Network Defense Analyst Ii
3 weeks ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Hybrid · You have been redirected to RTX's career page as we have recently transit ...
-
Cyber Network Defense Analyst Iii
2 weeks ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Onsite · You have been redirected to RTX's career page as we have recently transit ...
-
Booz Allen Arlington, United StatesDefense Program Analyst and Executive Assistant · **The Opportunity**: · As a project management specialist, you know the complexities of supporting a project from concept to completion. Many programs require a significant investment of limited resources, and it's imperative to k ...
-
Defensive Cyber Operations Analyst
2 weeks ago
Leidos Washington, United States**Description** · Leidos currently has an opening on our Defense Cyber Operations team based at Joint Base Anacostia-Bolling in Washington, DC. Our team supports our customer's (WHCA) mission to protect the Presidential Information Technology Community networked systems and servi ...
-
Cbrn Defense Modernization Analyst
1 week ago
Versar, Inc. Washington, United States**Who We Are**: · **What You'll Do**: · - Position will operate within the AF/A4C. · - Responsible to AF/A4CX for developing and advocating for DAF capability needs into all CBRN Defense Science and Technology initiatives under AF/A4C program management oversight. · - Analyze CBR ...
-
Cyber Network Defense Analyst Iii
3 weeks ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Hybrid · You have been redirected to RTX's career page as we have recently transit ...
-
Booz Allen Washington, United StatesDefense Communications and Congressional Analyst, Mid · **Key Role**: · Provide a DoD or Navy client with communications and Congressional support throughout the annual Defense Authorization and Appropriations process. Leverage existing Planning, Programming, Budgeting, and Execu ...
-
Cyber Network Defense Analyst Ii
3 days ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Onsite · You have been redirected to RTX's career page as we have recently transit ...
-
Defensive Cyber Operations Analyst
1 day ago
Leidos Washington, United States**Description** · Leidos currently has an opening on our Defense Cyber Operations team based at Joint Base Anacostia-Bolling in Washington, DC. Our team supports our customer's (WHCA) mission to protect the Presidential Information Technology Community networked systems and servi ...
-
Cyber Network Defense Analyst Iv Ap
2 weeks ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Onsite · You have been redirected to RTX's career page as we have recently transit ...
-
Cyber Network Defense Analyst Iv Ap
3 weeks ago
Raytheon Arlington, United States**Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA · **Position Role Type**: · Hybrid · You have been redirected to RTX's career page as we have recently transit ...
-
Cyber Network Defense Analyst Ii
1 week ago
Dhara Consulting Group Arlington, United StatesToday · - Dept of Homeland Security · - Unspecified · - Unspecified · - IT - Hardware · - Arlington, VA** (ON-SITE/OFFICE)** · **Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlingto ...
-
Cyber Network Defense Analyst Iv Ap
1 week ago
Dhara Consulting Group Arlington, United StatesToday · - Dept of Homeland Security · - Unspecified · - Unspecified · - IT - Hardware · - Arlington, VA** (ON-SITE/OFFICE)** · **Date Posted**: · **Country**: · United States of America · **Location**: · VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlingto ...
-
Houlihan Lokey Washington, United StatesBusiness Unit: · Corporate Finance · Industry: · ADG - Aerospace, Defense & Gov · Overview · Houlihan Lokey (NYSE:HLI) is a global investment bank with expertise in mergers and acquisitions, capital markets, financial restructuring, and financial and valuation advisory. The firm ...
-
Daf Cbrn Defense Readiness Analyst
1 week ago
Versar, Inc. Washington, United States**Who We Are**: · **What You'll Do**: · - Position will operate within the AF/A4C. · - Responsible to AF/A4CX to analyze and report status of installation CBRN Defense readiness. Requires access to Management Internal Control Toolkit (MICT), Automated Readiness Information System ...
-
Daf Cbrn Defense Training Analyst
1 week ago
Versar, Inc. Washington, United States**Who We Are**: · **What You'll Do**: · - Position will operate within the AF/A4C. · - Responsible to AF/A4CX to analyze threat, MICT, ARIS, DRRS, LL, IGEMS, and exercise data and make recommendations to the AF/A4C Career Field Managers (CFMs) on CE training. · - Directly support ...
-
Defense Analyst
2 weeks ago
Booz Allen Hamilton Washington, United States Full timeJob Number: R0191225 · Defense AnalystThe Opportunity: · As a defense mission professional, you understand the nuances of complex situations. You use your skills to think bigger and push further, solving complex problems. We're looking for someone like you to help create solutio ...
Cyber Network Defense Analyst - Arlington, United States - Gray Tier Technologies LLC
Description
Gray Tier Technologies is seeking Cyber Network Defense Analysts (CNDA) with Cloud Forensicsexperience to support this critical customer mission.
Our team provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities.
Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity.
Responsibilities:
Desired Certifications: - One or more of the following certifications: GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS certifications, Microsoft Azure associated certifications.