Sr. Threat Hunter with Security Clearance

4 weeks ago


Arlington, United States Base One Technologies Full time
Our client is seeking Cyber Forensics Analysts to support the Govt Hunt and Incident Response Team. This team secures the Nation’s cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission. Responsibilities:
• Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations • Collects network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and uses discovered data to enable mitigation of potential incidents
• Collects network device integrity data and analyze for signs of tampering or compromise - Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information - Tracking and documenting on-site incident response activities and providing updates to leadership through executive summaries and in-depth technical reports • Planning, coordinating and directing the inventory, examination and comprehensive technical analysis of computer related evidence • Serving as technical forensics liaison to stakeholders and explaining investigation details Required Skills: • U.S. Citizenship - Must have an active Secret clearance (TS/SCI eligible) and be able to obtain DHS Suitability • 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools
• Experience with reconstructing a malicious attack or activity • Ability to characterize and analyze network traffic, identify anomalous activity / potential threats, analyze anomalies in network traffic using metadata
• Ability to create forensically sound duplicates of evidence (forensic images) • Able to write cyber investigative reports documenting forensics findings • In depth knowledge and experience of identifying different classes and characterization of attacks and attack stages CND policies, procedures and regulations proactive analysis of systems and networks, to include creating trust levels of critical resources • system and application security threats and vulnerabilities of network topologies, Wi-Fi Networking, and TCP/IP protocols
• Splunk (or other SIEMs) • Vulnerability scanning, assessment and monitoring tools such as Security Center, Nessus, and Endgame MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
• Must be able to work collaboratively across physical locations. Desired Skills: Experience and proficiency with the following tools and techniques:
EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort EDR Tools: Crowdstrike, Carbon Black, Etc Carving and extracting information from PCAP data
Non-traditional network traffic: Command and Control
Preserving evidence integrity according to national standards Designing cyber security systems and environments in a Linux environment Virtualized environments Conducting all-source research Required Education: 8+ years of experience and BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience Desired Certifications:
GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFA
  • Cyber Threat Hunter

    7 days ago


    Arlington, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a Cyber Threat Hunter SME to support The Department of Homeland Security (DHS) Hunt and Incident Response Team (HIRT). DHS HIRT secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front-line response for cyber incidents and proactively hunting for malicious cyber activity. Gray Tier...


  • Arlington, United States Cherokee Federal Full time

    Mid Threat Manager ***This position requires an active TS/SCI security clearance to be considered. *** Cherokee Insights is seeking qualified individuals to serve as Threat Managers at the mid-level in support of the Behavioral Threat Analysis Center. The Threat Manager will support threat assessments with reviewing, identifying, and developing specific...


  • Arlington, United States Redhorse Corporation Full time

    About the Organization Now is a great time to join Redhorse Corporation. Redhorse specializes in developing and implementing creative strategies and solutions with private, state, and federal customers in the areas of cultural and environmental resources services, climate and energy change, information technology, and intelligence services. We are hiring...


  • Arlington, United States Gridiron IT Solutions Full time

    Seeking a Targeting Threat Analyst (China) local to the DC Metro area. Active TopSecret Clearance required!** Must be able to obtain SCI CI Polygraph Required: Bachelor’s degree required Active Top Secret Clearance required with the ability to obtain SCI with CI PolyPrior experience supporting a variety of core analytical tasks3 years experience conducting...


  • Arlington, United States Agile Defense, Inc. Full time

    At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of...


  • Arlington, United States Arsiem Corporation Full time

    ARSIEM is seeking a senior Cyber Threat Hunter. Responsibilities:- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack- Assesses network topology and device configurations identifying critical security concerns and providing...


  • Arlington, United States BCMC Full time

    Job DescriptionJob DescriptionBCMC is supporting a U.S. Government customer on a large mission critical development and sustainment program to design, build, deliver, and operate a network operations environment including introducing new cyber capabilities to address emerging threats.We are seeking a Sr. Cyber Security Subject Matter Expert (SME) who can...

  • Mid Threat Manager

    3 weeks ago


    Arlington, United States Cherokee Nation Businesses Full time

    Job DescriptionMid Threat Manager ***This position requires an active TS/SCI security clearance to be considered. *** Cherokee Insights is seeking qualified individuals to serve as Threat Managers at the mid-level in support of the Behavioral Threat Analysis Center. The Threat Manager will support threat assessments with reviewing, identifying, and...


  • Arlington, United States ASRC Federal Holding Company Full time

    Job Description ASRC Federal Professional Services is seeking a dynamic self-starter with experience in Insider Threat Security (IntSEC) discipline to support the Pentagon's Joint Service Security Office (JSSO). As part of its IntSEC mission, the Joint Staff Security Office is responsible for theestablishing an Insider Threat Program (InTP) to identify and...


  • Arlington, United States SAIC Full time

    Description SAIC is seeking a Traveling Security Specialist in Arlington, VA. Primary responsibility will be to provide comprehensive training and guidance to Army National Guard (ARNG) personnel across different locations. Expertise will play a crucial role in enhancing security awareness and compliance with new ARNG policies. Job Duties: Information...


  • Arlington, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is seeking a Threat Detection Engineer for a new customer on a highly-visible and strategic Cybersecurity Task Order. The Threat Detection Engineer will: Capture use cases from subscribers or other team members and develop correlation rules Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for...

  • Cyber Threat Analyst

    1 month ago


    Arlington, United States Node.Digital Full time

    Job DescriptionJob DescriptionCyber Threat AnalystLocation: Arlington, VAMust have Top Secret ClearanceNode is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel...


  • Arlington, United States Node.Digital Full time

    Cyber Threat AnalystLocation: Arlington, VAMust have Top Secret Clearance Node is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to...


  • Arlington, United States Node.Digital Full time

    Node.Digital Market leader in Digital Transformation & Automation using Artificial Intelligence and Machine Learning View company page Node is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and...


  • Arlington, United States GCyber Full time

    GCyber is currently seeking a highly skilled Rapid Response Sr. Network Engineer to lead our team in the development, maintenance, and enhancement of our network infrastructure within a dynamic and complex DoD environment. The ideal candidate will possess a deep understanding of network engineering principles, coupled with a proactive approach to...


  • Arlington, United States Base One Technologies Full time

    Primary Responsibilities:• Lead, manage, and understand the entire endpoint security lifecycle: obtain visibility, minimize surface area of attack, prevent and detect threats, investigate and respond, and remediate• Deploying, configuring, operating, monitoring, tuning, upgrading, and troubleshooting endpoint security tools• Collaborate, guide, and...


  • Arlington, United States SAIC Full time

    Description Cyber SME Description Cyber Subject Matter Expert (SME) with strong knowledge and experience with Department of Defense and Intelligence Community practices in protecting National Security. This Cyber SME will be immersed into a fast - paced, deadline-oriented environment composed of a diverse team of analysts, linguists, cultural experts, and...


  • Arlington, United States Nine Mind Solutions Full time

    We are looking for Cyber Threat Analyst to support this critical customer mission. Shift Work: Saturday & Sunday 0600-1830; plus two 8-hour shifts during the work week Eligibility: Must be a US Citizen Must have an active TS/SCI clearance Must be able to obtain Client Entry on Duty (EOD) Suitability prior to onboarding Must have 2+ years of directly...


  • Arlington, United States Base One Technologies Full time

    Incident Manager - II Responsibilities:- Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise- Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate...


  • Arlington, United States Base One Technologies Full time

    Responsibilities:• Correlating incident data to identify specific trends in reported incidents• Recommending defense in depth principles and practices (i.e. Defense in Multiple Places, layered defenses, security robustness, etc.) • Performing Computer Network Defense incident triage to include determining scope, urgency, and potential impact•...