Host Based Systems Analyst SME

4 weeks ago


Arlington, United States Gray Tier Technologies LLC Full time

Gray Tier Technologies is looking for a Cyber Forensics Analysts to support the DHS Hunt and Incident Response Team (HIRT). This team secures the Nation’s cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. Our team performs HIRT investigations to develop a diagnosis of the severity of breaches. Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission.

Responsibilities: - Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack - Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations - Collects network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and uses discovered data to enable mitigation of potential incidents - Collects network device integrity data and analyze for signs of tampering or compromise - Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information - Tracking and documenting on-site incident response activities and providing updates to leadership through executive summaries and in-depth technical reports - Planning, coordinating and directing the inventory, examination and comprehensive technical analysis of computer related evidence - Serving as technical forensics liaison to stakeholders and explaining investigation details

Required Skills: - U.S. Citizenship - Active DoD Secret clearance. Must be able to obtain a TS/SCI clearance. - Must be able to obtain DHS Suitability - 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools - Experience leading cross functional teams conducting cyber threat hunting activities - Experience with reconstructing a malicious attack or activity - Ability to characterize and analyze network traffic, identify anomalous activity / potential threats, analyze anomalies in network traffic using metadata - Ability to create forensically sound duplicates of evidence (forensic images) - Able to write cyber investigative reports documenting forensics findings - In depth knowledge and experience of: • utilizing COTS and custom developed tools to detect APT activity • reviewing threat reports and searching the network for applicable IOC (Indicators of Compromise) • identifying different classes and characterization of attacks and attack stages • CND policies, procedures and regulations • of network topologies, Wi-Fi Networking, and TCP/IP protocols • Splunk (or other SIEMs) • Vulnerability scanning, assessment and monitoring tools such as Security Center, Nessus, and Endgame • MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK) - Must be able to work collaboratively across physical locations.

Desired Skills: - Experience and proficiency with the following tools and techniques: • EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort • EDR Tools: Crowdstrike, Carbon Black, Etc • Carving and extracting information from PCAP data • Non-traditional network traffic: Command and Control • Preserving evidence integrity according to national standards • Designing cyber security systems and environments in a Linux environment • Virtualized environments • Conducting all-source research

Required Education: BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience.

Desired Certifications: - GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFA On-Site work 2-3 days per week

#J-18808-Ljbffr



  • Arlington, United States Base One Technologies Full time

    Host Based Systems Analyst - IV -HBA04 - SME High Priority Apply Location Arlington, VA Hybrid Posted May 1, 2023 Host Based Systems Analyst - IV -HBA04 - SME High Priority Responsibilities: - Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness...


  • Arlington, United States RadiantHire Solutions, Inc. Full time

    Host Based Systems Analyst - IV The DHS’s Hunt and Incident Response Team (HIRT) secures the Nation’s cyber and communications infrastructure. HIRT provides DHS’s front line response for cyber incidents and proactively hunting for malicious cyber activity. Our client as a prime contractor to DHS, performs HIRT investigations to develop a preliminary...


  • Arlington, United States Node.Digital Full time

    Job DescriptionJob DescriptionHost Forensics Analysts/Host Based Systems AnalystLocation: Arlington, VAMust have Top Secret Security ClearanceNode provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis...


  • Arlington, United States Argo Cyber Systems Full time

    The DHS's Hunt and Incident Response Team (HIRT) secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front line response for cyber incidents and proactively hunting for malicious cyber activity. Argo Cyber Systems is a key partner to DHS, and performs HIRT investigations to develop a preliminary diagnosis of the severity of...


  • Arlington, United States Argo Cyber Systems Full time

    Job DescriptionJob DescriptionThe DHS's Hunt and Incident Response Team (HIRT) secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front line response for cyber incidents and proactively hunting for malicious cyber activity. Argo Cyber Systems is a key partner to DHS, and performs HIRT investigations to develop a...


  • Arlington, United States Node Full time

    Host-Based Systems Analyst Location: Arlington, VA Must have an active Top Secret Security Clearance Node provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based, and cloud-based cybersecurity analysis capabilities. Team personnel...


  • Arlington, United States Gray Tier Technologies LLC Full time

    Gray Tier Technologies is looking for a Cyber Forensics Analysts to support the DHS Hunt and Incident Response Team (HIRT). This team secures the Nation's cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. Our team performs HIRT investigations to develop a diagnosis of the...


  • Arlington, United States Node.Digital Full time

    Job DescriptionJob DescriptionHost-Based Systems Analyst Location: Arlington, VAMust have an active Top Secret Security ClearanceNode provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based, and cloud-based cybersecurity analysis...


  • Arlington, United States Fusion Technology Full time

    Who are you? Trusted Employee: The Government trusts you and so do we. You possess an active Top Secret security clearance. You must also be able to obtain Department of Homeland Security (DHS) suitability. Threat Expert: You have experience with proper evidence handling procedures and chain of custody protocols. You are skilled in identifying...


  • Arlington, Virginia, United States Node.Digital Full time

    Host-Based Systems Analyst Location: Arlington, VA Must have an active Top Secret Security Clearance Node provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based, and cloud-based cybersecurity analysis capabilities. Team...


  • Arlington, United States Solutions³ LLC Full time

    Job DescriptionJob DescriptionHost Based Systems Analyst - IV -HBA04The DHS’s Hunt and Incident Response Team (HIRT) secures the Nation’s cyber and communications infrastructure. HIRT provides DHS’s front line response for cyber incidents and proactively hunting for malicious cyber activity. Solutions3 Technologies (RTX), as a prime contractor to DHS,...


  • Arlington, United States ARGO Cyber Systems, LLC Full time

    The DHS's Hunt and Incident Response Team (HIRT) secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front line response for cyber incidents and proactively hunting for malicious cyber activity. Argo Cyber Systems is a key partner to DHS, and performs HIRT investigations to develop a preliminary diagnosis of the severity of...


  • Arlington, United States Anonymous Employer Full time

    Our Arlington VA based client is looking for Host Based Systems Analyst . If you are qualified for this position, please email your updated resume in word format to This position will require physical presence in the National Capital Region (NCR) for at least 3 weeks for training and orientation. Subsequent work will be primarily supported outside the NCR...


  • Arlington, United States Node.Digital Full time

    Host-based Systems Analyst /Senior SOC AnalystLocation: Arlington, VAMust have an active Secret Security ClearanceNode provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities. Contract...


  • Arlington, United States Node.Digital Full time

    Job DescriptionJob DescriptionHost-based Systems Analyst /Senior SOC AnalystLocation: Arlington, VAMust have an active Secret Security ClearanceNode provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis...


  • Arlington, United States Anonymous Employer Full time

    Our Arlington VA based client is looking for Host Based Systems Analyst. If you are qualified for this position, please email your updated resume in word format to Responsibilities: • Assists with leading and coordinating forensic teams in preliminary investigations• Plans, coordinates and directs the inventory, examination and comprehensive technical...


  • Arlington, United States Anonymous Employer Full time

    Our Arlington VA based client is looking for Host Based Systems Analyst. If you are qualified for this position, please email your updated resume in word format to Responsibilities: • Assists with leading and coordinating forensic teams in preliminary investigations• Plans, coordinates and directs the inventory, examination and comprehensive technical...


  • Arlington, United States Solutions³ LLC Full time

    Job DescriptionJob DescriptionHost Based Systems Analyst - IV -HBA04The DHS’s Hunt and Incident Response Team (HIRT) secures the Nation’s cyber and communications infrastructure. HIRT provides DHS’s front line response for cyber incidents and proactively hunting for malicious cyber activity. Solutions3, as a prime contractor to DHS, performs HIRT...


  • Arlington, United States Solutions³ LLC Full time

    Job DescriptionJob DescriptionHost Based Systems Analyst - IV -HBA04The DHS’s Hunt and Incident Response Team (HIRT) secures the Nation’s cyber and communications infrastructure. HIRT provides DHS’s front line response for cyber incidents and proactively hunting for malicious cyber activity. Solutions3, as a prime contractor to DHS, performs HIRT...


  • Arlington, United States Base One Technologies Full time

    Our Arlington VA based client is looking for a Host Based Systems Analyst Level II. If you are qualified for this position, please email your updated resume in word format to Working location: Arlington VA Host Based Systems Analyst Level IISecurity ClearanceActive Top Secret w SCI Core Competencies:Uses leading edge technology and industry standard...