Cyber Defense Analyst IV

6 days ago


Arlington, Virginia, United States Nightwing Full time
About Nightwing

Nightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence support services to the U.S. government. With a rich history of delivering technically advanced solutions, we continue to shape the future of cybersecurity and intelligence.

Job Summary

We are seeking a highly skilled Cybersecurity Threat Hunter IV to join our team. As a key member of our Cyber Defense team, you will be responsible for identifying and mitigating cyber threats, conducting forensic analysis, and providing expert guidance to our customers.

Responsibilities
  • Acquire and collect computer artifacts in support of onsite engagements
  • Triage electronic devices and assess evidentiary value
  • Correlate forensic findings to network events in support of developing an intrusion narrative
  • Collect and document system state information prior to imaging, as required
  • Perform forensic triage of an incident to include determining scope, urgency, and potential impact
  • Track and document forensic analysis from initial participation through resolution
  • Collect, process, preserve, analyze, and present computer-related evidence
  • Coordinate with Government staff and customer personnel to validate/investigate alerts or additional preliminary findings
  • Conduct analysis of forensic images and available evidence in support of forensic write-ups for inclusion in reports and written products
  • Evaluate, extract, and analyze suspected malicious code
  • Assist in documenting and publishing Computer Network Defense (CND) guidance and reports pertaining to incident findings
  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Coordinate with enterprise-wide cyber defense staff to validate network alerts
  • Perform management duties as required to support the team, projects, and analysts
  • Document and escalate incidents, including event history, status, and potential impact for further action
  • Perform cyber defense trend analysis and reporting
  • Perform event correlation using information gathered from various sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
  • Provide daily summary reports of network events and activity relevant to cyber defense practices
  • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of alerts
  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
  • Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity
  • Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Identify and analyze anomalies in network traffic using metadata
  • Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools
  • Identify applications and operating systems of a network device based on network traffic
  • Reconstruct a malicious attack or activity based on network traffic
  • Identify network mapping and operating system (OS) fingerprinting activities
  • Assist in the construction of signatures that can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave
Requirements
  • U.S. Citizenship
  • Active TS/SCI clearance
  • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
  • 8+ years of direct relevant experience in cyber defense analysis using leading-edge technologies and industry-standard cyber defense tools
  • Ability to create forensically sound duplicates of evidence (forensic images)
  • Ability to author cyber investigative reports documenting digital forensics findings
  • Proficiency with analysis and characterization of cyber attacks
  • Skilled in identifying different classes of attacks and attack stages
  • Understanding of system and application security threats and vulnerabilities
  • Understanding of proactive analysis of systems and networks, to include creating trust levels of critical resources
  • Able to work collaboratively across physical locations
  • Action-oriented and have a proactive approach to problem-solving
  • Proficiency with common operating systems (e.g., Linux/Unix, Windows)
Desired Skills
  • Understanding of SaaS, PaaS, and IaaS in the Cloud Environment
  • Proficiency with one or more of the following EDR Tools: Crowdstrike, SentinelOne, Cortex, Microsoft MDE, or Trellix
  • Proficiency with two or more of the following tools: Host forensics software (EnCase, FTK, X-Ways, Sleuth Kit/Autopsy), SIFT, Volatility, KAPE, WireShark, Splunk
  • Proficiency conducting all-source research
Education

BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 10 years of network investigations experience



  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job SummaryArgo Cyber Systems is seeking a highly skilled Cyber Network Defense Analyst to support our critical customer mission. As a key member of our team, you will play a vital role in securing the Nation's cyber and communications infrastructure.Key ResponsibilitiesNetwork Monitoring and Analysis: Use information collected from various sources to...


  • Arlington, Virginia, United States Nodel Full time

    Job SummaryWe are seeking a highly skilled Cyber Network Defense Analyst to join our team at Node. Digital. As a Cyber Network Defense Analyst, you will play a critical role in supporting our customer mission by monitoring and analyzing network activity to identify and report potential threats.Key ResponsibilitiesNetwork Monitoring and Analysis: Characterize...


  • Arlington, Virginia, United States Zachary Piper Solutions Full time

    Zachary Piper Solutions is currently seeking Cyber Network Defense Analysts (CNDA) to support a critical customer mission.The Cybersecurity Threat Analyst is responsible for monitoring network activity, analyzing suspicious behavior, and recommending proactive measures to contain incidents.Characterize and analyze network traffic to identify...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewArgo Cyber Systems specializes in delivering advanced technical support, both remotely and on-site, for cybersecurity challenges. Our services include proactive threat hunting, immediate incident response, and thorough investigations utilizing host-based, network-based, and cloud-based analysis techniques. We are currently looking for skilled...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewPosition: Incident Manager Level IVARGO Cyber Systems is dedicated to providing essential support for U.S. Government entities in managing onsite incident responses for civilian agencies and critical asset owners facing cyber threats. Our mission involves immediate investigation and resolution of cyber incidents.We are currently seeking a Cyber...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewArgo Cyber Systems specializes in delivering both remote and onsite advanced technical support, proactive threat hunting, rapid incident response, and immediate investigation and resolution through host-based, network-based, and cloud-based cybersecurity analysis capabilities. Our team is dedicated to providing frontline response for digital...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewPosition: Incident Manager Level IVARGO Cyber Systems is engaged in supporting a U.S. Government client by providing expert assistance for on-site incident response to civilian Government entities and critical asset proprietors facing cyber threats. Our contract professionals are tasked with investigating incidents to assess the severity of...


  • Arlington, Virginia, United States Nightwing Full time

    About NightwingNightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence mission support services to the U.S. government. With a rich history of delivering technically advanced solutions, we are committed to shaping the future of cybersecurity and intelligence.Job SummaryWe are seeking a highly skilled...


  • Arlington, Virginia, United States Nightwing Full time

    About NightwingNightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence support services to the U.S. government. With a rich history of delivering technically advanced solutions, we continue to shape the future of cybersecurity and intelligence.Job SummaryWe are seeking a highly skilled Cybersecurity...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewPosition: Senior Cyber Incident Response ManagerArgo Cyber Systems is engaged in providing critical support to U.S. Government entities, delivering expert assistance for on-site incident management in response to cyber threats affecting civilian agencies and vital asset owners. Our team is dedicated to immediate investigation and resolution of...


  • Arlington, Virginia, United States Nightwing Full time

    About NightwingNightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence mission support services to the U.S. government. With a rich history of delivering technically advanced solutions, we continue to shape the future of cybersecurity and intelligence.Job SummaryWe are seeking a highly skilled Cyber...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewAs a Senior Cyber Incident Coordinator at ARGO Cyber Systems, you will play a pivotal role in supporting a U.S. Government client by providing expert assistance for on-site incident response to civilian agencies and critical asset owners facing cyber threats. Your expertise will be essential in conducting immediate investigations and facilitating...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job Description**Job Summary**Argo Cyber Systems is seeking a highly skilled Cyber Incident Manager to support our critical customer mission. As a key member of our team, you will be responsible for investigating and resolving cyber-attacks, providing immediate support to civilian Government agencies and critical asset owners.Key Responsibilities:Correlate...


  • Arlington, Virginia, United States Nightwing Full time

    About NightwingNightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence support services to the U.S. government. With a rich history of delivering technically advanced solutions, we continue to shape the future of cybersecurity and intelligence.Job SummaryWe are seeking a highly skilled Cybersecurity...


  • Arlington, Virginia, United States Nodel Full time

    Job SummaryWe are seeking a highly skilled Cyber Threat Analyst / Incident Response Specialist to join our team at Node. Digital. The successful candidate will be responsible for providing expert-level support in the detection, analysis, and response to cyber threats and incidents.Key ResponsibilitiesConduct in-depth research and analysis of cyber threats...


  • Arlington, Virginia, United States Argo Cyber Systems Full time

    Job OverviewArgo Cyber Systems specializes in delivering both remote and onsite advanced technical support, proactive threat hunting, rapid incident response, and immediate investigation and resolution through host-based, network-based, and cloud-based cybersecurity analysis capabilities. Our team members are at the forefront of digital forensics and...


  • Arlington, Virginia, United States Booz Allen Hamilton Full time

    Position Overview:As a Senior Cyber Threat Intelligence Analyst, you will play a crucial role in safeguarding national interests against cyber threats. Your primary responsibility will be to analyze, interpret, and disseminate intelligence related to cyber threats, providing actionable insights to enhance the client's security posture.Key...


  • Arlington, Virginia, United States Nightwing Full time

    About NightwingNightwing is a leading provider of full-spectrum cyber, data operations, systems integration, and intelligence mission support services to the U.S. government. With a rich history of delivering technically advanced solutions, our team has been supporting the nation's most mission-impactful initiatives for over four decades.Job SummaryWe are...


  • Arlington, Virginia, United States Nodel Full time

    Network-Based Systems Analysts / Cyber Network Defense Analysts (CNDA)Location: Arlington, VAMust have an active Top Secret Security ClearanceNode is seeking Cyber Network Defense Analysts (CNDA) to support this critical customer mission. Responsibilities: Characterize and analyze network traffic to identify anomalous activity and potential threats to...


  • Arlington, Virginia, United States Zachary Piper Full time

    Zachary Piper Solutions is seeking a highly skilled Cyber Threat Analyst to join our team in Arlington, VA. The successful candidate will be responsible for leading onsite incident response and investigation, assessing cyber-attack severity, developing mitigation strategies, and aiding in service restoration for civilian government agencies and critical...