Advanced Cybersecurity Analytics

Abile Group, Inc.

$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI clearance with ability to obtain CI Poly.
  • Bachelor's degree with 8+ years in advanced cybersecurity analytics.
  • DoD 8140.01 and DoD 8570.01-M compliant IAT Level III and CSSP Analyst certification required.
  • Strong background in data mining and SIEM query construction.
  • Proficient in signature development and tuning, with in-depth knowledge of network protocols.

Responsibilities

  • Analyze network data trends to identify potential cyber incidents.
  • Coordinate the development of cybersecurity rules with Defensive Cyber Operations.
  • Investigate potential security compromises to enhance system protections.
  • Correlate warnings to develop proactive cybersecurity measures.
  • Collaborate with Cyber Data Analytics to improve SIEM alert handling.
  • Support the Cyber Incident Response Team in triage of ongoing incidents.
  • Document all activities for stakeholder review and reporting.

Benefits

  • Support for continued education and certifications.
  • Opportunities for global travel across multiple facilities.
  • Collaborative team environment within the Intelligence Community.
  • Access to advanced technologies and cybersecurity tools.
Full Job Description
Overview

Abile Group has an exciting and challenging opportunity for an Advanced Cyber Analyst on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission.

The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

Responsibilities

  • Analyzes trends and patterns of data on networks to identify and predict previously undiscovered events and incidents, and develop or tune rules/signatures/scripts as needed.
  • Coordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.
  • Coordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems, and develop or tune rules/signatures/scripts as needed.
  • Correlates and analyzes precursors to incidents, and develop or tune rules/signatures/scripts as needed.
  • Collaborates with the Cyber Data Analytics team to achieve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed.
  • Works with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.
  • Documents all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis.
  • Provides input to reoccurring meetings and briefings as required.


Qualifications

Clearance Required: TS/SCI with ability to obtain a CI Poly.

Degree and Years of Experience: Bachelor's degree and 8+ years of related advanced cyber security analytics work experience.

Required Certifications:
  • Must have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.

Required Skills:
  • Experience with data mining or building queries in a SIEM.
  • Strong understanding of signature development and tuning.
  • Strong understanding of network protocols and analysis with protocol analyzers.
  • Knowledge of static file signatures, i.e. "magic numbers" and how it applies to developing countermeasures for files in transit and that reside locally on a host.
  • Good working knowledge of regular expressions.

Desired Skills:
  • Comfortable in a hex editor.
  • Ability to write python/bash/powershell scripts.
  • Ability to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.
  • Good understanding of Purple Team Tactics.
  • Familiarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining.


Similar Jobs

More Jobs at Abile Group, Inc.

More Information Technology Jobs

Find similar Advanced Cybersecurity Analytics jobs: