Cyber Ops Analyst- Lead Fusion Cell Cybersecurity

Marathon TS

$100K — $130K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a related discipline with 12+ years of experience (or equivalent experience in lieu of a degree).
  • Active DoD TS/SCI clearance, eligible for C/I Polygraph.
  • IAT Level II Certification + CE (e.g., Security +, CCNA Security, CySA+).
  • Direct experience with network traffic monitoring, IDS, IPS, and SIEM technologies.
  • Familiarity with cybersecurity operations, incident response, and security architecture.
  • In-depth knowledge of network/application protocols and cyber threat methodologies.
  • Proficiency with datasets supporting analysis and open-source/commercial threat intelligence platforms.

Responsibilities

  • Leverage intelligence and processes to identify threats and improve security.
  • Utilize network monitoring tools to detect cyber adversary activity.
  • Support collaborative forums for coordinated vulnerability scoring and mitigation.
  • Develop Cyber Fusion frameworks based on best practices and DoD guidance.
  • Perform threat-informed analysis using various intelligence sources.
  • Investigate anomalies in logs and sensor data to assess system compromises.
  • Provide risk assessments and recommend countermeasures based on analysis.

Benefits

  • Supportive work environment within a critical national security context.
  • Engagement with cutting-edge cybersecurity technologies and methodologies.
  • Opportunities for collaboration across various intelligence and operations teams.
  • Significant role in shaping threat mitigation strategies.
  • Potential for career advancement in a major defense organization.
Full Job Description
This position will support the DISA GSM-O II Task Number 07 (TN07) Joint Force Headquarters DODIN. GSM-O II provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of the DoD and CoCOMs. The selected candidate shall execute in real time, in accordance with mission requirements, incident handling, triage of events, network analysis and threat detection, trend analysis, metric development, vulnerability information dissemination, and the DoD CNDSP methodology.

Primary Responsibilities
  • Leverage intelligence and operational data, information and processes to identify threats, improve security, and reduce the enterprise's exposure of vulnerabilities.
  • Leverage an array of network monitoring and detection capabilities (including netflow, custom application protocol logging, signature-based IDS, and full packet capture (PCAP) data) to identify cyber adversary activity.
  • Support various collaborative and cross functional (Intelligence, Current Operations, Future Operations, Logistics, Planning, Resourcing and Requirements) forums to achieve centrally coordinated, threat informed and prioritized vulnerability scoring and mitigation methodology.
  • Support the development of Cyber Fusion Standard, Cyber Fusion Framework and Methodology based on industry best practice and department of defense instruction, guidance, and policy.
  • Perform threat informed analysis by leveraging serialized reporting, intelligence product sharing, OSINT, and open source vulnerability information to ensure prioritized plans are developed.
  • Analyze and document malicious cyber actors TTPs, providing recommendations and alignment to vulnerabilities and applicability to the enterprise operational environment.
  • Client adversary campaigns, anomalies and inconsistencies in sensor and system logs, SIEMs, and other data; investigate to identify or rule out system compromises, provide written analytic summaries and attack life cycle visualizations.
  • Provide risk assessments and recommendations based on analysis of technologies, threats, intelligence, and vulnerabilities.
  • Recommend adjustment of countermeasures, enterprise or tactical, to account for threats impacting the DODIN.
  • Recommend adjustment of prioritized enterprise focused analysis based on immediate threat identified based on intelligence and other analysis performed.
  • Collect analysis metrics and trending data, identify key trends, and provide situational awareness on these trends.
Required skills/Level of Experience :
  • Bachelor's degree in a related discipline with 12+ years of applicable combined education and experience; additional related years of experience is accepted in lieu of a degree.
  • Active DoD TS/SCI clearance and eligible for C/I Polygraph
  • IAT Level II Certification + CE. (Security +, CCNA Security, CySA+, GICSP, GSEC, CND, SCCP)
  • Direct experience with network traffic monitoring/capture/analysis capabilities, and various IDS, IPS, SIM/SIEM/SOAR technologies, to include IDS signature development.
  • Familiarity with all related aspects of cybersecurity operations/analysis (e.g. incident response & management, forensic media analysis, malware analysis/reverse-engineering, cyber threat intelligence analysis, etc.) and security architecture & engineering.
  • In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies (TTPs).
  • Proficiency with datasets that support analysis (e.g. passive DNS, WHOIS/registration data, system/service enumeration data, threat indicators/observables, malware analysis results, etc) and various open-source and commercial vendor portals/services/platforms that provide that data.
  • Proficiency working with various types of network data (e.g. netflow, PCAP, custom application logs)

Nice to have skills:
  • Experience with DISA and DoD Networks.
  • Skilled in building extended cyber security analytics.
  • Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership.
  • Experience in intelligence driven defense and/or cyber Kill Chain methodology.

OTHER SKILL/REQUIREMENT: Required skills: Microsoft Excel Microsoft Word Rational Clearquest Rational ClearCase CMMi Level 3 Excellent verbal and written communication skills
To be considered for work, A CANDIDATE MUST BE EITHER A U.S. CITIZEN OR PERMANENT RESIDENT ALIEN (No H1 visa holders).

Similar Jobs

More Jobs at Marathon TS

More Aerospace & Defense Jobs

Find similar Cyber Ops Analyst- Lead Fusion Cell Cybersecurity jobs: