Overview
Edgewater Federal Solutions is currently seeking a Cyber Threat Intelligence (CTI) Analyst to provide support to an Edgewater Federal government contract.
**Due to the nature of the contract and work, US Citizenship is a requirement**
Responsibilities
- Become an integral part of a diverse team.
- Establish and maintain complete intelligence cycle operations to support enterprise cyber security, accounting for strategic, operational, and tactical intelligence needs.
- Use open source, government-provided and commercially provided intelligence in support of cyber security.
- Potentially attend classified briefings that may help inform intelligence efforts.
- Develop and brief status updates to the Federal Team.
- Research known adversarial Tactics, Techniques and Procedures (TTPs) to identify foundational components, isolate associated host or network events, and enable threat mitigation, detection, and response.
- Produce comprehensive cyber security reports including sourced and summarized threat intelligence, threat hunt findings and limitations, and present recommendations to system owners, cyber defenders, and policy makers.
- Disseminate timely Indicators of Compromise (IOCs) and warnings of cyber threat activity against the U.S. and NIH-owned and operated hosts and networks.
- Identify and provide high quality sources of indicators of attack and compromise to the team for application to the sensor array.
- Participate in hunt, computer network defense, and incident response activities Conduct stakeholder analysis, determine client's goals and objectives, and identify appropriate strategies to support the client's mission/vision.
- Create an NIH Cyber Threat Profile and analysis.
- Complete job/system-related training as required by NIH.
Qualifications
- BS/BA degree (additional years of experience in cyber security reduce this educational requirement).
- 12 or more years work experience.
- Sound cyber security knowledge foundation, to include sufficient understanding of networking and application layer protocols.
- Knowledge of the cyber kill chain and/or diamond model.
- The ability to handle stress and work well under pressure and ambiguity.
- The ability to make decisions and resolve problems effectively - seek out information and data to evaluate, prioritize and formulate best solutions and practices.
- The ability to multi-task, work independently and as part of a team, and deal with sudden shifts in project priorities.
- Working knowledge of enterprise toolsets and platforms (e.g., M365 Suite, Azure Cloud, and/or AWS).
- Working knowledge of SecOps platforms (e.g., Tenable).
- Technical aptitude for effective participation in hunt, computer network defense, and incident response activities, to include ability to reconstruct events based on in-depth analysis of network, endpoint, and log data.
- Experience tracking threat actors and their TTPs
Preferred Qualifications:
- One or more certifications in information security (such as GCIA, GCIH, CEH, CISSP, SSCP, Sec+, etc.)
- Experience and effective participation in hunt, computer network defense, and incident response activities
- Malware analysis skills and experience
- Intelligence community experience
Salary = $160K - $180K