General Dynamics Information Technology→
Cyber Threat Analyst Associate at General… · USA LA…
Entry LevelHybridFull-timeUSA LA Bossier City$73k–$99k/yr
Skills
information security event monitoringsecurity incident responsenetwork intrusion detection (nid) monitoringcyber-attack stagesips/idssiem systemssentinel onesplunkfederal and dod security standardsnistdcidcnssdod 8500windows oslinux oscommand line interfacepenetration testingvulnerability testingdata loss prevention (dlp)anti-virusanti-malwaretcp/ipcomputer networkingrouting and switchingnetwork traffic analysisnetwork packet capture analysise-mail security
Job Description
Summary: General Dynamics Information Technology is a global technology and professional services company focused on delivering consulting and mission services to the U.S. government and defense sector. The Cyber Threat Analyst Associate will be responsible for monitoring and triaging security events, utilizing SIEM technology to support SOC operations, and identifying security threats within the client's environment.
Responsibilities:
- Provides technical support on post event network security logs and trend analysis to uncover security and compliance violations
- Detects the full spectrum of known cyberattacks (e.g., DDoS, malware, phishing, others)
- Pinpoints location of compromised systems and devices, and conducts cyber incident and event monitoring identifying anomalous and malicious activity
- Correlates events from the various components in the IT security infrastructure and identifies attacks and breaches
- Associates and correlates IP address related events with specific systems or devices in the IT infrastructure
- Identifies and analyzes intelligence information about threats to customer’s information processing systems
- Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough triage of events utilizing relevant event detail and summary information
- Ensure the integrity and protection of networks, systems, and applications through monitoring of security devices. React to customers escalations
- Observes and documents actions taken by malicious actors in customer networks and contribute to content creation
- Experience working within a wide range of environments to include Linux, UNIX, Windows in addition to a strong understanding of networking, the OSI model, and TCP/IP protocols
- Maintain an understanding of the current vulnerabilities, response, and mitigation strategies used in cyber security operations
Required Qualifications:
- Computer Security
- Information Technology Security
- Security Incident Response
- 0 + years of related experience
- Knowledge of information security event monitoring and detection and NID monitoring and incident response
- Knowledge of Cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks)
- Attack methods and techniques (e.g., DDoS, brute force, spoofing, etc.)
- Knowledge of IPS/IDS, managing cases with enterprise SIEM systems (e.g. Sentinel One, Splunk) and other network security tools
- Familiarity with Federal and DoD security standards such as NIST, DCID, CNSS and DoD 8500
- Exposure to Windows and Linux OS to include knowledge of the command line interface
- Knowledge of IDS/IPS, penetration and vulnerability testing, DLP, anti-virus and anti-malware, TCP/IP, computer networking, routing and switching
- Understanding of computer networking fundamentals, network traffic analysis methods, and ability to review and analyze network packet captures
- Understanding of e-mail security fundamentals
- Technical Training, Certification, or Degree
Required Skills: Information security event monitoring, Security incident response, Network intrusion detection (NID) monitoring, Cyber-attack stages, IPS/IDS, SIEM systems, Sentinel One, Splunk, Federal and DoD security standards, NIST, DCID, CNSS, DoD 8500, Windows OS, Linux OS, Command line interface, Penetration testing, Vulnerability testing, Data loss prevention (DLP), Anti-virus, Anti-malware, TCP/IP, Computer networking, Routing and switching, Network traffic analysis, Network packet capture analysis, E-mail security
Benefits: Comprehensive benefits and wellness packages, 401K with company match, Variety of medical plan options, Some with Health Savings Accounts, Dental plan options, A vision plan, Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave, Short and long-term disability benefits, Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
Benefits
Comprehensive benefits and wellness packages
401K with company match
Variety of medical plan options
Some with Health Savings Accounts
Dental plan options
A vision plan
Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
Short and long-term disability benefits
Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance