Sorry, this listing is no longer accepting applications. Don’t worry, we have more awesome opportunities and internships for you.

Cyber Forensic Analyst II (Network Based)

Metronome, LLC

Cyber Forensic Analyst II (Network Based)

Arlington, VA
Full Time
Paid
  • Responsibilities

    Job Description

    EMPLOYMENT TYPE: Full-time

    RESPONSIBILITIES: The DHS’s Hunt and Incident Response Team (HIRT) secures the Nation’s cyber and communications infrastructure. HIRT provides DHS’s front line response for cyber incidents and proactively hunting for malicious cyber activity. This team performs HIRT investigations to develop a preliminary diagnosis of the severity of breaches. We provide HIRT remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities

    Metronome, LLC is seeking a Network Based Cybersecurity Systems Analyst to support this critical customer mission.

    • Collect network intrusion artifacts (e.g., domains, URI’s, certificates, etc.) and use discovered data to enable mitigation of potential Computer Network Defense incidents.
    • Analyze identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information
    • Collect network device integrity data and analyze for signs of tampering or compromise
    • Assist with real-time CND incident handling (i.e., forensic collections, intrusion correlation and tracking, threat analysis, and advising on system remediation) tasks to support onsite engagements
    • Monitor external data sources to maintain currency of Computer Network Defense threat conditions
    • Perform analysis of log files from a variety of sources (e.g., network traffic logs, firewall logs, intrusion detection system logs, DNS logs) to identify possible threats to network security
    • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts
    • Track and document Computer Network Defense incidents from initial detection through final resolution

    REQUIRED QUALIFICATIONS:

    • Must have an active TS/SCI clearance
    • Must be able to obtain DHS Suitability
    • One of the following combinations of Education and Experience
      • 4-6 years of network investigations experience with a High school diploma; OR
      • 2-4 years of network investigations experience with a Bachelor’s degree in a technical discipline from an accredited college or university in Computer Science, Cybersecurity, Computer Engineering, or related discipline
    • Knowledge of Computer Network Defense policies, procedures, and regulations
    • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
    • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
    • Ability to identify and analyze anomalies in network traffic using metadata
    • Experience with reconstructing a malicious attack or activity based on network traffic
    • Experience examining network topologies to understand data flows through the network
    • Must be able to work collaboratively across physical locations

    DESIRED QUALIFICATIONS:

    • Knowledge of network device integrity concepts and methodologies
    • Understanding of how to preserve evidence integrity according to standard operating procedures or national standards

    WORK SCHEDULE: Core Hours

    BACKGROUND SCREENING/CHECK/INVESTIGATION: Successful Completion of a Background Check will be required as a condition of hire.

    BENEFITS: Metronome offers a comprehensive benefits package that reflects our commitment to creating a diverse and supportive workplace.  Benefit eligibility is determined on the type of position (full-time, part-time, temporary). Metronome’s range of benefits include, but are not limited to, Medical, Vision & Dental Insurance, Life Insurance, Paid Time-Off & Company Paid Holidays, Personal Development & Learning Opportunities.

    APPLICATION PROCESS: Please follow all instructions carefully. Errors or omissions may affect your consideration for employment.

    1. Select Create Profile and Apply to Requirement
    2. Complete your Profile and Answer the Questionnaire
    3. Upload a current resume
    4. Complete the Online Application and Submit

    EVALUATION PROCESS: Metronome will evaluate applicants based on how well they meet the qualifications of the position above. Your completed application (including questionnaire, resume, and online application) will be used to determine your eligibility and how well you meet the qualifications for this position.

    Your responses to the questionnaire may be compared to your resume and application; if either your resume or application contradicts or does not support your responses, you will disqualify yourself and not receive further consideration for this job.

    EQUAL EMPLOYMENT OPPORTUNITY POLICY

    Metronome does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor.

    REASONABLE ACCOMMODATION POLICY

    Metronome is committed to providing reasonable accommodations to applicants with disabilities where appropriate. A reasonable accommodation is any change to a job, the work environment, or the way things are usually done that enables an individual with a disability to apply for a job, perform job duties or receive equal access to job benefits.

    Applicants requiring reasonable accommodation for any part of the application process or hiring process should contact Metronome Human Resources at hr@wearemetronome.com or 703-957-4082. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.