Intrusion Detection Analyst
Company: Leidos
Location: Belleville
Posted on: March 16, 2023
|
|
Job Description:
Description Job Description:Looking for an opportunity to make
an impact?Leidos is a FORTUNE 500 company bringing a mix of
innovative technology and sector expertise to customers in the
national security, engineering, and the health industries.At
Leidos, we deliver innovative solutions through the efforts of our
diverse and talented people who are dedicated to our customers'
success. We empower our teams, contribute to our communities, and
operate sustainable. Everything we do is built on a commitment to
do the right thing for our customers, our people, and our
community. Our Mission, Vision, and Values guide the way we do
business.Your greatest work is ahead!Leidos Defense Group is
looking for an Intrusion Detection Analyst to work on the United
States Transportation Command (USTRANSCOM) Cyberspaces Operations
Forces' (COF) program located at Scott Air Force Base, Illinois.
The COF mission is to provide Department of Defense Information
Network (DODIN) Operations, defensive cyber operations-internal
defensive measures, and overall cyberspace operations in support of
USTRANSCOM network systems and missions. You will provide Intrusion
Detection Monitoring and Incident Management Daily Operations and
Maintenance Services through the application of the intrusion
detection monitoring and incident management tools and processes.
Intrusion detection/analysis/incident management activities will be
performed for all USTRANSCOM information systems/networks that
subscribe to USTRANSCOM Cyber Security Service Provider (CSSP)
services. You will also identify unauthorized, malicious, or
anomalous activity and initiate appropriate incident response
actions in support of mission assurance for USTRANSCOM information
systems and networks on NIPRNet and SIPRNet, to include USTRANSCOM
cloud environments.If this sounds like the kind of environment
where you can thrive, keep reading!Leidos Defense Group provides a
diverse portfolio of systems, solutions, and services covering
land, sea, air, space, and cyberspace for customers worldwide.
Solutions for Defense include enterprise and mission IT,
large-scale intelligence systems, command and control, geospatial
and data analytics, cybersecurity, logistics, training, and
intelligence analysis and operations support. Our team is solving
the world's toughest security challenges for customers with "can't
fail" missions. To explore and learn more, click here! Are you
ready to make an impact? Begin your journey of a flourishing and
meaningful career, share your resume with us today!Responsibilities
Include: Review audit data, e-mail spam, and network traffic data
for irregularities or other indications of real or potential
security violationsCorrelate and analyze security data and events
from alert and traffic flow systemsIdentify potential distributed,
long-term, coordinated, low-visibility network-based
attacksIdentify potential advanced persistent and coordinated
threats across multiple platformsPerform tuning and optimization
tasks to include sensor rule review and log
aggregation/visibilityDevelop/enhance existing intrusion detection
analytics/dashboards/signatures to remain commensurate with
evolving cyber threatInvestigate all security related events and
incidents involving information systemsReport identified security
incidents through the Joint Incident Management System (JIMS) or
otherReview and share significant activity via SIGACT reports and
Attack Sense and Warning (AS&W) tippersPerform incident
response based on security events identifiedGenerate and share
Suspicious Network Activity Reports (SNARS)Track acknowledgements
of SNARS and AS&W tippers from the CSSP Subscriber
communityDevelop and deploy countermeasures in response to
cybersecurity incidentsAnalyze and identify root cause(s) and
lessons learned from security incidentsDocument a formal after
actions report (AAR)Provide recommendations related to tactical
response actions, such as updating signatures and
heuristicsMaintain an inventory of log data sources and resident
locationsMaintain a daily activity log containing continuous event
management updates and shift-turnover details of
events/incidentsBasic Qualifications:DoD 8570 Compliant to include
IAT-II, CSSP-A, and CSSP-IR certifications6-month waiver in lieu of
CSSP certificationPreferred Experience, Skills, and
Education:Experience with any of the following tools: Splunk, Zeek,
Tanium, Crowdstrike, HBSS, Firepower, Wireshark, StealthWatch, &
AWS ConsoleClearance Required:Requires an active Secret or above
clearance with ability to obtain Top Secret/SCI security
clearanceUSTCCOFExternal Referral EligiblePay Range:Pay Range
$63,050.00 - $97,000.00 - $130,950.00The Leidos pay range for this
job level is a general guideline onlyand not a guarantee of
compensation or salary. Additional factors considered in extending
an offer include (but are not limited to) responsibilities of the
job, education, experience, knowledge, skills, and abilities, as
well as internal equity, alignment with market data, applicable
bargaining agreement (if any), or other law.
Keywords: Leidos, Belleville , Intrusion Detection Analyst, Professions , Belleville, Illinois
Click
here to apply!
|