Cyber/Indications and Warnings Analyst
- Annapolis Junction, MD
The Cyber/Indications and Warnings Analyst is responsible for performing Security Incident and Event Handling for a critical DoD operational system. The successful candidate will demonstrate strong skills in Incident Response and Handling, Forensic Analysis, and the ability to quickly relay critical information to team members and management clearly, completely, and concisely.
Primary Roles and Responsibilities
As the Attack, Sensing, Warning, and Response (ASWR) analyst, the successful candidate will analyze collected data and derive facts, inferences, and projections to determine if the systems being monitored are operating normally or being attacked by an adversary. This individual will also analyze this collected data to detect an Insider Threat. The successful candidate will develop new dashboards and analytics to refine existing reports and create new reports. He/she will also work with System Engineers and System Administrators to better define the audit data being collected to eliminate false positives and false negatives from the data.
Required Skills and Education
- A Bachelor's Degree in Information Assurance or related field .
- At least 3 years of experience with an Indications and Warnings monitoring tool.
- Experience with one or more of the following: StealthWatch, TripWire, Zenoss, and ArcSight .
- Experience tuning audit data to reduce number of false positives and false negatives.
- Experience in responding to detected security incidents.
- Must possess excellent troubleshooting skills.
- Must have a solid understanding of network intrusion detection methods and techniques.
- Network Security Operations Center (SOC) experience preferred.
- Experience creating Dashboards and Analytics within SEIM (Security Information and Event Management) Tool.
- Experience creating workflows for Incident Response within a SEIM (Security Information and Event Management) Tool.
- Experience with the following: StealthWatch, TripWire, Zenoss, and ArcSight.
- CISSP Certification.
- GIAC Certified Incident Handler Certification.
- GIAC Cyber Threat Intelligence Certification.
BAE Systems Intelligence & Security, based in McLean, Virginia, designs and delivers advanced defense, intelligence, and security solutions that support the important missions of our customers. Our pride and dedication shows in everything we do-from intelligence analysis, cyber operations and IT expertise to systems development, systems integration, and operations and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage and defeat threats inspires us to push ourselves and our technologies to new levels. That's BAE Systems. That's Inspired Work. Equal Opportunity Employer/Females/Minorities/Veterans/Disabled/Sexual Orientation/Gender Identity/Gender Expression. To see Inspired Work in action, visit www.baesystems.com and follow us on Facebook: www.facebook.com/baesystemsintel.
Back to top