Cyber Threat Intelligence Analyst - NC

RTX Corporation Morrisville , NC 27560

Posted 2 days ago

Date Posted:

2024-04-24

Country:

United States of America

Location:

NC607: Aerial Ctr 6001 HospitalityCrt 6001 Hospitality Court Aerial Center, Morrisville, NC, 27560 USA

Position Role Type:

Hybrid

You have been redirected to RTX's career page as we have recently transitioned from RTX to become a standalone company, which provides us with greater autonomy and opportunities for growth. As a prospective employee of Nightwing, you'll have the chance to contribute to our continued success and shape the future of our cybersecurity, intelligence, and services offerings.

This position is CONTINGENT upon funding, an open position, customer approval, completion of a favorable background investigation, and the ability to obtain and maintain our customer's sensitive clearance.

An experienced Cyber Threat Intelligence Analyst is needed to support the Cybersecurity Operations Portfolio in the Detection Automation and Engineering group at our customer's site.

  • Customer locations are available in Falls Church, VA and in Morrisville, NC. The role is Hybrid (mostly remote).

Job Responsibilities:

  • Implement a dynamic, advanced Risk-Based Alerting (RBA) security framework within Splunk.

  • Create and test detections written in advanced Splunk Programming Language (SPL).

  • Perform analysis on hosts running on a variety of platforms and operating systems, to include Microsoft Windows & Linux.

  • Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system logs) to identify possible threats to network security.

  • Leverage tools including Splunk, Tanium, Firepower, Azure, GoogleCloud, SentinelOne, SESC suite as part of duties performing cyber incident response analysis.

  • Act as an observer to Red Team penetration testing exercises and collaborating with Cybersecurity Operations Center (CSOC).

  • Correlate event or incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.

  • Work with a diverse team of analysts in conducting incident triage, incident handling, and remediation.

  • Identifies and assesses the capabilities and activities of cyber criminals or foreign intelligence entities; produces finds to help initialize or support law enforcement and counterintelligence investigations or activities.

Required Experience and Skills:

  • Must be eligible to obtain a sensitive clearance - Position of Public Trust - and may be required to obtain a higher security clearance.

  • Must have strong working knowledge of:

Cyber Threat Intelligence Analysis and Reporting, Cyber Defense Techniques, Adversary Tactics, Techniques, and Procedures (TTPs), Boolean Logic, TCP/IP Fundamentals, Network Level Exploits, Threat Management

  • Must have excellent oral and written communication skills.

  • Must have excellent interpersonal and organizational skills.

  • 5+ years related work experience and a Bachelor's degree.

  • Networking experience, with routing, switching, and analysis experience.

  • Statistical modeling and analysis experience to infer possible cybersecurity threats.

  • Experience in analysis in investigations, such as in IT, law enforcement, military intelligence, or business analytics.

  • Interest in learning about Windows, Linux, Database, Application, Web server, firewall, SIEM etc. log analysis.

  • Strong communication and interpersonal skills to effectively communicate with team-members.

  • Must be highly motivated with the ability to self-start, prioritize, multi-task and work in a team setting.

  • Understanding of intelligence cycle, Cyber Kill Chain, and Diamond Model.

Desired Skills and Experience:

  • 5+ years of experience working as a Cyber Threat Intelligence Analyst.

  • Familiarity with common network vulnerability/penetration testing.

  • Experience with, Recorded Future, Tanium, Redseal, and/or Anomali.

  • An understanding of log data for Sourcefire, Brightmail, Blue Coat, and Tipping Point.

  • Experience evaluating systems and network devices and enterprise networks for IA vulnerabilities.

  • Experience evaluating enterprise networks for IA/security vulnerabilities.

  • Splunk query-development expertise.

  • Experience on an Incident Response team performing Tier I/II initial incident triage.

  • Excellent writing skills.

Required Education:

Bachelor of Science Degree with a major in Computer Science/Computer Engineering, Engineering, Science or a related field. In lieu of degree, two additional years of related work experience may be substituted for each year of degree-level education.

Desired Certifications (one or more is desired):

DOD 8570.1-M Compliance at IAT Level II; CISSP, Certified Ethical Hacker (C|EH), SFCP, GCIA, SEC +, or SANS.

The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.

The Cybersecurity, Intelligence and Services (CIS) business provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. CIS brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets

Previously part of a leading Fortune 100 company and headquartered in Dulles, VA; Nightwing became independent in 2024 but continues to support the nation's most mission impactful initiatives. When we formed Nightwing, we brought a deep set of credentials and an unfaltering commitment to the mission. For over four decades, our team has been providing some of the world's most technically advanced full-spectrum cyber, data operations, systems integration and intelligence support services to the U.S. government on its most important missions.

At Nightwing, we value collaboration and teamwork. You'll have the opportunity to work alongside talented individuals who are passionate about what they do. Together, we'll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.

Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.

This requisition is eligible for an employee referral award. ALL eligibility requirements must be met to receive the referral award.

Morrisville, NC (Hybrid)

Falls Church, VA (Hybrid)

Relocation Eligible: No

Sign On Bonus Eligible: No

#CISJobs

#Cyber

#Mercury

The salary range for this role is 77,000 USD - 163,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

RTX is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.

Privacy Policy and Terms:

Click on this link to read the Policy and Terms


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove

Cyber Threat Intelligence Analyst - NC

RTX Corporation