Senior Cyber Threat Analyst - APT Hunt

Mantech International Corporation Herndon , VA 20171

Posted 2 months ago

Secure our Nation, Ignite your Future

Assists in providing computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments. Assists in conduct vulnerability assessments/penetration tests of information systems. Researches and maintains proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption. Assists in deterring, identifying, monitoring, investigating and analyzing computer network intrusions. Requires Bachelors degree or equivalent and two to four years of related experience with a minimum of six months experience in one or more of the following: computer network penetration testing and techniques; computer evidence seizure, computer forensic analysis, and data recovery; computer intrusion analysis and incident response, intrusion detection; computer network surveillance/monitoring; network protocols, network devices, multiple operating systems, and secure architectures. Ability to obtain a security clearance.

Join our elite team of Cyber Hunters who identify and defeat advanced persistent threats (APT's) and analyze patterns to profile adversary groups to protect and defend the most coveted intelligence target in the world. Use your expertise of hunting out the Black Hats playbook and identify anomalies and develop scenarios based on real-world cyber threat intelligence and conduct analysis on the associated data sets. You will collaborate with the detection and incident response teams to hunt for adversary behavior and based on findings, develop logic to operationalize future detection by the incident response function. This Herndon based position will be Monday

  • Friday with Core Hours. At ManTech, you will help protect our national security while working on innovative projects that offer opportunities for advancement.

Responsibilities include, but are not limited to:

Clearance Level: Top Secret SCI++

The Senior Cyber Threat Analyst

  • APT Hunt on this Agency-level Cyber Security support contract executes an APT Hunt capability for the Government. The selected candidate shall have experience with host-based and network-based APT related commercial technologies.

Duties include but are not limited to:

  • Construct and exploit threat intelligence to detect, respond, and defeat advanced persistent threats (APTs)

  • Fully analyze network and host activity in successful and unsuccessful intrusions by advanced attackers

  • Piece together intrusion campaigns, threat actors, and nation-state organizations

  • Manage, share, and receive intelligence on APT adversary groups

  • Generate intelligence from their own data sources and share it accordingly

  • Identify, extract, and leverage intelligence from APT intrusions

  • Expand upon existing intelligence to build profiles of adversary groups

  • Leverage intelligence to better defend against and respond to future intrusions

  • Conduct advanced threat hunt operations using known adversary tactics, techniques and procedures as well as indicators of attack in order to detect adversaries with persistent access to the enterprise

  • Create and add custom signatures, to mitigate highly dynamic threats to the enterprise using the latest threat information obtained from multiple sources

  • Conduct initial dynamic malware analysis on samples obtained during the course of an investigation or hunt operation in order to create custom signatures

  • Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues

  • Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs

  • Notify the management team of significant changes in the security threat against the government networks in a timely manner and in writing via established reporting methods

  • Coordinate with appropriate organizations within the intelligence community regarding possible security incidents. Conduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contact.

  • Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event

  • Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary

Position Requirements:

Required Experience/SKills:

Excellent interpersonal, organizational, writing, communications, and briefing skills

Strong analytical and problem solving skills

Minimum of 5 years of progressively responsible experience in Cyber Security, incident response, or related experience

Required Tools:

Familiarity with the following classes of enterprise cyber defense technologies:

Security Information and Event Management (SIEM) systems

Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)

Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)

Network and Host malware detection and prevention

Network and Host forensic applications

Web/Email gateway security technologies

Required Certifications:

DoD 8570 IAT Level III or CSSP-IR

Required Degree:

BS (bachelor's degree in electrical engineering, computer engineering, computer science, or other closely related IT discipline)

Security Clearance Requirements:
Active TS/SCI w/ Polygraph

Skills:

Ability to handle stress and work well under pressure,Ability to use MS Office,Ability to use PC,Analytical and Critical Thinking Skills,Interpersonal and People Skills

#LI-RT1

ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.

If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech's Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech's utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services.

If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click careers@mantech.com and provide your name and contact information.


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Senior Principal Cyber Threat Analyst APT Hunt SME

Mantech International Corporation

Posted 2 months ago

VIEW JOBS 8/28/2019 12:00:00 AM 2019-11-26T00:00 Secure our Nation, Ignite your Future Become an integral part of a diverse team in the Mission, Cyber and Intelligence Solutions (MCIS) Group. Currently, ManTech is seeking a motivated,mission-oriented, Senior Cyber Threat Analyst - APT Hunt SME to support in the Herndon, VA area, with strong Customer relationships. The NIS Division provides mission solutions to a wide range of Defense and Intelligence Community customers. This division consists of a team of technical leaders that deliver advanced technical solutions to government organizations. Our customers have high standards, are technically adept, and use our products daily to support their mission of protecting national security. Our contributions to our customers success is driving our growth Join our elite team of Cyber Hunters who identify and defeat advanced persistent threats (APT's) and analyze patterns to profile adversary groups to protect and defend the most coveted intelligence target in the world. Use your expertise of hunting out the Black Hats playbook and identify anomalies and develop scenarios based on real-world cyber threat intelligence and conduct analysis on the associated data sets. You will collaborate with the detection and incident response teams to hunt for adversary behavior and based on findings, develop logic to ope-rationalize future detection by the incident response function. This McLean based position will be Monday - Friday with Core Hours. At ManTech, you will help protect our national security while working on innovative projects that offer opportunities for advancement. Responsibilities include, but are not limited to: Be the Guru of our elite team of Cyber Hunters who identify and defeat advanced persistent threats (APT's) and analyze patterns to profile adversary groups to protect and defend the most coveted intelligence target in the world. Use your expertise of hunting out the Black Hats playbook and identify anomalies and develop scenarios based on real-world cyber threat intelligence and conduct analysis on the associated data sets. You will work within a group of matrixed subject matter experts to root out advanced adversaries from various customer mission networks (in the WMA). This McLean based position will be Monday - Friday with Core Hours. At ManTech, you will help protect our national security while working on innovative projects that offer opportunities for advancement. Duties include but are not limited to: * The Cyber Threat/APT Hunt Subject Matter Expert (SME) on this Agency-level Cyber Security support contract develops and implements an APT Hunt capability for the Government. The selected candidate shall have experience with host-based and network-based APT related commercial technologies. * Provide strategic and tactical direction to cyber hunters and leadership based on trends and actionable intelligence related to threat capabilities. * Construct and exploit threat intelligence to detect, respond, and defeat advanced persistent threats (APTs). * Coordinate hunt activities between various internal and external hunt groups. * Fully analyze network and host activity in successful and unsuccessful intrusions by advanced attackers. * Piece together intrusion campaigns, threat actors, and nation-state organizations. * Manage, share, and receive intelligence on APT adversary groups. * Generate intelligence from their own data sources and share it accordingly. * Identify, extract, and leverage intelligence from APT intrusions. * Expand upon existing intelligence to build profiles of adversary groups. * Leverage intelligence to better defend against and respond to future intrusions. * Conduct advanced threat hunt operations using known adversary tactics, techniques and procedures as well as indicators of attack in order to detect adversaries with persistent access to the enterprise. * Create and add custom signatures, to mitigate highly dynamic threats to the enterprise using the latest threat information obtained from multiple sources. * Conduct initial dynamic malware analysis on samples obtained during the course of an investigation or hunt operation in order to create custom signatures. * Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues. * Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs. * Notify the management team of significant changes in the security threat against the government networks in a timely manner and in writing via established reporting methods. * Coordinate with appropriate organizations within the intelligence community regarding possible security incidents. Conduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contact. * Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event. * Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary. Required Qualifications/Skills: * Excellent interpersonal, organizational, writing, communications, and briefing skills. * Strong analytical and problem solving skills. * Minimum of 10 years of progressively responsible experience in Cyber Security, InfoSec, Security Engineering, Network Engineering with emphasis in Cyber Security issues and operations, computer incident response, systems architecture and data management. * Requires Bachelor's Degree (in electrical engineering, computer engineering, computer science or other closely related IT discipline) or equivalent and ten years of related experience. * An ideal candidate will have expert level experience in one of more of the following disciplines: (Windows and/or Linux Operating Systems, Network Forensics, Malware Analysis/Reverse Engineering, Exploit Development, CNE and On-Net Pursuit/response). Required Tools: * Familiarity with the following classes of enterprise cyber defense technologies: * Security Information and Event Management (SIEM) systems. * Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS). * Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS). * Network and Host malware detection, prevention and host forensic applications. * Web/Email gateway security technologies. * Ability to handle stress and work well under pressure. * Ability to use MS Office, use PC, MultiTasking, Organizational Skills, Switchboard or Computer Operating Skills. Required Certifications: * DoD 8570 IAT Level III or CSSP-IR. Security Clearance Requirements: Active TS/SCI w/ Polygraph #LI-RT1 ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law. If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech's Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech's utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click careers@mantech.com and provide your name and contact information. Mantech International Corporation Herndon VA

Senior Cyber Threat Analyst - APT Hunt

Mantech International Corporation