Where

Threat Operations Analyst

$117,962 a year
Department of Homeland Security - Agency Wide
Arlington Full-day Full-time

Description:

1-year non- reimbursable assignment
CISA
Threat Operations Analyst
Series Requested: 0132
Security Clearance: TS/SCI
Virtual/Remote: No
Only current, full-time federal employees are eligible.
Resumes are reviewed every 30 days until selection/closing date.
This is a Detail, not a Developmental Rotation.
Supervisory approval form must be signed.

Requirements:

Qualifications required:
  1. Access to a SCIF
  2. Combined 7+ years' experience in any number of cybersecurity fields (preferably network, host, and intelligence analysis)
  3. Strong network-based analysis and analytic discovery skills (e.g., knowledgeable about common network/security protocols [HTTP, SSL, SSH, DNS/secure DNS, etc.], including ability to identify normal vs. abnormal behavior)
  4. Familiarity with host-based anomaly detection (e.g., have basic understanding of what normal process trees look like, vs. malware injection into a process, etc.)
  5. Experience connecting open-source information with network and/or host-based anomalies (e.g., identifying cyber threat intelligence about suspicious processes, finding new insights through tools such as VirusTotal, understanding of how to find threat intelligence about malformed HTTP traffic, etc.)
  6. Hands-on experience with open-source cyber threat/related tools (e.g., VirusTotal, Maltego, Shodan, exploit-db, etc.)
  7. Familiarity working with public/purchased Cyber Threat Intel (CTI) feeds/data (e.g., Crowdstrike reporting, GreyNoise, RecordedFuture, Palo Alto Xpanse, or others)
  8. Excellent time-management skills with the ability to work in a collaborative team on a common project/event, as well as on your own.
  9. Excellent mission documentation skills; familiarity with ServiceNow, Confluence, and JIRA is a plus.
  10. Comfort to autonomously engage with others across the Agency/organization to obtain relevant information in support of unique mission needs.
  11. Familiarity with Red Teaming / Cyber exploitation concepts (e.g., killchain, MITRE ATT&CK, common hacker tools such as Metasploit/Meterpreter, Kali linux, etc.)
  12. Ability to code/script simple programs and functions in Python, bash, powershell, etc., to enable analytic triage and automation.
  13. Familiarity with Amazon AWS/S3, Jupyter Notebooks, and experience using specific CTI APIs is a plus; fusing multiple mission-relevant data streams is a highly desired.
  14. Broad familiarity with the tactics, techniques, procedures (TTPs) of nation-state and/or ransomware actors is desired; specialization in key nation-state intel a plus.
  15. Excellent technical reasoning skills / considers analysis of competing hypothesis (ACH) / values quality over quantity / proactive & self-starting approach to work.
Please read the following important information to ensure we have everything we need to consider your application:
It is your responsibility to ensure that you submit appropriate documentation prior to the closing date. Your resume serves as the basis for qualification determinations and must highlight your most relevant and significant experience as it relates to this Joint Duty assignment opportunity announcement.

Be clear and specific when describing your work history since human resources cannot make assumptions regarding your experience. Your application will be rated based on your resume.

Please ensure EACH work history includes ALL of the following information:
  1. Job Title (Include series and grade of Federal Job)
  2. Duties (Be specific in describing your duties)
  3. Name of Federal agency
  4. Supervisor name, email, and phone number
  5. Start and end dates including month and year (e.g. June 2007 to April 2008)
Aug 9, 2024;   from: usajobs.gov

Similar jobs

  • InCom Technologies Inc.
  • Arlington
Description: Job DescriptionOverall Summary Execute processes related to Order to Cash with a focus on efficiency, first-time quality, and overall continuous process improvement. Role Responsibilities Support to maintain and improve service performance ...
19 days ago
  • Connexions Data Inc
  • Arlington
Description: Dear Candidates, Would you or someone you know be interested in Cyber Threat Intelligence Analyst role that we have open for one of our clients. The details are below. Title: Cyber Threat Intelligence Analyst Duration: 12 Months + Possible ...
4 days ago
  • Knowledge Management, Inc
  • Arlington
Description: Knowledge Management, Inc. (KMI) has the leadership and experience to deliver innovative technology, logistics and management solutions to meet real mission requirements. KMI is a Minority Business Enterprise (MBE) and Small Disadvantage ...
2 days ago
  • Knowledge Management, Inc
  • Arlington
Description: Knowledge Management, Inc. (KMI) has the leadership and experience to deliver innovative technology, logistics and management solutions to meet real mission requirements. KMI is a Minority Business Enterprise (MBE) and Small Disadvantage ...
3 days ago