Cyber Countermeasure Specialist

ClearBridge Technology Group
United States
11 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$116,480.0 - $168,480.0
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Multitier Architecture JIRA Bash Shell Border Gateway Protocol Domain Name System (DNS) Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Python (Programming Language) Network Intrusion Detection Systems Packet Analyzer Network Protocols Parsing
+12 more
Windows PowerShell Prometheus Kusto Query Language TCP/IP Tcpdump Wireshark Wide Area Networks Snort (Software) Transport Layer Security Restful APIs Cyber Warfare Elk Stack

Job description

Our client, a leading Government Systems Integrator, is in need of a TS / SCI cleared Cyber Countermeasure Specialist for initial 12 month contract onsite in Pearl Harbor, HI. The Cyber Countermeasure Specialist will be working on a defensive cyber operations team. The Cyber Countermeasure Specialist will play a critical role in bridging detection analytics and active threat containment across an associated multi-domain operational enclave. The Cyber Countermeasure Specialist will be responsible for the engineering, operational validation, deployment and lifecycle maintanance of defensive countermeasures, detection signatures, sensor tuning and containment workflows (operating across active operational nodes, including SD-WAN transport fabrics and out-of-band management links), tuning advanced network sensor grids (Corelight and Elastic Defend) and authoring actionable threat containment playbooks within JIRA and collaborate closely with Tier II NOC Engineers and NIWC pipeline architects to neutralize adversarial activity across the customers operational battlespace.

Requirements

  • Must have an active TS / SCI clearance.
  • At least 4 years of experience working in Intrusion Detection / prevention Engineering, custom signature creation and / or network defense operations and a Bachelors degree (military experience will suffice if candidates do not have a degree.
  • Prior experience authoring, testing and deploying custom network intrusion signatures and parsing logic (Snort / Suricata rules, Zeek Scripts, YARA and / or Elastic KQL / EQL query rules).
  • Hands on operational experience with enterprise sensor platforms such as Corelight, Elastic Defense / ELK Stack or next-gen firewalls, ideally Palo Alto.
  • Experience developing, documenting and executing threat containment workflows and tracking procedures using Atlassian JIRA.
  • Understanding of networking protocols (TCP / IP, BGP, IPsec, DNS, TLS), network perimeter architecture and packet analysis tools, ideally, Wireshark or tcpdump.
  • Must hold a valid certification or degree meeting DOD 8140.03 / DCWF Work Role Code 532 Cyber Defense Incident Responder (at the intermediate proficiency level) prior to being onsite.
  • Any of the following certifications, CySA+, GIAC CGTI, EC-C CEH, CND, Security+, etc.

Preferred or Nice to Have Skills:

  • Experience deploying and managing countermeasures across SIPRNet or TS / SCI enclaves.
  • Experience with automated containment scripting using Python, PowerShell, Bash or REST APIs.
  • Understanding of Darktrace Managed Detection & Response (MDR) and Prometheus pipeline data flows.

Benefits & conditions

ClearBridge Technology Group is an Equal Opportunity Employer. We offer excellent benefits and compensation packages. The expected hourly rate range for this role is $56 - 81 / hr The posted range is an estimate, the actual compensation offer will be based on the candidate’s experience, skills, qualifications and will be in line with internal equity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Loading talks and stories from around this role…