Cyber Detection Engineer (CI Polygraph)

Zachary Piper
Chantilly, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$135,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Computing Platforms Unix Network Operating System (NOS) Computer Networks Databases Intrusion Detection Systems Network Monitoring Reverse Engineering Security Information and Event Management Reliability of Systems Cyber Threat Analysis
+2 more
Cyber Warfare Splunk

Job description

· Support Cyber Operations Squadron (COS) efforts by ensuring timely publication of updated cybersecurity tool signatures, including antivirus and host-based security systems.

· Conduct in-depth threat analysis, including reverse engineering of malware, to uncover critical details such as origin, target, impacted systems, recommended mitigations, and mission risk.

· Develop custom content for Security Information and Event Management (SIEM) tools and create tailored IDS/IPS signatures to counter specific threats.

· Correlate security events and incidents using data from diverse enterprise sources to identify patterns and potential threats.

· Assess the impact of cyber incidents on data and infrastructure, providing detailed evaluations of damage and recovery needs.

· Perform trend analysis and reporting on cyber incidents to identify recurring threats and inform proactive defense strategies.

· Analyze network traffic and system data to detect anomalies and potential security threats.

· Deliver real-time detection, identification, and reporting of cyber intrusions, suspicious activities, and policy violations.

· Create and implement detection rules

Requirements

· Active TS/SCI CI Polygraph required in order to be considered

· Bachelor’s degree from an accredited college in a related discipline and 5+ years of prior relevant experience

· IAT Level II (GSEC, Security+, SSCP, or CCNA-Security) certification required

· Proficient in modern operating systems, including Windows, UNIX, network OS environments, databases, and virtualized computing platforms.

· Experienced with enterprise-grade security tools, such as Security Information and Event Management (SIEM) systems specifically Splunk, Threat Intelligence Platforms (TIPs), and network monitoring solutions.

· Skilled in developing, modifying, and fine-tuning detection mechanisms, including IDS signatures and SIEM correlation rules.

· Knowledgeable in implementing cybersecurity countermeasures and mitigation strategies to reduce risk and enhance system resilience.

Benefits & conditions

· Total compensation based on experience level - $135,000-$150,000+ based on experience level

· Full Benefits: PTO, 11 Paid Holidays, Cigna Medical, Dental, and Vision, 401k with ADP

· Certification reimbursement

· Contract mobility and job stability - Contract through 2026

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

Videos

See all

Related articles

See all