Computer Network Defense Analyst

CAREER LINK
Columbus, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 130K

Job location

Columbus, United States of America

Tech stack

Bash
Computer Security
Information Systems
Computer Networks
Digital Forensics
Perl
Monitoring of Systems
Intrusion Detection and Prevention
Intrusion Detection Systems
Python
Network Security
Log Files
Network Architecture
Packet Analyzer
Powershell
Security Information and Event Management
Forensic Toolkit
Scripting (Bash/Python/Go/Ruby)
Mitre Att&ck
Malware
Cyber Threat Analysis
Information Technology
Cybercrime
Cyber Warfare

Job description

SarelaTech is seeking a Computer Network Defense (CND) Analyst to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide enterprise-level cyber defense support for continuous monitoring, threat detection, incident response, and defensive cyber operations across government information systems and network infrastructure. Working as part of a 24x7x365 cybersecurity operations team, the CND Analyst will identify, analyze, investigate, contain, and respond to cybersecurity events while supporting enterprise network defense, threat hunting, malware analysis, incident reporting, and continuous process improvement. The position supports the protection of government systems by maintaining the confidentiality, integrity, availability, and resilience of enterprise networks, applications, and data. Primary Responsibilities

  • Monitor, analyze, investigate, and respond to cybersecurity events, alerts, and incidents affecting enterprise networks, systems, applications, and data in accordance with established Incident Response procedures.
  • Perform proactive threat hunting and cybersecurity analysis utilizing SIEM platforms, IDS/IPS, system logs, packet captures, forensic tools, and threat intelligence to identify malicious activity and emerging threats.
  • Conduct incident triage, root cause analysis, containment, eradication, recovery, and post-incident reporting while ensuring compliance with established Standard Operating Procedures (SOPs) and Tactics, Techniques, and Procedures (TTPs).
  • Develop, tune, and maintain cybersecurity detection capabilities, including SIEM correlation rules, IDS/IPS signatures, and other defensive security countermeasures.
  • Perform malware analysis and support forensic collection, preservation, and analysis of digital evidence.
  • Prepare incident reports, After Action Reports (AARs), lessons learned documentation, and operational metrics.
  • Coordinate cybersecurity incident reporting, escalation, and notifications with government stakeholders.
  • Support cybersecurity readiness through tabletop exercises, continuous process improvement, and cybersecurity awareness training., * Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD organizations.

Requirements

  • Top Secret security clearance with SCI eligibility.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical discipline.
  • Five (5) or more years supporting Cyber Network Defense (CND), SOC, Incident Response, or Defensive Cyber Operations.
  • Two (2) or more years of performing incident investigation, root cause analysis, and network or system log analysis.
  • Experience utilizing SIEM platforms, IDS/IPS technologies, packet analysis, threat intelligence, and cybersecurity monitoring tools.
  • Strong understanding of Incident Response methodologies, malware analysis, threat hunting, digital forensics, and enterprise cyber defense principles.
  • Strong written and verbal communication skills., * Experience supporting Cyber Security Service Provider (CSSP), Security Operations Center (SOC), or Computer Emergency Response Team (CERT) operations.
  • Knowledge of MITRE ATT&CK, NIST SP 800-61, NIST SP 800-53, DISA STIGs, and DoD cybersecurity policies.
  • Experience developing SIEM correlation rules, IDS/IPS signatures, or enterprise detection capabilities.
  • Experience with PowerShell, Python, Bash, Perl, or similar scripting.
  • Experience participating in cybersecurity exercises and developing After Action Reports (AARs).
  • Professional certifications such as Security+, CySA+, CEH, GCIH, GCFA, CISSP, or equivalent.

Preferred Skills

  • Security Operations Center (SOC) operations
  • Computer Network Defense (CND)
  • Incident Response
  • Threat Hunting
  • SIEM administration and monitoring
  • IDS/IPS analysis
  • Malware Analysis
  • Digital Forensics
  • Packet Analysis
  • Threat Intelligence
  • PowerShell, Python, Bash
  • Technical documentation and reporting
  • NIST and DoD cybersecurity standards

Benefits & conditions

Pulled from the full job description Tuition reimbursement 401(k) Health insurance 401(k) matching Paid time off Vision insurance Dental insurance, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Profit sharing
  • Training & development
  • Tuition assistance
  • Vision insurance

Apply for this position