Job Details
Junior CND Analyst
Description
Job Description:At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Your most important work is ahead.
If this sounds like the kind of environment where you can thrive, keep reading!
The CND Analyst watchstanders provide 24x7 support. Candidates must have the ability to support shift work. Duties include network security monitoring and detection, proactively searching for threats, inspecting traffic for anomalies and new malware patterns, investigating and analyzing logs, providing analysis and response to alerts, and documenting activity in investigations.
This is a 24/7/365 team. This position is for the daytime shift. On-call support/hours may be required.
Primary Responsibilities
- Work on a team of cyber professionals responsible for 24x7x365 monitoring of all CND detection on all customer security domains.
- Utilize a SIEM for enterprise monitoring and detection
- Perform critical thinking and analysis to investigate cyber security alerts
- Perform initial alert triage and document findings and recommendations
- Analyze network traffic using enterprise tools (e.g. SIEM, Full PCAP, Firewall, Proxy logs, IDS logs, etc)
- Collaborate with team members to analyze an alert or a threat
- Stay up to date with latest threats
- Monitor shared email box for notifications and requests
- Utilize OSINT to aid in their investigation
- Contribute to content tuning requests
Basic Qualifications
Candidates should be able to demonstrate the following:
- Familiarity with a SOC’s purpose and role within an organization
- General understanding of common network ports and protocols (e.g. TCP/UDP, HTTP, ICMP, DNS, SMTP, etc)
- Familiarity with network topologies and network security device functions (e.g. Firewall, IDS/IPS, Proxy, DNS, etc).
- Familiarity with packet analysis tools such as Wireshark
- Able to perform critical thinking and analysis to investigate cyber security alerts
- Familiarity with common malware and attack vectors
- Familiarity with Windows operating systems and standard OS logging
- Familiarity with Malware Protection, DLP, and host based firewalls
- Experience working in a 24/7/365 environment
- Excellent oral and written communication skills. Ability to communicate and work effectively with other contractors and Government civilians.
- Highly organized with strong troubleshooting and problem-solving skills
- Ability to work independently and as a team member under tight deadlines with changing priorities.
- Must be a self-motivated individual in pursuit of a career in cybersecurity!
Security Clearance
- TS/SCI with CI Poly required for Position or TS/SCI and willingness to get a poly.
- US Citizenship is required due to the nature of the government contracts we support.
Required Certifications
- DoD 8570 IAT Level II equivalent certification (with continuing education where applicable) (Security+, CCNA Security, CSA+, GICSP, GSEC, SSCP) or higher
- DoDD 8140/DoD 8570.01M Computing Environment certification
- GIAC Continuous Monitoring (GMON) or equivalent (CySA+, CCNA – Cyber Operations, CCIH) within 180 days of contract start
- DoD 8570 CND-Analyst/CSSP Analyst equivalent certification (CEH, CFR, CSA+, GCIA, GCIH, GICSP, SCYBER) within 180 days of contract start
- Splunk Core Certified User within 180 days of contract start
Education/Experience
- Bachelor’s Degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field. Additional experience may be considered in lieu of degree.
- A minimum of 2 years of relevant professional experience such as:
- Network Administration
- Unix/Linux Administration
- Software engineering
- Software development
- Systems administration
- Help desk/IT support
Preferred Qualifications:
- SOC Analyst experience
- Experience with both Splunk and ArcSight SIEM platforms
- Splunk certifications (Splunk Core Certified User, Splunk Core Certified Power User)
- Experience supporting 24x7 missions
- Experience in network and cybersecurity design, engineering and operations
- Experience with Service Desk support and operations
- Familiarity with SOC methodologies and processes
- Familiarity with scripting languages (e.g. Python, Powershell, Javascript, VBS etc)
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.