ManTech International Corporation
Secure our Nation, Ignite your Future
Entering ManTech’s 50th year, we hold the distinct honor of being named a “Top 100 Global Technology Company” by Thomson Reuters. We have earned this and many other accolades over the years for our dedication to serving the missions of our nation’s most important customers: U.S. Intelligence, Defense and Federal Civilian agencies. All know us as a trusted partner offering best-in-class solutions in cyber, data collection & analytics, enterprise IT, and systems and software engineering tailored to meet their specific requirements.
Become an integral part of a diverse team that leads the world in Mission, Cyber, and Intelligence Solutions (MCIS) Group. Currently ManTech is seeking a motivated, mission oriented Cyber Network Defender-Senior in Clarksburg WV , with strong Customer relationships. At ManTech International Corporation, you will help protect our national security while working on innovative projects that offer opportunities for advancement.
The FSS Division provides cyber solutions to a wide range of Defense and Intelligence Community customers. This division consists of a team of technical leaders that deliver advanced technical solutions to government organizations.Our customers have high standards, are technically adept, and use our products daily to support their mission of protecting national security. Our contributions to our customers’s success is driving our growth.
As a Cyber Security Analyst in a Security Operations Center (SOC), the tasks will include analyzing all relevant cyber security event data and other data sources for attack indicators and potential security breaches; produce reports, assist in coordination during incidents; and coordinate with the O&M team to maintain all security monitoring systems are on-line, up to date, and fully operational.
Responsibilities Include :
- Foundation knowledge in in-depth Packet Analysis, the OSI Model, Data Analysis, and a high level of understanding of packet structure and knowledge of the modern cyber security threat landscape preferred.
- Monitor intrusion detection and prevention systems and other security event data sources on a 24x7x365 basis.
- Determine if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.
- Ability to problem solve, ask questions, and discover why things are happening.
- Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs.
- Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues.
- Reporting outputs will be reviewed and approved to ensure quality and metrics are maintained.
- Responsible for tuning and filtering of events and information, creating custom views and content using all available tools following an approved methodology and with approval and concurrence from management.
- Notify the Customer of significant changes in the security threat against the Customer networks in a timely manner and in writing via established reporting methods.
- Provide support for the A/V hotline and appropriately document each call in an existing tracking database for this purpose.
- Coordinate with the O&M team to ensure production systems are operational.
- Produce daily/weekly/monthly/quarterly reporting as required by management.
- Maintain system baselines and configuration management items, including security event monitoring policies in a manner determined and agreed to by management.
- Ensure changes are made using an approval process agreed to in advance.
- Coordinate with appropriate organizations regarding possible security incidents.
- Conduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contact.
- Produce reports identifying significant or suspicious security events to appropriate parties. Include latest security threat information and tie back to specific intrusion sets of nation state actors when possible.
- Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event.
- Review and evaluate network modifications and recommend security monitoring policy updates.
- Establish procedures for handling each security event detected.
- Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary.
- Be able to create and add user defined signatures, or custom signatures, to compensate for the lack of monitoring in threat areas as warranted by threat changes or as directed by the customer. This includes creating content in Arcsight as needed.
- Maintain a network diagram depleting the relevant security checkpoints in the network.
- Develop and implement a methodology using Arcsight Use Case UML processes that identify procedures for correlating security events. Analysis should all be able to create custom content and develop new use cases to better correlate security event information.
- Develop and utilize Case Management processes for incident and resolution tracking.
- The processes should also be used for historic recording of all anomalous or suspicious activity.Identify misuse, malware, or unauthorized activity on monitored networks. Report the activity appropriately as determined by the customer.Maintain proficiency and skills through relevant training, conventions, conferences, and on-the-job training.
- Provide analytical support as needed for the overall project
Ability to handle stress and work well under pressure,Ability to use MS Office,Ability to use PC,Analytical and Critical Thinking Skills
U.S. Citizenship and an active TS/SCI clearance required.
ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Waretime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.
If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech’s Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer – minorities, females, disabled and protected veterans are urged to apply. ManTech’s utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click email@example.com and provide your name and contact information.
Apply For This Job
To apply for this job please visit the following URL:http://www.indeed.com/viewjob?t=Cyber+Security+Analyst&c=ManTech+International+Corporation&l=Clarksburg%2C+WV&jk=d573df2a098fb0a6&rtk=1dbc56a8gbinv801&from=rss→