Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
CI
CALNET Inc.
Senior Cyber Defense Analyst with Secret Clearance
Career Insights for Incident Analyst / Responder
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on North Carolina data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.
$124,145 / year median in North Carolina
+12% projected growth
Job Description
Founded in 1989, CALNET, Inc. has become one of the fastest growing privately held companies in the Technology, Intelligence Analysis, and Language Services consulting arena. Headquartered in Reston, VA, CALNET employees deliver true value to our customers by employing best practices, world-class technologies industry expertise in every project. CALNET is
ISO 9001, ISO
20000, and CMMI-Level III certified For a USARC - Defensive Cyberspace Operations opportunity, we are currently searching for a talented Senior Cyber Defense Analyst in Fort Bragg, NC to join our team. About the Job In this position you will provide 24/7/365 Blue Team services for Cyberspace Security Incident Investigation and Mitigation on both NIPRNet and SIPRNet supported networks. Blue Team operations comprise the primary operational layer of the DCO mission. You shall perform all Blue Team functionsIAW CJCSM 6510.01B, AR
25-2, the current ARCYBER and supported RCC TTPs/SOPs, and the current DoD Cybersecurity Services Evaluator Scoring Matrix. You will ingest, correlate, and analyze sensor and host data from across the supported enterprise (historical baseline: approximately 410 sensor feeds producing in excess of 800 events per second, approximately 500 million security events per week) and shall scale staffing and tradecraft to maintain operational tempo at or above these volumes. Job Requirements Network Security Monitoring and Event Analysis. Conduct continuous monitoring using the enterprise SIEM platform (currently Elastic SIEM, or successor as designated by the Government) and supporting big-data analytics and detection tooling. Analyze and correlate anomalous events across SIEM, host-based security (Trellix ENS or successor), endpoint detection (Tychon or successor), full packet capture (PCAP), NetFlow, IDS/IPS (Snort, Suricata, Sourcefire, Fidelis, Zeek), forward and reverse proxy logs, router/firewall syslog, and JRSS-equivalent boundary devices. Perform exploratory and in-depth analysis of host-based audit logs, captured network traffic, malware artifacts, and incident report trends to characterize threats and identify Advanced Persistent Threat (APT) activity not detected via traditional means. Develop, document, and refine a definable, repeatable triage process and support analytic scripts to enable consistent escalation across the analyst team. Maintain and update SIEM correlation rules, watchlists, and detection logic, and coordinate signature submissions with ARCYBER signature working groups for global implementation where appropriate. Incident Response and Internal Defensive Measures (IDM). Execute critical blocks within two (2) hours of notification or detection (or as otherwise determined by event criticality) to mitigate ongoing threat activity within the AOR. Execute immediate (within 24 hours) action steps to mitigate threats where the operational impact of delay would exceed acceptable risk. Coordinate with the applicable Theater Signal Command (TSC), DoDIN-A staff, and supported RCC for network configuration changes such as IP blocking, ACL modification, and signature deployment; where the Contractor does not administratively control the sensor grid, submit internal defensive measure recommendations (with operational impact analysis and risk justification) to the appropriate Configuration Control Board (CCB) or Designated Approving Authority Capture and perform initial analysis of volatile data, log data, and captured network traffic; maintain incident chain of custodyIAW ARCYBER F&MA
procedures and coordinate shipment of original forensic evidence toARCYBER F&MA
for imaging when required. Maintain quality control of incident records to ensureCJCSM 6510.01B
compliance, conduct incident trend analyses, and ensure all investigation data is fed to the designated ARCYBER incident-handling portal with the most current action visible. Required Skills Bachelor's Degree in an IT field preferred U.S Citizenship and Secret Clearance is required. 5+ years' IT Infrastructure experience This opportunity is in Fort Bragg, NC CALNET, Inc. offers a competitive salary and a generous benefits package. This package includes medical, dental, vision, life, short- and long-term disability insurances, a 401(k)-retirement savings plan, and generous leave time. CALNET, Inc. is an Equal Opportunity Employer. EEO/M/F/D/VBenefits
- 401(k) Plans
- Other Retirement and Savings
- Health Insurance
- Dental Insurance