Source description
About the role
BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 7-9 years of network investigations experience.
5+ years of directly relevant experience in network investigations
In depth knowledge of CND policies, procedures and regulations
In depth knowledge of TCP/IP protocols
In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
In depth knowledge and experience of Wifi networking
In depth knowledge and experience of network topologies DMZ’s, WAN’s, etc.
Substantial knowledge of Splunk (or other SIEM’s)
Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
Knowledge of Computer Network Defense policies, procedures, and regulations
Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
Ability to identify and analyze anomalies in network traffic using metadata
Experience with reconstructing a malicious attack or activity based on network traffic
Experience examining network topologies to understand data flows through the network
Must be able to work collaboratively across physical locations
More at ARSIEM
Related open roles
Lab Manager I
United States · Onsite
Applications Developer III
United States · Onsite
Applications Developer III
United States · Onsite
Network Based Systems Analyst III
United States · Onsite
Junior Microsoft 365 Developer (Power Platform / SharePoint)
Remote · United States
364 - Senior Systems Engineer
United States · Onsite
