Cyber Defense Analyst
Amarillo, TX 
Share
Posted Today
Job Description

Location: Amarillo, TX or Oak Ridge, TN
Job Title: Cyber Defense Analyst
Career Level From: Senior Associate
Career Level To: Senior Specialist
Organization: Chief Information Security Off (50003144)
Job Specialty: Cyber Security

Location

This position is a hybrid role at the Pantex plant in Amarillo, TX. Some on-site work is required in this position. If offered the role, relocation assistance will be available.

What You'll Do

The Cyber Defense Analyst uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within CNS's networks for the purposes of mitigating threats. Job functions include:

  • Develop content for cyber defense tools
  • Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Coordinate with enterprise-wide cyber defense staff to validate network alerts
  • Document and escalate incidents (including event's history, status, and potential impact for further action) that may cause ongoing and immediate impact to the environment
  • Perform cyber defense trend analysis and reporting
  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack
  • Receive and analyze network alerts from various sources within the enterprise and determine possible causes of such alerts
  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
  • Use cyber defense tools for continual monitoring and analysis of system activity to identify malicious activity
  • Analyze identified malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information
  • Examine network topologies to understand data flows through the network
  • Reconstruct a malicious attack or activity based off network traffic
  • Provide daily summary reports of network events and activity relevant to cyber defense practices
  • Notify designated managers, cyber incident responders, and cybersecurity service provider team members of suspected cyber incidents and articulate the event's history, status, and potential impact for further action in accordance with the organization's cyber incident response plan.
  • Additional responsibilities as necessary
What You Can Expect
  • Meaningful work and unique opportunities to support missions vital to national and global security
  • Top-notch, dedicated colleagues
  • Generous pay and benefits with a stable organization
  • Career advancement and professional development programs
  • Work-life balance fostered through flexible work options and wellness initiatives
Minimum Job Requirements

Requires a Bachelor's degree in Computer Science, Information Security, Information Systems or a related field with at least two (2) years of relevant professional experience.

Ten or more years of education and/or relevant experience may be considered to satisfy educational and years-of-experience requirements for this posting.

  • Knowledge of computer networking concepts and protocols, and network security methodologies
  • Knowledge of cyber threats and vulnerabilities
  • Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption)
  • Knowledge of operating systems
  • Knowledge of network traffic analysis methods
  • Knowledge of the common attack vectors on the network layer
  • Strong problem solving and communication skills (both orally and in writing)
Preferred Job Requirements

Bachelor's degree in Computer Science, Information Security, Information Systems or a related field with at least two (2) years of relevant professional experience, and 5 years of cyber defense experience in an enterprise network environment.

  • Ability to recognize and categorize types of vulnerabilities and associated attacks
  • Knowledge of adversarial tactics, techniques, and procedures
  • Knowledge of intrusion detection methodologies and techniques for detecting host and network-based intrusions
  • Knowledge of authentication, authorization, and access control methods
  • Knowledge of network access, identity, and access management
  • Knowledge of system and application security threats and vulnerabilities
  • Knowledge of incident response and handling methodologies
  • Knowledge of Windows/Unix ports and services
  • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services
  • Knowledge of the use of sub-netting tools
  • Knowledge of Virtual Private Network (VPN) security
  • Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations
  • Experience using cyber defense, vulnerability assessment, and analysis tools, and familiarity with their capabilities
  • Experience with network tools (e.g., ping, traceroute, nslookup)
  • Relevant cybersecurity experience including SIEM operations, event management and incident management Experience
  • Ability to conduct vulnerability scans and recognize vulnerabilities in security systems
  • Ability to review logs to identify evidence of past intrusions
  • Ability to analyze malware
  • Ability to identify applications and operating systems of a network device based on network traffic
  • Ability to perform packet-level analysis
Notes
The minimum education and experience for the lowest career level in the job posting range are listed under Minimum Job Requirements. Successful candidates hired into a higher career level than the minimum in the range must meet the requirements listed in the job leveling charts for the career level into which they are being hired.

If a range of Career Levels is posted, i.e., Senior Associate to Senior Specialist, internal applicants already in one of the Career Levels would come across at their current Career Level. Internal applicants currently in a lower level Career Level would move to the lowest posted Career Level, and internal applicants in higher Career Levels may be considered, on an exception basis, to come across laterally based on the applicant's education and experience, and the scope of work being performed in the role.

Requires a Q clearance; however all qualified candidates will be considered regardless of their current clearance status. The ability to obtain and maintain a Department of Energy Q clearance is required.

Position may require entry into Materials Access Areas (MAA) and participation in the Human Reliability Program (HRP). If HRP is required, candidate must complete a counterintelligence-scope polygraph, pursuant to 10CFR 709. Medical requirements may apply.

CNS is a drug-free workplace. Candidates accepting a job offer will be required to pass a pre-placement physical, drug screening and background investigation. As an employee, you may be required to receive and maintain a security clearance from the United States Department of Energy in order to meet eligibility requirements for access to sensitive information or matter. U.S. citizenship is a requirement for security clearance applicants. All employees are subject to being randomly selected for drug testing without advance notification.
CNS is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, gender, sexual orientation, gender identity, age, religion, national origin, ancestry, genetic information, disability or veteran status.

 

Job Summary
Company
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Required Education
Bachelor's Degree
Required Experience
2 years
Email this Job to Yourself or a Friend
Indicates required fields