The incumbent will report to the FLDS’ incident response lead and investigate, analyze and respond to cyber incidents within the agency’s network environment.
Additional job functions and responsibilities include:
- Providing targeted attack detection and analysis and developing custom signatures, SIEM/EDR queries and analytics to help identify attacks
- Leading and facilitating investigatory processes with mission partners by identifying root causes for security events, evaluating anomalous activity and tuning for frequent false positives
- Providing forensic analysis of network packet captures, live memory captures, drive acquisitions, malware and logs from various types of security sensors, applications and operating systems
- Participating in security architecture reviews for new projects to ensure proposed solutions align with risk requirements
- Participating in the design and execution of vulnerability assessments, penetration tests and security audits
- Ability to accurately define incidents, problems and events within the agency’s trouble ticketing system
- Knowledge of local area and wide area networking principles and concepts, including bandwidth management
- Skill in configuring and utilizing software-based computer protection tools such as software firewalls, antivirus software and anti-spyware
- Knowledge of computer networking concepts, protocols and network security methodologies
- Ability to operate standard network tools such as ping, traceroute and nslookup