Cloud Cyber Incident Response Analyst

  • ManTech
  • McLean, VA
  • Full-time
  • time-alarm-solid 2024-02-01T00:00:00Z
  • $134700 - $224700 year

Cloud Cyber Incident Response Analyst

Job Type: Full-time

Secure our Nation, Ignite your Future

Are you ready to safeguard one of the world's most critical targets ensuring the security of information systems against intentional or inadvertent access or destruction? Join ManTech and play a crucial role in protecting national security while working on cutting-edge projects that pave the way for professional growth.

ManTech is seeking a Azure Cyber Incident Responder. This position, offering primarily remote work, is your opportunity to lead incident response, detection engineering, and threat hunting activities. Employee must be able to complete a 6-week onsite training program in McLean, VA upon hire. Additional onsite requirements will include one multi-day training annually in Northern Virginia and the ability to attend meetings as needed in secured facilities located in McLean, VA or San Antonio, TX.

Responsibilities include, but are not limited to:

  • Execute cyber analysis and response, detection engineering, and automation in commercial cloud environments.
  • Develop metrics and reports to communicate identified risks to the customer's environment.
  • Create and refine SIEM dashboards for clear identification of findings scope or activity monitoring.
  • Identify patterns and outliers in data sets aligned with threat actor Tactics, Techniques, and Procedures (TTPs), post-compromise behavior, and unusual activities like insider threats.
  • Conduct dynamic and static malware analysis on samples obtained during incident handling or hunt operations to identify Indicators of Compromise (IOCs).
  • Track investigations to resolution and provide an after-action report as required.
  • Identify misuse, malware, or unauthorized activity on monitored networks
  • Analyze all relevant cyber security event data and other data sources for attack indicators and potential security breaches
  • Assist with coordination during incidents and identify intrusions using various detection and prevention systems and security event data sources on a 24x7x365 basis.
  • Analyze intrusion related data to determine root cause and identify follow on activity while coordinating with Incident Handlers, Hunters, and various partners.
  • Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs, to include NetFlow, metadata, and pcap analysis.
  • Contribute to the tuning and filtering of events and information, creating custom views and content using all available tools.
  • Contribute to the development of playbooks and procedures for handling each security event detected

Required Qualifications:

  • 5+ years of experience in Cyber Security, InfoSec, Security Engineering or Network Engineering with emphasis in cyber security issues and operations, computer incident response, systems architecture, data management.
  • Understanding of the following classes of enterprise cyber defense technologies: Security Information and Event Management (SIEM) systems such as Splunk ES, Elk, Sentinel, or Chronicle; Sysmon; Azure; AWS; GCP; Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS); Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS); Network and Host malware detection and prevention; Network and Host forensic applications; Web/Email gateway security technologies; Log aggregation tools.
  • Ability to demonstrate effective interpersonal, organizational, writing, communications, and briefing skills.
  • Ability to use analytical and problem-solving skills.
  • Ability to travel to ManTech offices for training and to customer site as needed for meetings
  • DOD 8570 IAT Level I or CSSP-A certification (can be obtained within 6 months of start date)
  • Active/Current TS/SCI with polygraph clearance

Preferred Requirements:

  • Bachelor’s Degree in Information Technology or related technical field of study

Security Clearance Requirement:

  • Active/Current TS/SCI with polygraph

Physical Requirements:

  • Must be able to remain in a stationary position 50%
  • Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer
  • The person in this position needs to occasionally move about inside the office to access file cabinets, office machinery, etc.

The projected compensation range for this position is $134,700-$224,700. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, ManTech invests in it’s employees beyond just compensation. ManTech’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, Short Term and Long Term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.

For all positions requiring access to technology/software source code that is subject to export control laws, employment with the company is contingent on either verifying U.S.-person status or obtaining any necessary license. The applicant will be required to answer certain questions for export control purposes and that information will be reviewed by compliance personnel to ensure compliance with federal law. ManTech may choose not to apply for a license for such individuals whose access to export-controlled technology or software source code may require authorization and may decline to proceed with an applicant on that basis alone.

If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech’s Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech’s utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services. If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access as a result of your disability. To request an accommodation please click [email protected] and submit your request.