GSM-O provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of the Department of Defense (DoD) and Combatant Commands (COCOMs). PRIMARY RESPONSIBILITIES:
- Direct and track enterprise countermeasure actions and assess the effectiveness of countermeasures on an ongoing basis.
- Analyze high volumes of logs, network data (e.g. Netflow, PCAP), and other attack artifacts in support of incident investigations.
- Understand the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
- Collaborate with team members and Subject Matter Experts (SMEs) to create and validate countermeasures in accordance with (IAW) the DoDIN boundary defense posture.
- Maintain situational awareness of cyber activity by reviewing DoD, Intelligence Community and open source reporting for new vulnerabilities, malware or other threats that have the potential to impact the DoDIN. QUALIFICATIONS:
- Bachelor’s degree from an accredited college in a related discipline and 8+ years of professional experience; additional related years of experience is accepted in lieu of a degree.
- Must have a DoD-8570 IAT Level 2 baseline certification (Security+ CE or equivalent) to start and must obtain a CSSP-A certification within 180 days of start date.
- Proficient understanding of Cyber Network Defense (CND) in regards to protect, detect, respond and sustain within a Computer Incident Response organization.
- Advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
- Must have an active TS/SCI clearance. PREFERRED QUALIFICATIONS:
- Experience with DISA and DoD Networks.
- Experience with malware analysis concepts and methods.
- Advanced Certifications such as SANS GIAC/GCIA/GCIH, CISSP or CASP.
- Experience in intelligence driven defense and/or cyber Kill Chain methodology GSMO External Referral External Referral Bonus: Eligible Potential for Telework: No Clearance Level Required: Top Secret/SCI Travel: Yes, 10% of the time Scheduled Weekly Hours: 40 Shift: Day Requisition Category: Professional Job Family: Cyber Operations