
Job Information
CACI International Cyber Security Analyst in Springfield, Virginia
Cyber Security Analyst
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
CACI's Transport & Cybersecurity (TCS) program has an immediate opportunity for a Cyber Security Analyst to join our (growing) Advanced Cybersecurity Analytics team in Springfield, VA! This position is on a long-term, CACI Prime contract supporting our Government Customer's GEOINT mission.
What You’ll Get to Do
You will provide advanced cybersecurity analytics (ACA) services which aggregates and analyzes products, data, and information to identify trends and patterns, anomalous activity, provide situational awareness of NGA’s networks, missions and threats, and provide operational recommendations, visualizations, tuning requests, and custom signature creation to the CSOC and other internal and external stakeholders.
More About the Role
Analyze trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents, and develop or tune rules/signatures/scripts as needed
Coordinate with other Cybersecurity Operations to develop or tune rules/signatures/scripts
Coordinate with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on NGA systems, and develop or tune rules/signatures/scripts as needed
Correlates and analyzes precursors to incidents, and develop or tune rules/signatures/scripts as needed
Improve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed
Assists the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise
Documents all work in the authorized ticketing system with a sufficient level of detail to ensure the Government and other contract services can systematically reconstruct the analysis
Provide input to the daily CSOC Significant Activity Report, the daily CSOC Operations Update, and the Weekly CSOC Status Report
You’ll Bring These Qualifications:
Clearance:
TS/SCI Clearance (current) with the ability to successfully pass/maintain Government Polygraph (post-hire).
Education / Experience
BA/BS Degree and Six (6) years of related advanced cyber security analytics work experience. Additional experience may be considered in lieu of degree.
Certifications:
DoD 8140.01 and DoD 8570.01-M IAT Level III compliant; CSSP Analyst certification must be obtained within 120 days of hire date.
Key Skills:
Data mining or building queries in a SIEM
Strong understanding of signature development and tuning
Strong understanding of network protocols and analysis with protocol analyzers
These Qualifications Would Be Nice to Have
Good working knowledge of regular expressions
Knowledge of static file signatures, i.e. "magic numbers"
Comfortable in a hex editor
Ability to write Python / Bash / PowerShell scripts
What We Can Offer You:
We’ve been named a Best Place to Work by the Washington Post.
Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives.
We offer competitive benefits and learning and development opportunities.
We are mission-oriented and ever vigilant in aligning our solutions with the nation’s highest priorities.
For over 55 years, the principles of CACI’s unique, character-based culture have been the driving force behind our success.
TCS2
Company Overview: At CACI, you will have the opportunity to make an immediate impact by providing information solutions and services in support of national security missions and government transformation for Intelligence, Defense, and Federal Civilian customers. CACI is an Equal Opportunity Employer – Females/Minorities/Protected Veterans/Individuals with Disabilities.
As a federal contractor, CACI is subject to any federal vaccine mandates or other customer vaccination requirements. All new hires are required to report their vaccination status.