As an Operations Watch Analyst, you will isolate, investigate, inform, and implement measures to detect and protect data across a wide spectrum of sources and locations.
Requirements
- Maintains familiarity with CJCSM 6510.01B
- Compiles and maintains internal standard operating procedure (SOP) documentation
- Ensures associated documentation and capabilities remain compliant with CJCSM 6510.01B and other applicable policy directives
- Provides network intrusion detection and monitoring, correlation analysis, incident response and support for the Cybersecurity Service Provider (CSSP) and its subscriber sites
- Validates suspicious events or reports and determine if the event constitutes an incident and properly enter associated data into the appropriate reporting systems
- Coordinates with JFHQ-DoDIN and supported entities regarding significant incidents to ensure proper analysis is performed and timely and accurate reporting of the incident is completed
- Provides 24x7 support for the CSSP’s Incident Response capability during non-core business hours consistent with CSSP requirements as needed
- Performs network and host-based digital forensics on Microsoft Windows based systems and other operating systems as necessary to enhance response to, support of, and investigation into significant network incidents
- Possesses working knowledge of full packet capture PCAP analysis and accompanying tools (Wireshark, etc.)
- Explores patterns in network and system activity via log correlation using Splunk and supplemental tools
- Possesses understanding of IDS/IPS solutions to include signature development and implementation
- Participates in program reviews, product evaluations, and onsite certification evaluations
- Overtime may be required as needed to support incident response actions (Surge)
- Due to the nature of the work required, operations are conducted 24/7/365 with three primary shifts
Benefits
- Comprehensive Physical Wellness Package
- 401k Retirement Plan with Matching Contribution
- Annual Training Budget
- Eleven Federal Holidays
- Three weeks of PTO/vacation/sick leave
- Employee Assistance Program