XOR Security is currently seeking a Network Security Specialist to support an Agency-level SOC. The SOC program provides comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. To support this vital mission, XOR staff are on the forefront of providing Advanced CND Operations, and Systems Engineering support to include the development of advanced analytics and countermeasures to protect critical assets from hostile adversaries. To ensure the integrity, security, and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, analysis and incident response. Strong written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP’s, Threat Actors, Campaigns, and Observables with experience in complex malware analysis techniques, scripting, coding, and content development. Examples of complex analysis techniques include malware de-obfuscation, examining code, sandbox/dynamic analysis, and memory analysis.
- Perform analysis of log files from a variety of sources (e.g., network traffic logs, firewall logs, intrusion detection system logs, Domain Name System (DNS) logs) to identify possible threats to network security.
- Collect network intrusion artifacts (e.g., domains, Uniform Resource Identifiers (URIs), certificates, etc.) and use discovered data to enable mitigation of potential CND hunts and incidents.
- Analyze identified malicious network activity to determine weaknesses exploited, exploitation methods, effects on system and information.
- Identify and document network based tactics, techniques, and procedures used by an attacker to gain unauthorized system access.
- Track and document CND incidents from initial detection through final resolution.
- Perform real-time CND Incident Handling (i.e. forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support deployable incident response teams.
- Create and disseminate technical reports in response to conducted analysis.
- Write and publish CND guidance and reports (e.g. engagement reports) on incident findings to appropriate constituencies.
- Assist with developing and maintaining SOPs.
- Participate in inter-agency sponsored community of interest analysis groups, participate in technical briefings and exchanges.
- Serve as technical expert and liaison to leadership, NCCIC, the IC, and law enforcement personnel explaining incident details as required.
- Manual review network device configurations for suspicious configurations or signs of compromise.
- Assess network topology and device configurations identifying critical security concerns and providing security best practice recommendations
- Collect network device integrity data, utilizing specialized tools, to detect unauthorized access (login access, configuration changes, interface changes, physical access, unscheduled reboots, blocked attempts, downgraded encryption, etc.).
- Collect network device integrity data, utilizing specialized tools, to detect software modifications (file verification, online/offline hash, published hashed, memory verification, firmware verification, rootkit detection).
- Collect network device integrity data, utilizing specialized tools, to detect hardware modifications (operating statistics, network traffic analysis).
- Support network device integrity analysis on multi-vendor products (e.g. Cisco, Juniper, HP, Dell, etc.).
- Divert/deploy teams of contractor resources to provide on-site support and assistance in the event of an exercise or cyber incident.
XOR Security offers a very competitive benefits package including health insurance coverage from the first day of employment, 401k with a vested company match, vacation and supplemental insurance benefits.
XOR Security is an Equal Opportunity Employer (EOE). M/F/D/V.
Citizenship Clearance Requirement
Applicants selected may be subject to a government security investigation and must meet eligibility requirements - US CITIZENSHIP and ACTIVE TOP SECRET CLEARANCE REQUIRED.