What are the responsibilities and job description for the Cybersecurity (CND) Analyst I position at MKS2 Technologies?
Founded in 2008, MKS2 Technologies has helped Federal government customers design, implement and sustain mission-focused IT solutions focusing on cyber security support, enterprise application development, and instructional design and training. MKS2 is a Service-Disabled Veteran-Owned Small Business (SDVOSB) headquartered in Austin, Texas, with regional offices in Colorado Springs, CO, Monterey, CA, Portland, ME, and Washington, D.C.
Our full-time staff works on Federal services contracts in 27 states and the District of Columbia to provide mission-critical support to the Department of Veterans Affairs, The U.S. Army, and the U.S. Navy.
In this position you will utilize Computer Network Defense/Cybersecurity tools, defensive measures, and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the enterprise network in order to protect information, Information Systems, and networks from threats. Responsibilities include:
- Identifying, analyzing, and mitigating threats to hosted information systems
- Investigating and analyzing response activities related to cyber incidents within the environment.
- Correlating incident data and performing CND trend analysis and reporting
- Developing and providing CND activity/incident reports, summaries, and other situational awareness information to present to the CIO or designated representatives.
- Developing and maintaining documentation as it pertains to the use and operation of CND tools (SOPs, playbooks, incident reporting, incident response, etc.)
- Executing a continuous monitoring and analysis strategy for host information systems to monitor and report on any indications of outsider and insider threats; watch for and report on unauthorized changes; and monitor the operational environment and report on any suspected intrusions
- Utilizing Splunk software to include Splunk Enterprise Security (ES) and Splunk User Behavior Analytics (UBA) for continuous monitoring, incident reviews, investigations, and event correlation
Qualifications
Experience Requirements:
- A minimum of one year of experience in Information Security (INFOSEC) operations experience and/or cybersecurity related experience is required
- 2 years of experience working in an operational Security Operations Center (SOC) as a cybersecurity professional is desired
- 2 years of experience working with industry standard solutions for some, or all, of the following: Security Information and Events Management (SIEM), Vulnerability Assessment and Management, Advanced Network Inspection/Analysis, Advanced Malware Detection, Data Loss Prevention (DLP), Incident Response, Forensics Tools, User Activity Monitoring (UAM), and User Behavioral Analytics (UBA) solutions is desired
Technical Requirements:
- Candidates must meet the Cyber IT/Cybersecurity Workforce (CSWF) SECNAV M-5239.2 requirements for this position. For more information visit: Navy Cool Cyber IT/CSWF Workforce Model.
Education: Bachelor's degree from accredited University. If no degree is held, qualified candidates must possess one of the following certifications*.
- CompTIA Security CE
- GIAC Security Essentials Certification (GSEC)
- Systems Security Certified Practitioner (SSCP)
*Other certifications may qualify as listed in the Navy Cool Cyber IT/CSWF Workforce Model.
Security Clearance
- This position will require an active DoD TS/SCI clearance; the ability to obtain and maintain a Counterintelligence (CI) Polygraph is required.