The Cyber Threat Detection Engineer SME shall have the following qualifications:
• In-depth knowledge of Firewalls/Proxies/Intrusion Detection Systems/ Domain Name Servers/DHCP/VPN and other network technologies and tools
• Experience updating, maintaining, and creating IDS variables within a complex enterprise network
• Expert in creating, modifying, tuning IDS signatures/SIEM Correlation Searches/yara rules and/or other detection signatures
• Familiarity with disk based forensic methodologies, Windows, and Linux forensic artifacts
• Experience with Endpoint Detection and Response (EDR) tools such as Carbon Black, Tanium, Crowdstrike, etc
• Able to create, modify, update, and maintain Python and Powershell scripts that enhance endpoint detection capabilities
• In-depth knowledge of attacker tactics, techniques, and procedures
• Author, test, and maintain automation scripts within SOAR platform
The candidate must currently possess a Secret Clearance. In addition to clearance requirement, all personnel must have a current or be able to favorably pass a 5 year background investigation (BI).
BS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience.
Should have 5 years of experience serving as a digital media analyst or as a computer forensic analyst.
Ability to work independently with minimal direction; self-starter/self-motivated
Must have one of the following:
CCFP – Certified Cyber Forensics Professional
CHFI – Computer Hacking Forensic Investigator
CISSP – Certified Information Systems Security
ECSA – EC-Council Certified Security Analyst
EnCE
GCFA – Forensic Analyst
GCFE – Forensic Examiner
GCIH – Incident Handler
GISF – Security Fundamentals
GREM – Reverse Engineering Malware
GXPN – Exploit Researcher and Advanced Penetration Tester
LPT – Licensed Penetration Tester
OSCE (Certified Expert)
OSCP (Certified Professional)
OSEE (Exploitation Expert)
OSWP (Wireless Professional)
CIRC
FIWE
WFE-E-CI
FTK-WFE-FTK
Preferred Qualifications:
One of the following certifications:
SANS Global Information Assurance Certification (GIAC) Certified Intrusion Analyst (GCIA)
SANS Global Information Assurance Certification (GIAC) Certified Forensic Analyst (GCFA)
SANS Global Information Assurance Certification (GIAC) Certified Network Forensic Analyst (GNFA)
Certified Information System Security Professional (CISSP)
Essential Requirements:
US Citizenship is required.
Active secret clearance.
ISYS Technologies is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected Veteran status, or disability status.
In compliance with Colorado’s Equal Pay for Equal Work Act, the annual base salary range for this position is listed . Please note that the salary information is a general guideline only. ISYS Technologies considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation.
While performing the duties of this job, the employee will regularly sit, walk, stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally, movement that requires twisting at the neck and/or trunk more than the average person, squatting/ stooping/kneeling, reaching above the head, and forward motion will be required. The employee will continuously be required to repeat the same hand, arm, or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close, distance, depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress.
ISYS Technologies is an Engineering and Information Technology Company focused on providing Services to the Federal and State Government. ISYS offers a competitive compensation program and comprehensive benefits package to our employees.