CACI International
Cyber Incident Response Analyst (SME)
CACI International, Hampton, Virginia, United States, 23661
Overview
Cyber Incident Response Analyst (SME) on the DCGS Management Center (DMC) program located at Langley AFB. The role requires a strong system administration background, Windows and Linux experience, hands-on ELK/Elastic Stack for threat detection, and the ability to follow established Incident Response processes with minimal supervision. This position is onsite with shift work. Responsibilities
Lead and assist in incident response investigations through all phases (detection, containment, eradication, recovery, lessons learned) to ensure the confidentiality, integrity, and availability of the OA DCGS weapon system. Utilize ELK/Elastic Stack to perform log analysis, threat detection, and investigations; create and maintain security incident reports and dashboards. Escalate and document internal/external security incidents through appropriate ticketing and reporting processing. Design, implement, and maintain cybersecurity SOPs and incident playbooks. Maintain documentation of IR processes and case notes; ensure security testing and evaluations are completed and properly documented. Support proactive threat hunting and vulnerability assessments. Analyze and correlate logs from varied data sources to identify patterns and anomalies. Understand network protocols and establish baselines to identify abnormal activity. Perform cyber threat analysis and reporting on information from internal and external sources and apply cyber threat intelligence to defending the enterprise network. Apply knowledge of Zero-Day vulnerabilities and CVEs to incident handling and remediation. Collaborate with cross-functional teams and external stakeholders as needed. Provide guidance for securing information systems and support cyber vulnerability penetration assessments. Operate independently during shifts and respond to security alerts with urgency. Qualifications
Required: Top Secret/SCI security clearance. Bachelor’s degree in IT Technology, Computer Science, or related field with 4+ years of experience. Degree may be substituted with additional years of experience. DOD 8140 (8570) IAT Level II (Security+ or equivalent). Strong system administration skills across Windows and Linux platforms. In-depth understanding of the Incident Response lifecycle. Proficiency in using the Elastic Stack (Elasticsearch, Logstash, Kibana). Familiarity with enterprise security tools and procedures. Strong problem-solving and analytical skills. Comfortable working with limited supervision in a shift-work setting. Availability to work weekends and holidays as part of our 24/7 operations. Desired: AF DCGS experience. Four to seven years of intelligence network communications or Systems Administration experience. Knowledge of security best practices and standards, including NIST, ISO, and SOC operations. Experience with AWS and/or other cloud security platforms. Background as an ISSO, including STIG/SCAP and vulnerability management. Familiarity with tools such as Tanium, Trellix, and ACAS. Understanding of network architecture and traffic analysis. Basic scripting skills (Python, PowerShell, Bash). Elastic certification or SME-level expertise. Effective written and verbal communication skills for documentation and collaboration. What You Can Expect
CACI offers a culture of integrity, trust, and growth. You’ll be part of a high-performing team dedicated to our customers\' missions and the safety of our nation, with flexible time off and robust learning resources. We support continuous growth and offer a comprehensive benefits package including healthcare, retirement, and education benefits. Learn more about CACI here. Pay and Equal Opportunity
The proposed salary range for this position is $75,200-$158,100, commensurate with location, experience, and qualifications. CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
#J-18808-Ljbffr
Cyber Incident Response Analyst (SME) on the DCGS Management Center (DMC) program located at Langley AFB. The role requires a strong system administration background, Windows and Linux experience, hands-on ELK/Elastic Stack for threat detection, and the ability to follow established Incident Response processes with minimal supervision. This position is onsite with shift work. Responsibilities
Lead and assist in incident response investigations through all phases (detection, containment, eradication, recovery, lessons learned) to ensure the confidentiality, integrity, and availability of the OA DCGS weapon system. Utilize ELK/Elastic Stack to perform log analysis, threat detection, and investigations; create and maintain security incident reports and dashboards. Escalate and document internal/external security incidents through appropriate ticketing and reporting processing. Design, implement, and maintain cybersecurity SOPs and incident playbooks. Maintain documentation of IR processes and case notes; ensure security testing and evaluations are completed and properly documented. Support proactive threat hunting and vulnerability assessments. Analyze and correlate logs from varied data sources to identify patterns and anomalies. Understand network protocols and establish baselines to identify abnormal activity. Perform cyber threat analysis and reporting on information from internal and external sources and apply cyber threat intelligence to defending the enterprise network. Apply knowledge of Zero-Day vulnerabilities and CVEs to incident handling and remediation. Collaborate with cross-functional teams and external stakeholders as needed. Provide guidance for securing information systems and support cyber vulnerability penetration assessments. Operate independently during shifts and respond to security alerts with urgency. Qualifications
Required: Top Secret/SCI security clearance. Bachelor’s degree in IT Technology, Computer Science, or related field with 4+ years of experience. Degree may be substituted with additional years of experience. DOD 8140 (8570) IAT Level II (Security+ or equivalent). Strong system administration skills across Windows and Linux platforms. In-depth understanding of the Incident Response lifecycle. Proficiency in using the Elastic Stack (Elasticsearch, Logstash, Kibana). Familiarity with enterprise security tools and procedures. Strong problem-solving and analytical skills. Comfortable working with limited supervision in a shift-work setting. Availability to work weekends and holidays as part of our 24/7 operations. Desired: AF DCGS experience. Four to seven years of intelligence network communications or Systems Administration experience. Knowledge of security best practices and standards, including NIST, ISO, and SOC operations. Experience with AWS and/or other cloud security platforms. Background as an ISSO, including STIG/SCAP and vulnerability management. Familiarity with tools such as Tanium, Trellix, and ACAS. Understanding of network architecture and traffic analysis. Basic scripting skills (Python, PowerShell, Bash). Elastic certification or SME-level expertise. Effective written and verbal communication skills for documentation and collaboration. What You Can Expect
CACI offers a culture of integrity, trust, and growth. You’ll be part of a high-performing team dedicated to our customers\' missions and the safety of our nation, with flexible time off and robust learning resources. We support continuous growth and offer a comprehensive benefits package including healthcare, retirement, and education benefits. Learn more about CACI here. Pay and Equal Opportunity
The proposed salary range for this position is $75,200-$158,100, commensurate with location, experience, and qualifications. CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
#J-18808-Ljbffr