NetWitness Cyber Incident Response Analyst (Senior)

Posted 2 Days Ago
Be an Early Applicant
Washington, DC
7+ Years Experience
Software
The Role
The NetWitness Cyber Incident Response Analyst will implement RSA NetWitness, perform binary analysis, provide technical support for incident response, analyze forensic artifacts from various operating systems, and create detailed reports on findings related to incidents and malware analysis.
Summary Generated by Built In

cFocus Software seeks a NetWitness Cyber Incident Response Analyst (Senior) to join our program supporting the Administrative Offices of the United States Courts in Washington, DC. This position requires an active Public Trust clearance.
Qualifications:

  • Bachelor’s Degree or equivalent experience in a computer, engineering, or science field.
  • Active Public Trust clearance.
  • NetWitness Certified XDR Administrator 
  • Hold active certifications such as GCIA or GCIH or GSEC or GMON, and Splunk Core Power User.
  • 7+ years of relevant experience.

Duties:

  • Assist with implementation of RSA NetWiitness 
  • Perform a binary analysis and produce a report on what are the exploits that could potentially be available to an attacker and countermeasures to mitigate the exposure of those exploits
  • Support the development of staff schedules and staffing forecasts for approval.
  • Ensure shift members follow the appropriate incident escalation and reporting procedures.
  • Provide support promptly and efficiently through front-line telephone and email communications.
  • Assist with knowledge management – Standard Operating Procedures and procedural support data.
  • Accept and respond to government technical requests through the AOUSC ITSM ticket (e.g., HEAT or ServiceNow) for advanced subject matter expert (SME) technical investigative support for real-time incident response (IR).
  • IR includes cloud-based and non-cloud-based applications such as: Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Cloud Access Security Brokers (e.g., Zscaler).
  • Create duplicates of evidence that ensure the original evidence is not unintentionally modified. AOUSC supplied procedures and tools shall be used to acquire the evidence.
  • Analyze forensic artifacts of operating systems (e.g., Windows, Linux, and macOS) to discover elements of an intrusion and identify root cause.
  • Perform live forensic analysis based on SIEM data (e.g., Splunk).
  • Perform filesystem timeline analysis for inclusion in forensic report.
  • Extract deleted data using data carving techniques.
  • Collect and analyze data from compromised systems using EDR agents and custom scripts provided by the AOUSC.
  • Perform static and dynamic malware analysis to discover indicators of compromise (IOC).
  • Analyze memory images to identify malicious patterns using Judiciary tools (e.g. Volatility). Analysis results documented in forensics report.
  • Write forensic and malware analysis reports.

Top Skills

Gcia
Gcih
Gmon
Gsec
Netwitness
Splunk
The Company
HQ: Largo, MD
25 Employees
On-site Workplace
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint.

cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365.

Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Jobs at Similar Companies

bet365 Logo bet365

Junior Sports Analyst

Digital Media • Gaming • Software • eSports • Automation
Denver, CO, USA
6100 Employees
55K-80K Annually

Jobba Trade Technologies, Inc. Logo Jobba Trade Technologies, Inc.

Customer Success Specialist

Cloud • Information Technology • Productivity • Professional Services • Software
Hybrid
Chicago, IL, USA
45 Employees

Similar Companies Hiring

TrainingPeaks (A Peaksware Company) Thumbnail
Software • Fitness
Louisville, CO
69 Employees
bet365 Thumbnail
Software • Gaming • eSports • Digital Media • Automation
Denver, Colorado
6100 Employees
Jobba Trade Technologies, Inc. Thumbnail
Software • Professional Services • Productivity • Information Technology • Cloud
Chicago, IL
45 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account