Information Technology Specialist - Cyber Security Host Analyst
Current• Participate in threat hunting, clearing, and hardening missions• Evaluate host logs, network traffic logs, and NetFlow using analytical expertise to form data gathered from big data platforms like Gabriel Nimbus, DCO Splunk, and locally managed SIEM • Corroborate data gathered with intelligence resources and then craft reports that include graphical and statistical representation of relative data for presentation to peers, leadership, and for baselining as reference• Identify indicators of compromise and determine appropriate action to prioritize threats and make countermeasure recommendations to system owners• Use, install, and configure tools such as Event Viewer, Elasticsearch, Splunk, Tanium, Carbon Black, Security Onion, and Red Seal to identify anomalous behavior from network traffic and on host systems • Ensure patches, hot fixes, system change packages and current antivirus definitions are applied and in compliance with current Defense Information Systems Agency’s (DISA) Security Technical Implementation Guide (STIG)• Review doctrine, incident response plans, and other documentation and make recommendations to system owners and leadership for changes