Focused Cyber Threat Analyst
CurrentCYBER THREAT INTEL ANALYST:▪ Performing daily classified and unclassified IT/cyber research, identifying possible malware/ vulnerabilities and thousands of associated Indicators of Compromise (IoCs) that could negatively affect the DoS network▪ Experience aligning MITRE ATT&CK framework and Cybersecurity Kill Chain process to Incident Response workflows▪ Operate autonomously to further investigate and update tickets in accordance with protocols and contractual SLAs. Uphold and enforce established processes▪ Authors and provides daily threat intelligence reporting to senior IRM/CIC leadership, highlighting specific cyber vulnerabilities threatening the DoS network, OGAs and global communities of interest▪ Drafts weekly and monthly IoC reports for senior IRM leadership review; results: these executive summary presentations identify and define specific threats to the network and the corresponding level of CIC effort utilized to deter these threats▪ Utilizes Splunk SIEM software solutions to both manage potentially malicious activities and alert senior leadership in near real-time of attacks on the DoS enterprise network▪ Perform daily security event management operations via Splunk Enterprise; populates associated Threat Intel lookup tables with IoCs to alert the CIC and senior IRM staff of possible malicious activities▪ Serve as Point of Contact and Liaison for the CIC. Frequent briefings with Cybersecurity Intel Lead, Cybersecurity Program Manager and FTEs on notable threats