Cyber Network Defender
Current• Timely detection, identification, and alerting of possible attacks, intrusions, anomalous activities, and misuse activities • Use of cyber defense tools for continual monitoring and analysis of systems to identify malicious activity • Documentation and escalation of incidents that may cause ongoing and immediate impact to the environment • Analysis of identified malicious activity to determine weaknesses exploited, exploitation methods, and effects on systems and information • Event correlation using information gathered from various sources within the enterprise to gain situational awareness and determine the effectiveness of observed attacks • Research, analysis, and correlation across a wide variety of all-source data sets • Receipt and analysis of network alerts from various sources within the enterprise to determine possible causes of such alerts • Performance of cyber defense trend analysis and reporting • Characterization and analysis of network traffic to identify anomalous activity and potential threats to network resources • Coordination with enterprise-wide cyber defense staff to validate network alerts • Identification and analysis of anomalies in network traffic using metadata • Provision of daily summary reports of network events and activity relevant to cyber defense practices