Network Information Assurance
تفاصيل الوظيفة
Overview Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and 16,000 people work alongside our clients, here and abroad, to tackle their most complex challenges with integrity, respect, responsibility, and professionalism. Network Information Assurance specialist support Enterprise-class networks in the day-to-day operations in support of Computer Network Defense (CND), whose function is to deny adversaries access to information and information systems. The Network Information Assurance specialist is responsible for the operation and maintenance (O&M) of the technologies, to include, troubleshooting, optimization, administration, change management and technical documentation. The core network technology utilized is the McAfee Network Security Platform, which includes the Network Security Manager (NSM) and the physical Intrusion Prevention System appliances. Program: OMDAC-SWACA. This position offers company-paid housing and transportation, a completion bonus and tuition reimbursement program! You must satisfy all host country requirements to legally work in the host country in order to be qualified for this position. Responsibilities
- Provide enterprise-level O&M support as part of the DoDIN Defense-in-Depth strategy. This includes ensuring the NSM stays viable in its reporting capability as well as understanding, identifying and resolving varied appliance disconnects. Additionally, analysts develop an understanding of current and future attacks which will assist in determining the difference between a bonafide attack, verified suspicious or nuisance reconnaissance, and normal network noise.
- Perform blocking of Internet protocol (IP) networks when directed by the Government.
- Monitor, operate, and maintain network-based Intrusion Prevention System (IPS) sensors.
- Investigate possible network and Automated Information System (AIS) security events.
- Generate reports and update trouble tickets as required.
- Provide O&M support of the McAfee Network Security Platform (NSP), Network Security Manager (NSM) servers and IPS sensors (GUI and CLI).
- Analyze stock IPS alerts on all enclaves to ascertain if the alert should be put into block status.
- Create Access Control Lists (ACLs) (e.g. Firewall Policies) in the McAfee NSM for IP whitelisting.
- Develop custom IPS signatures using McAfee and/or Snort rule format in response to a recent or potential intrusion; or in response to security research performed by members of the IPS team for preventative measures.
- Perform in-depth analysis using SIEM to include but not limited to: Reports, Queries, Active Channels, Active Lists, Integration Commands, Data Monitors, Dashboards, Filters, Correlation Development using Rules, etc.
- Analyze potentially malicious traffic at the packet level using Wireshark.
- Respond to potentially malicious installed files on remote hosts by pulling down files via remote desktop for analysis, discovering what services are running on the remote host via command line, etc.
- Participate in CND exercises as requested by the Government to provide configuration and analysis of IPS alerts.
- Elevated account management of RCC-SWA personnel including certification validation and Army Training and Certification Tracking System (ATCTS) utilization.
- Utilize endpoint software to map software applications throughout the enclaves as well as to ensure appropriate versioning.
- The work environment will be 95% indoor and 5% outdoor.
- Perform additional duties as assigned.
- Qualifications:
- Security Clearance: Requires an active Secret Clearance.
- Education / Certification: One-year related experience can be substituted for one year of education if the degree is required.
- High school diploma required or equivalent.
- This position requires candidates to adhere to DoD 8570.01. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. Baseline certifications cannot also be used as a Computing Environment (CE) certification.
- The authorized certifications for this job title are listed as follows:
- IAT Level: Information Technology (IT) I / Information Assurance Technical (IAT) III.
- BASELINE:
- Cisco: CCNP Security.
- CompTIA: CASP+ ce: Advanced Security Practitioner.
- CompTIA: CySA+ ce: Cybersecurity Analyst.
- GIAC: GCED: Certified Enterprise Defender.
- GIAC: GCIH: Certified Incident Handler.
- ISACA: CISA: Certified Information Systems Auditor.
- ISC2: CCSP: Cloud Certified Security Practitioner.
- ISC2: CISSP ( or Associate ): Certified Information Systems Security Professional.
- COMPUTING ENVIRONMENT (CE):
- Cisco: CCIE: ( Any ).
- Cisco: CCNP: ( Any ).
- Microsoft: MCSA: Windows 10/11.
- Microsoft: MCSA: Windows Server 2016.
- Microsoft: MCSE: Cloud Platform and Infrastructure.
- Microsoft: MCSE: Database Management and Analytics.
- Microsoft: MCSE: Productivity.
- Microsoft: Certified: Azure Administrator Associate.
- Microsoft: Certified: Azure Security Engineer Associate.
- Microsoft: Certified: Azure Solutions Architect Expert.
- Microsoft: Certified: Identity and Access Administrator Associate.
- Microsoft: Certified: Information Protection Administrator Associate.
- Microsoft: Certified: Security Operations Analyst Associate.
- Experience: Requires a minimum of seven (7) years of experience in telecommunications sector.
Apply safely
To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.