Job Description
Key Role:
Support cyber analytics product development, threat analysis, statistical analysis, model development and direct customer mission support. Maintain responsibility for designing, building, and maintaining IDS/IPS capabilities that enable cyber hunt activities for enterprise teams responsible for active hunting for threats and reporting on findings, and supporting partner technologies including EDR, NDR, DLP, and others. Maintain responsibility for architecting, engineering, and operating capabilities to support Cyber Hunt analysts. Maintain responsibility for converting tools, techniques, and processes into automated capabilities, and collecting customer Cyber Operations requirements, generating use cases, providing Cyber SME support and system training to end users.
Basic Qualifications:
- 5+ years of experience with Linux System Architecture, Engineering, Design, and Support such as RHEL, CentOS, or Oracle Linux
- 2+ years of experience with Suricata, Snort, Zeek, FireEye HX, Endgame, or Corelight
- Experience architecting, Engineering, Deploying, or Sustaining Network Traffic Analysis tools leveraging both Open Source and Commercial Off the Shelf Capabilities
- Experience with implementing STIG, NIST, or OSCAP frameworks on Linux Operating Systems and with reading and interpreting signatures such as SNORT, SIGMA, Yara, YML, or XML
- Experience with data flow and tooling configurations for connections in SIEMs such as Splunk, Q-Radar, ArcSight, or ELK
- Knowledge of network traffic analysis methods such as TCP-DUMP, Wireshark, or Bro/Zeek, and core networking fundamentals such as TCP-IP or OSI Model
- Active TS/SCI clearance; willingness to take a polygraph exam
- HS diploma or GED and 12+ years of experience with supporting IT projects and activities, Associate’s degree and 10+ years of experience with supporting IT projects and activities, Bachelor’s degree and 8+ years of experience with supporting IT projects and activities, or Master’s degree and 6+ years of experience with supporting IT projects and activities
- DoD 8570.01-M Information Assurance Technician (IAT) Level II certification, including Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND
- Ability to obtain a DoD 8570.01-M Cybersecurity Service Provider (CSSP) - Infrastructure Support (IS) certification, including CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND within 60 days of hire
Additional Qualifications:
- Experience with collecting data from a variety of cyber defense resources such as CVE or OSINT
- Experience in various query languages such as SQL, Lucene, JEXL, or KQL
- Experience with dashboarding and visualizations such as Power-Bi, Superset, or Kibana
- Experience with SOARs such as Sentinel, CORTEX, or X-SOAR
- Experience with cloud providers and environments such as Azure, AWS, or Google Cloud Platform
- Experience developing and deploying threat detection signatures and detecting host and network-based intrusions
- Experience recognizing and categorizing types of vulnerabilities and associated attacks
- Experience scripting in PowerShell and BASH command line interfaces or in Python or Perl scripting languages
- Experience designing, building, deploying, and maintaining infrastructure in cloud environments with tools such as GitLab CI, Ansible Tower, JIRA, Jenkins, or Satellite
- Experience with VMware, ESXi, and vSphere
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $75,600.00 to $172,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity Statement
As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
- If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
- If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.
EEO Commitment
We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.