logo inner

Host Based Systems Analyst SME


Gray Tier Technologies is looking for a Cyber Forensics Analysts to support the DHS Hunt and Incident Response Team (HIRT). This team secures the Nation’s cyber and communications infrastructure while providing front line response for cyber incidents and hunting for malicious cyber activity. Our team performs HIRT investigations to develop a diagnosis of the severity of breaches. Contract personnel provide front line response for digital forensics/incident response and proactively hunting for malicious cyber activity for this critical customer mission.
Responsibilities:- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack- Assesses network topology and device configurations identifying critical security concerns and providing security best practice recommendations- Collects network intrusion artifacts (e.g., PCAP, domains, URI’s, certificates, etc.) and uses discovered data to enable mitigation of potential incidents- Collects network device integrity data and analyze for signs of tampering or compromise- Analyzes identified malicious network and system log activity to determine weaknesses exploited, exploitation methods, effects on system and information- Tracking and documenting on-site incident response activities and providing updates to leadership through executive summaries and in-depth technical reports- Planning, coordinating and directing the inventory, examination and comprehensive technical analysis of computer related evidence- Serving as technical forensics liaison to stakeholders and explaining investigation detailsRequired Skills:- U.S.

Citizenship- Active DoD Secret clearance. Must be able to obtain a TS/SCI clearance.- Must be able to obtain DHS Suitability- 8+ years of directly relevant experience in cyber forensic and network investigations using leading edge technologies and industry standard forensic tools- Experience leading cross functional teams conducting cyber threat hunting activities- Experience with reconstructing a malicious attack or activity- Ability to characterize and analyze network traffic, identify anomalous activity / potential threats, analyze anomalies in network traffic using metadata- Ability to create forensically sound duplicates of evidence (forensic images)- Able to write cyber investigative reports documenting forensics findings- In depth knowledge and experience of:• utilizing COTS and custom developed tools to detect APT activity• reviewing threat reports and searching the network for applicable IOC (Indicators of Compromise)• identifying different classes and characterization of attacks and attack stages• CND policies, procedures and regulations• of network topologies, Wi-Fi Networking, and TCP/IP protocols• Splunk (or other SIEMs)• Vulnerability scanning, assessment and monitoring tools such as Security Center, Nessus, and Endgame• MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)- Must be able to work collaboratively across physical locations.Desired Skills:- Experience and proficiency with the following tools and techniques:• EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, and Snort• EDR Tools: Crowdstrike, Carbon Black, Etc• Carving and extracting information from PCAP data• Non-traditional network traffic: Command and Control• Preserving evidence integrity according to national standards• Designing cyber security systems and environments in a Linux environment• Virtualized environments• Conducting all-source researchRequired Education:BS Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 10+ years of host or digital forensics or network forensic experience.Desired Certifications:- GCFA, GCFE, EnCE, CCE, CFCE, CEH, CCNA, CCSP, CCIE, OSCP, GNFAOn-Site work 2-3 days per week

Life at Gray Tier Technologies

Thrive Here & What We Value- Demonstrates proficiency in DISN functions- Collaborative Environment- Focus on Technical Expertise and Innovation- Strong Commitment to National Security- Diverse Contract Team Supporting DoD Client- Fast-paced and agile environment- Customer-focused approach- Opportunity to build expertise and solve technical problems- Support of cyberspace operations- Mentorship and supervision opportunities</s>
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2025