AGR, LLC · 4 weeks ago
Cyber Security Deception / Threat Hunter
AGR, LLC is seeking an experienced Senior Cyber Security Deception Engineer/Threat Hunter to join the Department of State Diplomatic Security Cyber Mission program. The role involves working with cross-functional teams to enhance security posture, performing advanced threat hunting, and responding to security events while implementing cybersecurity frameworks.
Responsibilities
Work closely with cross-functional teams, including Security Operations, Incident Response, Threat Intelligence, and Threat Hunting to ensure a proactive and robust security posture
Perform advanced network threat hunting to detect malicious or suspicious behavior on Department on-premises and cloud-based networks
Respond to security events received from CIRT, provide comprehensive findings and recommend remediation steps
Perform advanced traffic analysis (at the packet level) and reconstruction of network traffic to discover anomalies, trends, and patterns
Perform forensic analysis of suspected systems (e.g. on and off premise network devices, and storage media) impacted by malicious activity
Implement and use cyber security frameworks (e.g. MITRE-ATT&CK, Kill Chain, etc.)
Has proven expertise in performing analyses to validate established security requirements and recommended additional security requirements and safeguards
May interface with external entities including law enforcement, intelligence and other government organizations and agencies
Qualification
Required
A bachelor's degree and 9 years of experience, or 7 years of experience with a Master's. An additional 4 years of experience may be considered in lieu of degree
Possess one of the following certifications: CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, or SSCP
Proven ability to develop and recommend corrective actions
Expertise, knowledge, and experience integrating new architectural analysis of cyber security features
Comfortable interfacing with external entities including law enforcement, intelligence and other government organizations and agencies
Experience in threat hunting or network/cloud forensics
U.S. citizenship is required
Active Top Secret security clearance required
The ability to obtain a final TS/SCI
Preferred
Demonstrated experience performing static and dynamic analysis techniques
Experience using sandbox and other simulated networked environments for analysis
Ability to recommend sound counter measures to malware and other malicious type code and applications which exploit customer communication systems
Experience supporting the Department of State cyber security mission
Experience using Databricks
Experience using Artificial intelligence (AI) and large language models (LLMs)
Ability to create, troubleshoot, configure and operate complex scripting solutions with the ability to output the results in a variety of formats (e.g. HTML, XML, etc.) and to re-purpose the results for reports targeting different technical levels (e.g. other analysts, management, etc.)