Advanced Cybersecurity Analytics Engineer III
Job Description
CACI seeks an Advanced Cybersecurity Analytics Engineer III to design and maintain enterprise defensive countermeasures, analyze data to prevent breaches, and refine SIEM rules in collaboration with Defensive Cyber Operations and related teams.
Responsibilities
- Examine data trends across NGA networks to detect previously unseen events and incidents, and create or adjust rules, signatures, and scripts as needed.
- Collaborate with Defensive Cyber Operations and Focused Operations to develop or tune rules, signatures, and scripts.
- Work with Cybersecurity Operations Services to investigate potential sources of compromise on enterprise systems and update rules, signatures, and scripts as required.
- Correlate and analyze incident precursors to inform detections and adjust rules, signatures, and scripts.
- Partner with the Cyber Data Analytics team to optimize SIEM alert efficiency by validating alerts and reducing false positives, and refine rules, signatures, and scripts accordingly.
- Assist the Cyber Incident Response Team by assessing ongoing activity to anticipate adversary responses and locate compromises to aid triage.
- Document analyses and actions in the designated ticketing system with thorough detail to enable stakeholders to reproduce the workflow.
- Contribute to recurring meetings and briefings as required.
Requirements
- U.S. citizen with an active TS/SCI clearance.
- 8+ years of related advanced cybersecurity analytics experience.
- Certification compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.
- Experience mining data or building queries in a SIEM.
- Strong capability in signature development and tuning.
- Solid understanding of network protocols and analysis with protocol analyzers.
- Knowledge of static file signatures (magic numbers) and applying countermeasures for files in transit and on hosts.
- Proficiency with regular expressions.
Technologies
- Python
- Bash
- PowerShell
- Hex Editor
Benefits
- Healthcare
- Wellness
- Financial
- Retirement
- Family support
- Continuing education
- Time off benefits
- Learning resources
The Opportunity
Reporting to the Lead of Focused Operations under the Branch Chief of Defensive Cyber Operations, the role centers on developing and maintaining defensive countermeasures for the enterprise. In a Fusion model, you will collaborate with Focused Operations teams to proactively prevent compromises and eradicate persistent adversaries in the environment.
What You Can Expect
You will join a culture rooted in integrity and innovation, with autonomy supported by flexible time off and access to extensive learning resources. The organization emphasizes trust, values diverse contributions, and supports continuous growth as you advance in your career and contribute to national missions.
Location
- St. Louis, MO onsite
Pay Range
- $75,200 - $158,100 per year