Description: Responsible for maintaining the integrity and security of enterprise-wide cyber systems and networks. Supports cyber security initiatives through both predictive and reactive analysis, articulating emerging trends to leadership and staff. Coordinates resources during enterprise incident response efforts, driving incidents to timely and complete resolution. Employs advanced forensic tools and techniques for attack reconstruction, including dead system analysis and volatile data collection and analysis. Supports internal HR/Legal/Ethics investigations as forensic subject matter expert. Performs network traffic analysis utilizing raw packet data, net flow, IDS, and custom sensor output as it pertains to the cyber security of communications networks. Reviews threat data from various sources and develops custom signatures for Open Source IDS or other custom detection capabilities. Correlates actionable security events from various sources including Security Information Management System (SIMS) data and develops unique correlation techniques. Utilizes understanding of attack signatures, tactics, techniques and procedures associated with advanced threats. Develops analytical products fusing enterprise and all-source intelligence. May conduct malware analysis of attacker tools providing indicators for enterprise defensive measures, and reverse engineer attacker encoding protocols. Interfaces with external entities including law enforcement organizations, intelligence community organizations and other government agencies such as the Department of Defense.
- Thorough understanding of TCP/IP and common protocols such as SSH, HTTP/S, SMTP, RDP, DNS, S/FTP, DHCP, CIFS/NetBIOS, LDAP, and SNMP
- Must have a thorough understanding of the internet threat landscape and advanced persistent threats.
- Microsoft Windows, Linux (RHEL, Ubuntu).
- Solid understanding of Windows Active Directory, Group Policy, Configuration Management as well as common services such as SCCM, IIS, Exchange, Domain Controllers etc.
- Basic Scripting and/or Development Languages, such as Python, Shell Scripting
- Must be well spoken, customer oriented, and have experience as an engineering consultant.
Lockheed Martin is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.