Job Information
Nightwing Cyber Incident Response Analyst IV in Sterling, Virginia
Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers’ most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets.
Nightwing provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for Nightwing and proactively hunt for malicious cyber activity as well as providing forensic analysis etc... We are seeking Cyber Network/Host/Cloud Forensics Analysts (NF/HF/CF) to support the Nightwing infrastructure, thus ensuring our ability to maintain critical support of all customer missions.
The Corporate Incident Response Team uses information collected from a variety of sources to identify network/host/cloud activity, and to analyze it for evidence of suspicious behavior. The Nightwing IR Team will work with and support the Nightwing SOC who performs monitoring and analysis to identify and report events that occur, or might occur, within the network, in order to protect information, information systems, and networks from threats. Additionally, the IR Team will also be an intermediary between the SOC and Nightwing IT Service Desk for all IR related activities that affect Nightwing; as well as working with the Nightwing Digital Forensic/IR, (DFIR) team for analysis support to include proper chain of custody of all data/evidence. The IR Team will facilitate process integration with All teams ensuring full IR visibility across Nightwing networks.
Responsibilities:
Conducting incident response for breaches, data exfiltration, hacking and malware investigations.
Correlating forensic findings to network events in support of developing an intrusion narrative
Performing forensic triage of an incident to include determining scope, urgency and potential impact
Tracking and documenting forensic analysis from initial participation through resolution
Conducting Insider threat investigations and Ransomware investigations
Performing Digital Forensics investigations on varied operating systems such as (but not limited to) Windows, Linux, UNIX, and Mac OSX.
Preserving evidence (collect, process, preserve, and store evidence to ensure proper chain of custody)
Log collection and disk imaging etc., Data Recovery, and eDiscovery
Collecting and documenting system state information (e.g. running processes, network connections) prior to imaging, as required
Assisting with the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave
Required Skills:
U.S. Citizenship
Must be able to obtain a TS/SCI clearance
8+ years of directly relevant experience in network/host forensic investigations
In depth knowledge of CND policies, procedures and regulations
In depth knowledge of TCP/IP protocols
In depth knowledge of standard protocols – ICMP, HTTP/S, DNS, SSH, SMTP, SMB, NFS, etc.
In depth knowledge and experience of Wifi networking
In depth knowledge and experience of network topologies - DMZ’s, WAN’s, etc.
Substantial knowledge of Splunk (or other SIEM’s)
Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
Detailed Technical Report writing experience
Ability to identify and analyze anomalies in network traffic using metadata
Experience with reconstructing a malicious attack or activity based on network traffic
Experience examining network topologies to understand data flows through the network
Must be able to work collaboratively across physical locations
Desired Skills:
Substantial knowledge of network device integrity concepts and methodologies
Proficiency with network analysis software (e.g. Wireshark)
Proficiency with carving and extracting information from PCAP data
Proficiency with non-traditional network traffic (e.g. Command and Control)
Proficiency with preserving evidence integrity according to standard operating procedures or national standards
Proficiency with virtualized environments
Proficiency with one or more EDR Tools: CrowdStrike, SentinelOne, Microsoft MDE, or Trellix
Proficiency with one or more of the following tools: Host forensic software (EnCase, FTK, X-Ways, Sleuth Kit/Autopsy), SIFT, Volatility, KAPE
Experience with Web/client-based applications, and databases including Sybase, Oracle, MS SQL, and Postgres
Scripting experience with Python, Bash, PowerShell etc.
Understanding of SaaS, PaaS and IaaS in the Cloud environment
Required Education:
BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 16+ years of network investigations experience.
Desired Certifications: (One or More)
- DoD 8140.01 IAT Level III, IASAE III, CSSP Analyst, CSSP Analyst/CSSP Incident Responder, CEH, GCIA, GCIH, GNFA, GREM, CISSP, GCFE, GCFA, GCLD, GCPS, GCPN, GWEB, GIRD, GSEC, Kubernetes Security Specialist, Microsoft 365 Certifications, Microsoft Azure Certifications, AWS Certifications, SANS Cloud Courses (SEC488, SEC541, SEC549, SEC588) and Network+, SecurityDulles, VA
Previously part of a leading Fortune 100 company and headquartered in Dulles, VA; Nightwing became independent in 2024 but continues to support the nation’s most mission impactful initiatives.
When we formed Nightwing, we brought a deep set of credentials and an unfaltering commitment to the mission. For over four decades, our team has been providing some of the world’s most technically advanced full-spectrum cyber, data operations, systems integration and intelligence support services to the U.S. government on its most important missions.
At Nightwing, we value collaboration and teamwork. You’ll have the opportunity to work alongside talented individuals who are passionate about what they do. Together, we’ll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.
Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.
At Nightwing, we value collaboration and teamwork. You’ll have the opportunity to work alongside talented individuals who are passionate about what they do. Together, we’ll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.
Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.
Nightwing is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.