Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber Security Analyst (S-NET) image - Rise Careers
Job details

Cyber Security Analyst (S-NET)

Overview

Abile Group has an exciting and challenging opportunity for a Cyber Security Analyst (S-NET) supporting an Intelligence Community Customer. 

 

The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

Responsibilities

  • Performs technical analysis on a wide range of cybersecurity issues, with a focus on network activity, host activity, and data. This includes, but is not limited to: network flow (i.e. netflow) or related forms of session summary data, signature-based IDS/IPS alert/event data, full packet capture (PCAP) data, proxy and application server logs (various types).
  • Triages IDS/IPS alerts, collects related data from various systems, reviews open and closed source information on related threats & vulnerabilities, diagnose observed activity for likelihood of system infection, compromise or unintended/high-risk exposure.
  • Prepares analysis reports detailing background, observables, analysis process & criteria, and conclusions.
  • Analyzes large volumes of network flow data for specific patterns/characteristics or general anomalies, to trend network activity and to correlate flow data with other types of data or reporting regarding enterprise-wide network activity.
  • Leverages lightweight programming/scripting skills to automate data-parsing and simple analytics. Documents key event details and analytic findings in analysis reports and incident management systems. Identifies, extracts and characterizes network indicators from cyber threat intelligence sources, incident reporting and published technical advisories/bulletins.
  • Assesses cyber indicators/observables for technical relevance, accuracy, and potential value/risk/reliability in monitoring systems. Recommends detection and prevention/mitigation signatures and actions as part of a layered defensive strategy leveraging multiple capabilities and data types.
  • Develops IDS/IPS signatures, tests and tunes signature syntax, deploys signatures to operational sensors, and monitors and tunes signature and sensor performance.
  • Fuses open-source threat & vulnerability information with data collected from sensors across the enterprise into cohesive and comprehensive analysis.
  • Develops security metrics and trend analysis reports.

Qualifications

Clearance Required: TS/SCI.

 

Degree and Years of Experience: 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD.

  • 1+ year in a SOC or Incident Response role.

Required Certifications:  

  • Current DoD 8570.1-M IAT Level II certification.

Desired Certifications:

  • CEH, GCIH, GCIA, GCFA.

Desired Skills:

  • Experience with Cisco Firepower, Cisco Sourcefire, Cisco Advanced Malware Protection, Cisco Stealthwatch, Cisco Umbrella.
  • Experience with deploying and writing signatures (Snort, YARA, HIPS).
  • Experience with network hunting utilizing Zeek/Bro.
  • Experience with McAfee ePO, HBSS.
  • Splunk: Create log searches, dashboards, setting up alerts, and scheduled reports to help detect and remediate security concerns.
  • Experience with ArcSight.
  • Experience with Wireshark and packet analysis.
  • Experience with Tanium or other endpoint solutions.
  • Working knowledge of scripting languages such as Python, PowerShell, Shell.
  • Knowledge of Regular Expressions.
  • Knowledge of server and client operating systems.
  • Participate in development and reporting of security metrics.
  • Experience in a SOC or Incident Response role.

About Abile Group, Inc.

Abile Group, Inc. was formed in July 2004 to partner with the Intelligence Community and their Contractors in the areas of Enterprise Analytics & Performance Management, IT & Systems Engineering and Program & Project Management. We have significant experience with the Federal Government and are an EDWOSB dedicated to our employees and clients.  We are looking for high performing employees who enjoy providing advice and guidance along with solutions development and implementation support, crafted by combining industry best practices with the clients’ subject matter experience and Abile’s breadth of expertise. 

Hiring Statement

Abile is committed to hiring the most qualified and best fit person for the job - always has, always will. Anyone requiring reasonable accommodations should email careers@abilegroup.com with requested details. A member of the HR team will respond to your request within 2 business days. 

 

Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.

Average salary estimate

$95000 / YEARLY (est.)
min
max
$80000K
$110000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber Security Analyst (S-NET), Abile Group

Join Abile Group as a Cyber Security Analyst (S-NET) and dive into an exciting world of cybersecurity! Based in Annapolis Junction, you'll be at the forefront of protecting our Intelligence Community customer. This role offers you the chance to perform detailed technical analysis on a variety of cybersecurity issues. You'll focus on network and host activities, examining network flow data, packet captures, and server logs to safeguard vital information and systems. Your responsibilities will also include triaging alerts from Intrusion Detection Systems and analyzing large sets of network flow data for trends and anomalies. With your solid background in scripting and programming, you'll automate data processes, document findings, and recommend security measures to enhance our defenses. Collaborate with a talented team and use tools such as Cisco Firepower and Splunk among others, to make a real impact in cybersecurity. With 5 to 8 years of experience required, you'll be bringing your expertise to a company that values not just talent but also dedication and a passion for the field. Your efforts will contribute to developing cutting-edge security metrics and reports, shaping the future of cyber defense. Join us at Abile Group and help maintain the integrity of our national cybersecurity efforts while you develop professionally within a supportive and dynamic workforce.

Frequently Asked Questions (FAQs) for Cyber Security Analyst (S-NET) Role at Abile Group
What responsibilities does a Cyber Security Analyst (S-NET) have at Abile Group?

As a Cyber Security Analyst (S-NET) at Abile Group, your primary responsibilities include performing in-depth technical analyses of cybersecurity threats, with a focus on analyzing network and host activities and evaluating complex data sources. You'll deal with alerts from IDS/IPS systems, prepare detailed analysis reports, and develop security metrics to enhance the overall cybersecurity posture for our Intelligence Community customers.

Join Rise to see the full answer
What qualifications are required for the position of Cyber Security Analyst (S-NET) at Abile Group?

To qualify for the Cyber Security Analyst (S-NET) role at Abile Group, candidates need 5 to 8 years of experience with a BS/BA degree or 3 to 5 years with an MS/MA. A required TS/SCI clearance, DoD 8570.1-M IAT Level II certification, and familiarity with tools like Cisco Firepower and Splunk are vital. Experience in a Security Operations Center (SOC) or Incident Response role is also essential.

Join Rise to see the full answer
What tools and technologies should a Cyber Security Analyst (S-NET) be familiar with at Abile Group?

A Cyber Security Analyst (S-NET) at Abile Group should be comfortable using various cybersecurity tools, including Cisco Firepower, Cisco Sourcefire, and network hunting technologies like Zeek/Bro. Familiarity with Splunk for log searches and dashboards, Wireshark for packet analysis, and scripting languages such as Python and PowerShell is also advantageous for effective performance in this role.

Join Rise to see the full answer
How does Abile Group support professional development for Cyber Security Analysts?

Abile Group places a strong emphasis on professional development for Cyber Security Analysts (S-NET) by providing opportunities for continuous learning and training in the field. Employees are encouraged to pursue certifications, engage in collaborative projects, and participate in performance management initiatives that foster growth and expertise in cybersecurity practices.

Join Rise to see the full answer
What does the work environment look like for a Cyber Security Analyst (S-NET) at Abile Group?

The work environment for a Cyber Security Analyst (S-NET) at Abile Group is dynamic and collaborative, often involving team-focused problem-solving and knowledge sharing. With a commitment to maintaining the highest cybersecurity standards, analysts work in a supportive atmosphere where teamwork, mentorship, and professional growth are prioritized, all while directly impacting the security of our national interests.

Join Rise to see the full answer
Common Interview Questions for Cyber Security Analyst (S-NET)
What steps do you take to investigate a potential security breach?

In responding to a potential security breach, begin by gathering all relevant data, including network logs and IDS/IPS alerts. Analyze the indicators of compromise, assess the extent of the breach, and ensure to document every step thoroughly. Your answer should also reflect a structured approach to incident response, highlighting your experience with similar scenarios.

Join Rise to see the full answer
Can you explain the difference between symmetric and asymmetric encryption?

Symmetric encryption uses a single key for both encryption and decryption, making it faster but potentially less secure if the key is compromised. Asymmetric encryption, on the other hand, uses a pair of keys - a public key for encryption and a private key for decryption, enhancing security. Make sure to communicate real-world implications of both in your answer.

Join Rise to see the full answer
What is your experience with intrusion detection systems?

My experience with intrusion detection systems involves setting up and managing IDS/IPS technologies, analyzing alerts generated, and correlating those with data from various sources to detect potential threats. Highlight specific tools like Cisco Sourcefire or Snort that you have successfully utilized in previous roles.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats?

I regularly monitor cybersecurity news sources, participate in relevant forums, and collaborate with industry peers to stay informed about emerging threats. Subscribing to threat intelligence feeds and engaging in continuous learning through courses and certifications also helps me stay ahead of the curve.

Join Rise to see the full answer
Describe your experience with security incident reporting.

I've developed comprehensive security incident reports that include an analysis of the event, potential damage assessment, and recommendations for prevention. It's crucial that these reports are actionable and well-documented, allowing for future learning opportunities for the team.

Join Rise to see the full answer
What methodologies do you use for network traffic analysis?

I employ a combination of packet capture analysis using tools like Wireshark and netflow analysis to identify patterns or anomalies. My methodology involves both statistical analysis and behavior assessments of network traffic to detect potential intrusions effectively.

Join Rise to see the full answer
What scripting languages are you proficient in and how do you use them in your role?

I'm proficient in Python and PowerShell, which I use to automate data collection, conduct network analysis, and streamline reporting processes. Discuss specific examples where scripting improved efficiency in your workflows, showcasing your technical skills.

Join Rise to see the full answer
Can you explain what a false positive is in the context of security alerts?

A false positive in security alerts occurs when the system incorrectly identifies a benign event as a threat. It's crucial to minimize false positives to reduce alert fatigue and ensure that actual threats are prioritized. Discuss methods you've used to tune detection systems to lower false positive rates.

Join Rise to see the full answer
How do you prioritize security tasks in a high-pressure environment?

I prioritize security tasks by evaluating the potential impact and urgency of each situation. I use risk assessment frameworks to assign priority levels, ensuring critical vulnerabilities are addressed promptly, and communicate effectively with my team to manage workloads.

Join Rise to see the full answer
What experience do you have with vulnerability assessments?

I have extensive experience conducting vulnerability assessments, including scanning systems for weaknesses and performing manual checks. I analyze the findings to provide actionable remediation strategies, keeping in mind industry best practices in cybersecurity.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Become a Cyber Security Operations Specialist at Abile Group, where you'll play a vital role in enhanced cybersecurity measures for the Intelligence Community.

Photo of the Rise User
Posted 13 days ago

Join Peraton as a Technical Targeting Analyst and leverage your expertise to support critical national security missions.

Photo of the Rise User
Posted 5 days ago

Join USGS GHSC as an AWS Cloud Engineer to lead and maintain critical AWS-hosted scientific applications.

Photo of the Rise User
Posted 7 days ago
Customer-Centric
Rapid Growth
Diversity of Opinions
Reward & Recognition
Friends Outside of Work
Inclusive & Diverse
Empathetic
Feedback Forward
Work/Life Harmony
Casual Dress Code
Startup Mindset
Collaboration over Competition
Fast-Paced
Growth & Learning
Open Door Policy
Rise from Within
Maternity Leave
Paternity Leave
Flex-Friendly
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off

Join our innovative team as a Remote EDI Integration Analyst, where you'll play a crucial role in integrating applications and enhancing our business operations.

Posted 5 days ago

Join a large enterprise as an IAM Engineer, leading the design and management of identity platforms in a pivotal security role.

Photo of the Rise User

Join Lockheed Martin as an Info Systems Analyst to drive IT support within military Space Programs in Washington, DC.

Redcare Pharmacy Remote Brückenstraße, 10179 Berlin, Deutschland
Posted 11 days ago

As a Senior Microsoft Dynamics Developer at Redcare Pharmacy, you'll play a key role in evolving our supply chain solutions using innovative technologies.

Photo of the Rise User

Become a Senior Principal DevOps/FinOps Engineer at Palo Alto Networks, leading initiatives for cloud cost efficiency and optimization.

Photo of the Rise User
Posted 7 days ago

Join Rutgers University as a Senior Incident Response Analyst to lead in detecting and remediating security threats across our information technology landscape.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Eastlake just viewed (REMOTE) Account Executive at Trellis
Photo of the Rise User
12 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Elyria just viewed Security Officer - Factory Patrol at Allied Universal
C
14 people applied to ISSE/ ISSO at Centuria
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Software Test Engineer, Platform at Clari
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause