Host Based Systems Analyst 2

Arlington, VA
Systems Analyst – 0008-0003 /
Full-time (Remote) /
Remote
About ARSIEM Corporation

At ARSIEM Corporation we are committed to fostering a proven and trusted partnership with our government clients.  We provide support to multiple agencies across the United States Government.  ARSIEM has an experienced workforce of qualified professionals committed to providing the best possible support.

As demand increases, ARSIEM continues to provide reliable and cutting-edge technical solutions at the best value to our clients.  That means a career packed with opportunities to grow and the ability to have an impact on every client you work with. 

ARSIEM is looking for a Host-based Systems Analyst. This position is remote with business travel as needed. Personnel will be required to live in the Continental US and are required to work core hours (Eastern Standard Time) to support one of our Government clients in Arlington, VA.

Responsibilities

    • Acquires/collects computer artifacts (e.g., malware, user activity, link files, etc.) from systems in support of onsite engagements
    • Assesses evidentiary value by triaging electronic devices
    • Correlates forensic findings with network events to further develop an intrusion narrative
    • When available, collects and documents system state information (running processes, network connections, etc.) before imaging
    • Performs incident triage from a forensic perspective to include determination of scope, urgency, and potential impact.
    • Tracks and documents forensic analysis from initial involvement through final resolution
    • Collects, processes, preserves, analyzes, and presents computer-related evidence
    • Coordinates with others within the Government and with customer personnel to validate/investigate alerts or other preliminary findings
    • Analyzes forensic images and other available evidence and drafts forensic write-ups for inclusion in reports and other written products
    • Assists to document and publish Computer Network Defense guidance and reports on the  incident findings to appropriate constituencies

Minimum Qualifications

    • BS in Computer Science, Computer Engineering, Computer Information Systems, Computer Systems Engineering or related degree.
    • High School Diploma and 4-6 years of host investigations experience may be substituted for the BS & 2-4 years of experience
    • Possess GCIH and GCFA

Core Competencies

    • Knowledge of incident response and handling methodologies
    • Knowledge of the NCCIC National Cyber Incident Scoring System to be able to prioritize triaging of incident
    • Knowledge of general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)
    • Skill in recognizing and categorizing types of vulnerabilities and associated attacks
    • Knowledge of basic system administration and operating system hardening techniques
    • Knowledge of Computer Network Defense policies, procedures, and regulations
    • Knowledge of different operational threat environments (e.g., first-generation [script kiddies], second generation [non nation-state sponsored], and third-generation [nation-state sponsored])
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, and malicious code
Clearance Requirement: This position requires an Active TS/SCI clearance and the ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability.
 
Candidate Referral: Do you know someone who would be GREAT at this role? If you do, ARSIEM has a way for you to earn a bonus through our referral program for persons presenting NEW (not in our resume database) candidates who are successfully placed on one of our projects. The bonus for this position is $5,000,  and the referrer is eligible to receive the sum for any applicant we place within 12 months of referral. The bonus is paid after the referred employee reaches 6 months of employment.

ARSIEM is proud to be an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other federally protected class.