IDS/IPS Analyst
Posted on December 8, 2011
Description : Dependable Global Solutions, Inc, is seeking IPS/IDS Analysts to join our team. Several positions exist, including current vacancies in Charleston, SC and Arlington, VA. The candidate will perform roles as a IPS/IDS Analyst that focuses on maintaining the system health for all managed systems: Intrusion Detection/Prevention systems, security scanners, Websense, and Security Information and Event Management systems (SIEM). Serve as a staff member on the Computer Incident Response Team (CIRT), that will maintain existing IDS/IPS signatures and technologies. Lead resolution and recovery efforts of cross-functional technicians and troubleshoot issues reported by proactive alarming or problem notifications reported by end-users. Analyze and ensure the resolution of technical and client problems while providing quality customer service. Evaluate and develop network and operational solutions to fulfill business requirements.
Qualifications
Basic Qualifications:
-Experience with current IDS/IPS products and technologies.
-Knowledge of the TCP/IP protocol suite, security architecture.
-Knowledge of networking technologies and protocols, including Ethernet, TCP/IP and routing.
- Experience with security technologies including Intrusion Detection & Prevention Systems (IDS/IPS), Firewalls & Log Analysis, SIEM, Network Behavior Analysis, Antivirus, and Packet Analysis, malware analysis and forensics.
-Ability to perform on call functions and respond to emergency calls during non-business hours.
-Candidate must have a DoD Secret security clearance and be eligible for Top Secret.
-BS degree in Engineering, CS, Information Security, or Information Systems and two(2) years of related experience. May substitute four years additional experience for degree.
-Experience in analyzing audit logs, router/firewall logs, IDS/IPS logs.
-Relevant recent IDS/IPS work
-Regular expression and scripting experience
-Intrusion monitoring, analysis, and escalation experience
-Able to recognize and respond to common attack traffic
-SIEM experience (ArcSight preferred)