Search jobs > San Antonio, TX > Malware analyst

Sr. Forensic Malware Analyst

Bristol Bay Native
San Antonio, TX, USA
Full-time

STS Systems Support, LLC (SSS) is seeking a Sr. Forensic Malware Analyst

Requirements :

  • DoDD 8570.01 M / 8140.01 I AT Level III CND
  • Active TS / SCI
  • More than five (5) years of experience as a Forensic Malware Technician.
  • Experience performing forensic acquisition and examination of Windows, Unix / Linux, and Macintosh based computers and servers.
  • Strong skill in and a strong understanding of : the use of a variety of forensic tools (Access Data, FTK, Guidance EnCase;

including mobility (Axiom / BlackBag , Mobilyze / Cellebrite / Paraben and in, FTK, X Ways Forensics, FireEye, Volatility, Sleuthkit, BlackBag tools) and various Open Source forensic tools.

  • Shell Scripting is a plus.
  • Experience writing intelligence and technical articles for production and dissemination.
  • Very proficient w / malware analysis, sandboxing, and software reverse engineering.
  • Proficient Experience with scripting languages such as Python and PowerShell.
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (., Open Source projects).

Required : SANS GCFA (or equivalent).

Desired :

GREM, GCTI and / or ACE

Duties :

  • Document all findings in the investigation / incident log. (CDRL A008)
  • Track evidence inventory for intake and releasing to the forensics laboratory. This includes insuring proper handling and maintenance of evidence and chain of custody records with no more than 5% error rate.
  • Utilize forensic tools such as, but not limited to; EnCase, FTK, FireEye, etc. and other systems as required.
  • Conduct analysis of metadata and forensic examinations of digital media from a variety of sources including preservation, acquisition, and analysis of digital evidence with the goal of developing forensically sound evidence.
  • Confirm malicious activity when new information is identified through forensic analysis.
  • Investigate network and computer intrusions to identify root cause and generate indicators of compromise and document all findings in the investigation / incident log for each file.
  • Perform memory forensics and malware reverse engineering of suspected malicious files to verify if system compromise occurred document all findings Indicators of Compromise (IOCs) in the investigation / incident log for each file.
  • Perform Hard Drive Analysis of suspected / confirmed infected or exploited systems and document all findings in the investigation / incident log for each hard drive with no more than a 5% error rate.
  • Develop methods to identify, contain, log, and analyze malware based activities on AF AIS and networks. (A008)
  • Provide support to AF network administrators on the installation and analysis of packet sniffers on their network topology by reporting the functionality status upon request.
  • Generate forensic reports and synopses presenting complex technical processes and findings clearly and concisely to technical and non technical. (CDRL A008)
  • Collaborate with leadership and external agencies, including Counter Intelligence activities / agencies, OSI, FBI, and other security agencies, to include Incident Responders, as well as other forensic analysts.
  • Provide AF OSI DCO technical support to law enforcement and counter intelligence activities.
  • Turn any investigation over to AF OSI if it is determined during the course of an investigation a law was broken.
  • Support and / or augment Incident Response deployment with same day notice. This travel will allow responders to retrieve hard drives or miscellaneous storage media, isolate system(s) for additional investigation, and perform other on site Incident Response actions.
  • Set up a monitor or cage at the on site location as needed.
  • Provide OJT to other contractor employees, military, and / or civilian personnel, and ensure continuity folders / working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Provide requested forensic information to operational flight commander as it relates to the Host Detection processes and procedures.

Other details

  • Pay Type Salary
  • 3 days ago
Related jobs
Bristol Bay Native
San Antonio, Texas

Strong skill in and a strong understanding of: the use of a variety of forensic tools (Access Data, FTK, Guidance EnCase; including mobility (Axiom/BlackBag , Mobilyze/Cellebrite/Paraben and in, FTK, X‐Ways Forensics, FireEye, Volatility, Sleuthkit, BlackBag tools) and various Open Source forensic t...

Promoted
TCP Software
San Antonio, Texas

The Cybersecurity Engineer Role is a position providing an opportunity to work in a fast-paced collaborative environment protecting TCP Software cloud infrastructure from cyber threats. Cybersecurity Engineers must be agile, willing to learn, and able to think outside of the box in order to operate ...

Promoted
Numeric Technologies
TX, United States

Support SLM initiative from cybersecurity perspective, including code security coverage for both vendor code (SAP Security Notes) as well as custom code. Anaylse cybersecurity and system hardening requirements for SAP system landscape modernization (SLM). Information management & security. ...

Promoted
Tarvos Talent
TX, United States

As a Cyber Security Engineer, you will be a key player in a supportive and collaborative environment, driving the company's security and compliance requirements. Tarvos Talent is seeking a seasoned Cyber Security Engineer to join a dynamic and rapidly growing company that is making waves in its indu...

Promoted
Brooksource
TX, United States

Our client, a leading technology company, is seeking a Network Automation Engineer to join their team. The ideal candidate will have experience with VMware NSX, network automation, and software-defined networking (SDN). As Dell transitions away from VMware, they are embracing Sonic as their network ...

Promoted
Alined Consulting Group
TX, United States

Need to be able to talk with the business users and get their requirement and creat a story board for it to help roadmap. Need to be able to use Visio/Figma to draw out business processes from conversations with the teams. ...

Promoted
Robert Half
TX, United States

Robert Half is looking for a Data Analyst for a healthcare client based in Austin, TX. Support daily data integration processes for business continuity and maximum delivery of services. Support multiple real-time data feeds and troubleshoot issues as they arise. Analyze and resolve data related prob...

Promoted
ACENSI
San Antonio, Texas
Remote

However, its performance and data model flexibility issues necessitate a review of the data strategy. The client aims to replace SAP BFC and build a new data platform, with Phase 1 (Feb-May 2023) defining data needs, target architecture, and a macro roadmap. Refines AUM data granularity from affilia...

Promoted
Cielo Talent
San Antonio, Texas
Remote

Cielo has partnered with Cornerstone Building Brands to hire 4 Product- Data Analysts for an 18-month contract and 1 full-time, permanent. Work as the liaison between Engineering, technology and procurement teams on development and optimization of product data across multiple systems / processes wit...

Promoted
Kaimetrix, L.L.C.
San Antonio, Texas

Subject Matter Expert Cyber – Level II /Systems Security Engineer. Subject Matter Expert Cyber – Level II /Systems Security Engineer Responsibilities:. Subject Matter Expert Cyber – Level II /Systems Security Engineer Requirements:. Integration of capabilities on the AF network req...