CND Analyst
Columbus, OH, Fort Belvoir, VA, Battle Creek, MI
Description:
Connected Logistics is seeking a Certified Network Defender (CND) Analyst to perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity within assigned information systems and computer networks.
The CND Analyst performs defensive cyber operations supporting the Defense Logistics Agency (DLA) Cybersecurity Service Provider (CSSP) mission through continuous monitoring, detection, analysis, containment, eradication, and reporting of malicious cyber activity affecting enterprise networks, cloud environments, applications, and operational technologies. Employs Cybersecurity capabilities and deliberate actions to respond to a CND alert or emerging situational awareness/threat. Serves as an expert on CND requirements and compliance to such requirements by using IA tools and techniques to perform compliance analysis and correlation, tracking and remediation coordination, and escalating CND non-compliance. Experience using enterprise cybersecurity tools such as Splunk, ArcSight ESM, Microsoft Defender for Endpoint (MDE), ACAS/Nessus, HBSS/ESS, Palo Alto firewalls, and packet analysis tools such as Wireshark. Supports incident response activities including event triage, malware analysis coordination, containment recommendations, root cause analysis, evidence preservation, incident documentation, and after-action reporting.
Key Responsibilities:
- Operates within a 24x7x365 SOC/CSSP environment.
- Provides hands-on experience with SIEM platforms such as Splunk or ArcSight.
- Analyzes logs and telemetry from endpoints, firewalls, IDS/IPS, EDR, DNS, proxy, VPN, cloud, and server environments.
- Performs packet analysis using Wireshark, tcpdump, or similar network analysis tools.
- Applies MITRE ATT&CK framework, cyber threat indicators, and incident response methodologies.
- Supports cybersecurity incident triage, analysis, escalation, and reporting.
- Maintains and documents technical findings and verbally brief incidents to operational and leadership personnel.
- Administers cybersecurity tools such as MDE, ACAS/Nessus, HBSS/ESS, Palo Alto, or equivalent enterprise defensive technologies.
- Demonstrates understanding of Windows and Linux operating systems, networking fundamentals, and enterprise authentication technologies.
- Leverages scripting, automation, or query languages such as PowerShell, Python, KQL, or SPL preferred.
- Provides prior DoD, DLA, DISA, or federal cybersecurity operations experience preferred.
- Reviews and analyzes logs from multiple sources such as system event logs, F5, Firewall, etc.
- Reviews and analyzes network traffic through packet captures.
- Communicate cybersecurity incidents effectively through written documentation and verbal briefings.
- Minimum five (5) years of experience in cybersecurity operations, incident response, threat detection, or SOC/CSSP operations.
- Must possess an active DoD Top Secret clearance with current IT-I eligibility.
- Must possess a current IATII Certification: such as Security +.
- Must possess a current DoD Approved 8570/8140 Baseline Certification: CSSP- Analyst such as, CEH, CySA+, etc.
- DLA CE Cert IA Role/Function: Incident Response.
Total Rewards Statement
We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $110,000.00 to $120,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.
Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We’re excited to support you in building a rewarding career with us!
Connected Logistics respects the need for confidentiality for all applicants.
Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.
EOE/Disability/Veterans