Founded in 1999 in the beautiful Smoky Mountains of East Tennessee, Cadre5 provides innovative technical solutions to our customers locally and nationally. Our Cadre5 Lab Partners division has partnered with The Information Technology Services Directprate (ITSD) at Oak Ridge National Laboratory (ORNL) to hire a IT Cyber Analyst to immediately support their Defensive Cyber Operations (DCO) team. This position’s primary responsibility is to conduct event triage in a tiered operational security model while training in and supporting threat hunting and threat intelligence tasks.
ORNL delivers scientific discoveries and technical breakthroughs needed to realize solutions in energy and national security and provides economic benefit to the nation. This premier research institution located near Knoxville in Oak Ridge, TN, addresses national needs through impactful research and world-leading research centers.
This is a full-time, permanent position that will work onsite in Oak Ridge, TN 2-3 days each week.
Why Cadre5?
- Working with highly talented team members
- 3 weeks’ vacation
- Excellent medical insurance, including employer-paid benefits
Job Responsibilities:
- Support the DCO environment in identification and analysis of threats in Security Incident and Event Management (SIEM) alerts, dashboards, and queries
- Resolve or escalate alerts/events/incidents as defined in DCO service level agreements according to level of severity
- Help develop advanced queries and alerts to detect adversary actions and compile detailed investigation and analysis reports for internal DCO consumption, and for delivery to management
- Work with the Emerging Threat team to capture intelligence on threat actor tactics, techniques, and procedures (TTPs) and leverage automated and manual countermeasures in response
- Work with the ORNL Threat Hunting team to perform hypothesis-driven hunts of the ORNL network for undetected threats
- Field customer requests for support ranging from potential phishing events to abnormal system activity
- Triage reports from DOE entities, CISA, and external penetration testers, and coordinate resolution with ORNL system administrators in keeping with BOD 18-01, 19-02, and 22-01 requirements
- Analyze suspicious links and attachments in a secure malware analytics platform as part of a comprehensive phishing analysis procedure
- Triage malware and anomalous activity alerts generated by an EDR system
Basic Qualifications:
- Bachelor's Degree in Computer Science or related field with 1-2 years of cyber operations work experience
- Experience with ServiceNow, JIRA ServiceDesk, or other ticketing system
- Relevant certifications (GSEC, Security+, CEH, etc) preferred
- The position requires eligibility to obtain a DOE security clearance. This requires US Citizenship.Candidates with an Active Q Clearance or Top-Secret Clearance are a plus.
Benefits
Cadre5 offers excellent pay and benefits, to include full medical, dental, and vision coverage coupled with 401K match, 15 days PTO, and 10 holidays.
Cadre5 is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. Cadre5 is an E-Verify Employer.