Jobs and Careers
KB

Senior Cyber Security Specialist (S-NET)

KBR, Inc.
United Statesfull_timeVerifiedPosted 16 Apr 2025
💰 $200,000/yr($135,000/yr – $200,000/yr)

About the role

Title:

Senior Cyber Security Specialist (S-NET)

Belong. Connect. Grow. with KBR!

KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country’s most critical role – protecting our national security.

Why Join Us?

  • Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
  • Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
  • Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.

Key Responsibilities:

  • Support a government Cyber Security Operation Center (CSOC) andl conduct security event monitoring, advanced analytics, and response activities in support of the CND operational mission with diverse backgrounds in cyber security systems operations, analysis and incident response.
  • Perform technical analysis on a wide range of cybersecurity issues, with a focus on network activity, host activity, and data.  This includes, but is not limited to: network flow (i.e. netflow) or related forms of session summary data, signature-based IDS/IPS alert/event data, full packet capture (PCAP) data, proxy and application server logs (various types).
  • Triage IDS/IPS alerts, collect related data from various systems, review open and closed source information on related threats & vulnerabilities, diagnose observed activity for likelihood of system infection, compromise or unintended/high-risk exposure.
  • Prepare analysis reports detailing background, observables, analysis process & criteria, and conclusions.
  • Analyze large volumes of network flow data for specific patterns/characteristics or general anomalies, to trend network activity and to correlate flow data with other types of data or reporting regarding enterprise-wide network activity.
  • Leverage lightweight programming/scripting skills to automate data-parsing and simple analytics. Document key event details and analytic findings in analysis reports and incident management systems. Identify, extract and characterize network indicators from cyber threat intelligence sources, incident reporting and published technical advisories/bulletins.
  • Assess cyber indicators/observables for technical relevance, accuracy, and potential value/risk/reliability in monitoring systems. Recommend detection and prevention/mitigation signatures and actions as part of a layered defensive strategy leveraging multiple capabilities and data types.
  • Develop IDS/IPS signatures, test and tune signature syntax, deploy signatures to operational sensors, and monitor and tune signature and sensor performance.
  • Fuse open-source threat & vulnerability information with data collected from sensors across the enterprise into cohesive and comprehensive analysis.
  • Develop security metrics and trend analysis reports

Work Environment:

  • Location: Annapolis Junction MD [On-site]
  • Travel Requirements: Minimal 0-20% Travel
  • Working Hours: Standard 40 hour per week

Qualifications :

Required:

  • Clearance: Top Secret with SCI
  • 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD.
  • Bachelor’s degree in Computer Science, Information Systems, or equivalent education or work experience (additional relevant work experience can be substituted for a degree)
  • Must have a current DoD 8570.1-M IAT Level II certification

Desired:

  • Desired Certifications: CEH, GCIH, GCIA, GCFA
  • 3+ years in a SOC or Incident Response role
  • Experience with Cisco Firepower, Cisco Sourcefire, Cisco Advanced Malware Protection, Cisco Stealthwatch, Cisco Umbrella
  • Experience with deploying and writing signatures (Snort, YARA, HIPS)
  • Experience with network hunting utilizing Zeek/Bro
  • Experience with McAfee ePO, HBSS
  • Splunk: Create log searches, dashboards, setting up alerts, and scheduled reports to help detect and remediate security concerns.
  • Experience with ArcSight
  • Experience with Wireshark and packet analysis
  • Experience with Tanium o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

KBR, Inc.

View company profile →