The Department of Homeland Security (DHS) has a continuing requirement for Secure Enterprise Network Systems, Services, amp; Support (SENS3) for the continued operations and maintenance and evolution of the Homeland Secure Data Network (HSDN) and the Classified Local Area Network (C-LAN). This requirement was previously called Enterprise Networked Services Support (ENSS).
The candidate will support Enterprise Information Assurance Auditing Services. The candidate will monitor IT software and system operations to collect audit data about all user and system component events, The candidate will ingest audit and other log data sources into the Government-furnished SIEM tool. The candidate will be required to perform rigorous host and network analysis on collected audit data to uncover anomalies for further investigations. The candidate must establish automated alerts based on triggering events and trends in audit and other log data sources, conduct hunting analyses that search for indicators of sophisticated adversary penetrations of the HSDN and C-LAN network environments, and identify how an adversary might operate and then construct appropriately focused detection operations. The candidate must also deploy and update honeypots and monitor behaviors of intruders accessing them, monitor and collect audit events on all cross domain devices, automatically moving all cross domain logs on DHS SBU and SECRET networks to C-LAN for ingest and alerting on potential security events. The candidate will be required to create triggers to continuously monitor certifier-approved configurations on servers and clients.
Clearance Requirement: Top Secret (Must be able to obtain TS/SCI)