The selected candidate will be a member of the NIE-ESS Computer Security Incident Response Team that is responsible for computer security incident response, host and network forensics, malware analysis, and the development of countermeasures and advanced detection techniques.
- Identify and respond to complex computer security incidents, communicate findings, and modify defenses and response measures as appropriate;
- Develop advanced methods, techniques, and standards and communicate findings to multiple audiences;
- Independently lead work on moderately complex cyber issues, providing guidance and direction as appropriate to other cyber security personnel
- Critically analyze malware and develop indicators
What You Need
Minimum Job Requirements:
- A deep understanding of the cyber security environment, including network and host system security issues and concepts, compliance, and certification.
- Advanced understanding of common network and host-based attacks, attack methods, network defense architectures, and security tools.
- Extensive experience with one or more of the following: malware analysis and reverse engineering; enterprise host and memory forensics; network forensics and packet analysis; incident response and incident coordination; penetration testing.
- Experience leading projects or mentoring junior analysts.
- Strong analytical, documentation, and communication skills and the ability to collaborate well in a dynamic team environment.
Education/Experience: Cybersecurity Technical Staff 3 requires a bachelor's degree in a technical field and a minimum of 8 years' related experience, or an equivalent combination of education and experience.
- Enterprise forensics tools
- Memory analysis
- IDA Pro, BinDiff, yara rule creation beyond string searching
- Dynamic analysis of software samples via debuggers such as OllyDbg or IDA debugger
- Network signature creation
- ArcSight, Splunk, or similar tools
- Extensive background developing regular expressions
- Automated analysis and scripting with Python, Perl or similar languages
- Tool integration and event correlation with differing API's
Location: This position will be part of the Laboratory's Telework Pilot and may work from a remote/home location within a two-hour ground commute of the Laboratory. Employee participation in the Telework Pilot may be shortened or extended at the manager's discretion. Ability to report on-site is a must for this position.
The COVID vaccine is mandatory for all Laboratory employees, on-site contractors, and on-site subcontractors unless granted an accommodation under applicable state or federal law. This requirement will apply to those working on-site, those teleworking, and all new hires.
Position commitment: Regular appointment employees are required to serve a period of continuous service in their current position in order to be eligible to apply for posted jobs throughout the Laboratory. If an employee has not served the time required, they may only apply for Laboratory jobs with the documented approval of their Division Leader. The position commitment for this position is 1 year.
Note to Applicants: A comprehensive cover letter detailing how you meet the minimum and desired job skills is recommended.
Where You Will Work
Located in beautiful northern New Mexico, Los Alamos National Laboratory (LANL) is a multidisciplinary research institution engaged in strategic science on behalf of national security. Our generous benefits package includes:
- PPO or High Deductible medical insurance with the same large nationwide network
- Dental and vision insurance
- Free basic life and disability insurance
- Paid maternity and parental leave
- Award-winning 401(k) (6% matching plus 3.5% annually)
- Learning opportunities and tuition assistance
- Flexible schedules and time off (paid sick, vacation, and holidays)
- Onsite gyms and wellness programs
- Extensive relocation packages (outside a 50 mile radius)
Directive 206.2 - Employment with Triad requires a favorable decision by NNSA indicating employee is suitable under NNSA Supplemental Directive 206.2. Please note that this requirement applies only to citizens of the United States. Foreign nationals are subject to a similar requirement under DOE Order 142.3A.
Clearance: Q (Position will be cleared to this level). Applicants selected will be subject to a Federal background investigation and must meet eligibility requirements* for access to classified matter. This position requires a Q clearance which requires US Citizenship except in extremely rare circumstances. Dependent upon position, additional authorization to access nuclear weapons information may be required that may or may not be available to dual citizens depending upon the circumstances.
*Eligibility requirements: To obtain a clearance, an individual must be at least 18 years of age; U.S. citizenship is required except in very limited circumstances. See DOE Order 472.2 for additional information.
New-Employment Drug Test: The Laboratory requires successful applicants to complete a new-employment drug test and maintains a substance abuse policy that includes random drug testing.
Regular position: Term status Laboratory employees applying for regular-status positions are converted to regular status.
Internal Applicants: Regular appointment employees who have served the required period of continuous service in their current position are eligible to apply for posted jobs throughout the Laboratory. If an employee has not served the required period of continuous service, they may only apply for Laboratory jobs with the documented approval of their Division Leader. Please refer to Policy Policy P701 for applicant eligibility requirements.
Equal Opportunity: Los Alamos National Laboratory is an equal opportunity employer and supports a diverse and inclusive workforce. All employment practices are based on qualification and merit, without regard to race, color, national origin, ancestry, religion, age, sex, gender identity, sexual orientation or preference, marital status or spousal affiliation, physical or mental disability, medical conditions, pregnancy, status as a protected veteran, genetic information, or citizenship within the limits imposed by federal laws and regulations. The Laboratory is also committed to making our workplace accessible to individuals with disabilities and will provide reasonable accommodations, upon request, for individuals to participate in the application and hiring process. To request such an accommodation, please send an email to email@example.com or call 1-505-665-4444 option 1.