Threat Hunting Analyst

il y a 7 heures


Mons, Belgique Systems Planning and Analysis, Inc. Temps plein

Overview:
Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing
_Results that Matter_. Come work with the best We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

SPA has an immediate need for a Threat Hunting Analyst to provide contracting services for NATO.

**Responsibilities**:
As a Cyber Security Threat Hunting Analyst, the incumbent will work alongside a team of Security Analysts to proactively detect cyber security attacks against NATO networks. They will research and react to the latest threats, using industry‐leading tools to discover new and ongoing attacks.

Main responsibilities:

- Develop hypotheses to be used in a threat hunt;
- Create security tool content such as searches, reports and dashboards to facilitate threat hunting;
- Perform in‐depth analysis of suspicious activity to deliver conclusions and recommendations;
- Review and develop logging configurations to enable a comprehensive threat hunting capability;
- Develop and document threat‐hunting procedures;
- Share the results of threat hunts via presentations and technical reports.

Qualifications:
**Required Qualifications**:

- Expert level in at least three of the following areas and a high level of experience in several of the other areas;
- Cybersecurity threat hunting;
- MITRE ATT&CK Framework;
- Security Incidents Event Management products (SIEM) - e.g. Splunk;
- Splunk Processing Language;
- Network Based Intrusion Detection Systems (NIDS) - e.g. SourceFire, Palo Alto Network Threat Prevention;
- Host Based Intrusion Detection Systems (HIDS);
- Sysmon;
- Full Packet Capture systems - e.g. Niksun, RSA/NetWitness;
- Computer security tools (Vulnerability Assessment, Anti‐virus, Protocol Analysis, Anti‐Virus, Protocol Analysis, Anti‐Spyware, etc);
- Proficiency in Intrusion/Incident Detection and Handling;
- Normal office environment with standard working hours, but may exceptionally be required to work non‐standard hours in support of a major Cyber Incident, or on a shift system for a limited period of time due to urgent operational needs.
- NATO Secret security clearance
- National from one of the 30 NATO Nations

**Desirable Qualifications**:

- Industry leading certification in the area of Cybersecurity such as GCFA, GCIA, GNFA;
- Knowledge and experience in Splunk Enterprise Security suite;
- A good understanding of Security, Orchestrations, Automation and Response (SOAR) concepts and their benefits to the protection of CIS infrastructures;
- Knowledge and experience in threat hunting in corporate/government level environment;
- Strong knowledge of malware families and network attack vectors;
- Experience in analysis of various threat actor groups, attack patterns and tactics, techniques, and procedures (TTPs), deep analysis of threats across the enterprise by combining security rules, content, policy and relevant datasets;
- Ability to analyse attack vectors against a particular system to determine attack surface.
- Extensive practical experience with malware analysis products (Cuckoo, Opswat Metascan);
- Experience with system instrumentation solutions such as Ansible, Chef, etc.;
- Industry leading certification in the area of Cybersecurity such as CISSP, CISM, MCSE/S, CISA, GSNA, SANS GIAC;
- Tenable Certified Security Engineer;
- Prior experience of working in an international environment comprising both military and civilian elements.



  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: C001230 / Mons **Skills, knowledge, experience required**: - The lack of a degree may be compensated by at least 3 years of relevant experience in field of cyber security analysis; - Comprehensive knowledge of the principles of computer and communications security including...


  • Mons, Belgique Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a** Cloud Security and Automation Analyst **to join our UniQue team in Mons. **What will you be doing in this role?** - Monitor and respond to alerts from cloud and on-premise security systems. - Identify cloud security gaps and...


  • Mons, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...


  • Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **EXPERIENCE AND EDUCATION**: **Essential Qualifications/Experience**: - Experience of at least 2 years in: - engaging with highly technical cyber security professionals - summarizing discussions, identifying relevant points and action items - coordinating stakeholders at multiple levels (strategic, operational and tactical/technical) - creating work...


  • Mons, Belgique Vector Synergy Temps plein

    **Location**: Mons, Belgium **Security Clearance**: NATO Secret **Reference No**: RFQ 2025-0138 / Mons **Skills, knowledge, experience required**: - Experience of at least 2 years in: - engaging with highly technical cyber security professionals; - summarizing discussions, identifying relevant points and action items; - coordinating stakeholders at...

  • Cloud Analyst

    il y a 2 jours


    Mons, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...

  • Cyber Security Analyst

    il y a 2 jours


    Mons, Belgique Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. **Who we are supporting** The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT)...

  • Siemloga Tool Manager 2

    il y a 2 jours


    Mons, Belgique Enterpryze Consulting Ltd. Temps plein

    **SIEMLogA Tool Manager 2 - **Working Location**:Mons, Belgium** - **Security Clearance**: NATO Secret** - **Language**:High proficiency level in English language **EXPERIENCE AND EDUCATION: **Essential Qualifications/Experience: - Bachelor's Degree in Computer Science combined with a minimum of 2 years' experience in as Security Tool Analyst (STA), Tool...

  • 3046 SQL PowerBI Sme

    il y a 2 jours


    Mons, Belgique Contact One Communications, Inc. Temps plein

    SQL Subject Matter Expert - PowerBI Subject Matter Expert - Iterative approach using sprints. **Required Security Clearance**: NATO SECRET **SCOPE OF WORK** The aim of this SOW is to support NCSC with technical expertise specifically related to the operation and maintenance of SQL databases and Power BI SME activities with a deliverable-based contract to...