Job Description:
Computer Network Exploitation Analyst- Host
Host analysts (malware or forensic analyst)/CNO
Developer who would preferably have some combination of

  • Experience in host forensics, windows/linux internals,
vulnerability assessment (more than just running a tool
such as Retina or Gold Disk, but actually doing analysis
of that data or manually gathering vulnerability
analysis data via an innovative/custom method) and/or
Computer Network Exploitation
  • Performed analysis of host data at rest, forensic
analysis of windows, UNIX, or mobile systems, and/or
experience with file hashing and fuzzy file hashing
  • Experience with industry standard system tools
(Sysinternals suite for example)
  • Performed analysis of code in memory, including
analysis of RAM snapshots, Windows crash dump files,
and/or UNIX kernel dumps
  • Performed software reverse engineering to include use
of code disassemblers (like IDAPro) and debugging
unknown code (like Ollydbg)

Job Requirements:" -5+ years experience in 2 of the following:
a) Computer Network Exploitation
b) Vulnerability Assessment
c) Penetration Testing
d) Incident Response
e) Network and/or host forensics
  • 1+ years of experience in 2 of the following:
a) Analysis of host data at rest, including:
i. Microsoft Windows operation systems, system
internals, file attributes
ii. Executable file analysis (particularly PE files
including dynamic linked libraries)
iii. File Hashing and Fuzzy Files Hashing (e.g. ssdeep,
fciv, and md5deep)
b) Forensic analysis of Window systems, UNIX systems,
and/or mobile devices
c) Commercial, open source or GOTS tools for intrusion
detection (e.g., Snort, BroIDS).
d) Packet capture/evaluation (e.g. tcpdump,
ethereal/wireshark, NOSEHAIR).
e) Network mapping/discovery (e.g. nmap, TRICKLER)
f) Industry standard system/network tools (e.g. netcat,
netstat, traceroute, rpcinfo, nbtscan, snmpwalk,
Sysinternals suite).
g) Implementing networks with IPv6 protocols"/SCI with
