Title: Cyber Defense Analyst IILocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Independently monitor, triage, and investigate routine and moderately complex security alerts and suspected incidents.Perform cyber defense monitoring and analysis using security information from enterprise systems, networks, security sensors, firewalls, intrusion detection/prevention technologies, endpoint sources, and other available telemetry.Analyze log files and network activity to identify anomalous or malicious behavior, determine potential security impact, and document investigative findings in the authorized case or ticketing systemPerform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalationSupport incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and proceduresCorrelate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related eventsCollect and preserve relevant intrusion artifacts and investigative evidence in accordance with established proceduresCommunicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriateDevelop and test investigative hypotheses by correlating network, host, identity, firewall, vulnerability, and threat dataIdentify related activity beyond the initially alerted system and appropriately expand investigative scopeExecute established incident response and escalation procedures and coordinate with technical teams when containment or remediation action is requiredIdentify recurring alert-quality, telemetry, or process issues and recommend improvements to senior analysts Requirements:Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum four (4) years of relevant experience in addition to education level Working knowledge of TCP/IP, DNS, HTTP/S, authentication, enterprise networking, Windows/Linux security events, and common adversary techniquesHands-on experience using SIEM and one or more network, endpoint, firewall, IDS/IPS, or security-analysis technologiesAbility to independently investigate security activity, distinguish facts from assumptions, and communicate evidence-based conclusionsMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled
Job Posted by ApplicantPro