Senior Cybersecurity Defense Analyst III

    Highlights

    Partner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automation. Job Details: Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetry.

    Numbers & Facts

    LocationAlexandria, VA

    Description

    Title: Senior Cyber Defense Analyst III

    Location: Alexandria, VA

    Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

    Job Details:

    • Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetry
    • Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
    • Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
    • Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
    • Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
    • Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
    • Serve as a senior technical escalation point to less expereinced team members and provide hands-on guidance during complex investigations
    • Lead portions of incident response activities, including scoping, evidence analysis, containment recommendations, technical coordination, and post-incident review
    • Conduct proactive analysis and threat hunting when warranted to identify related or previously undetected activity
    • Develop, maintain, and improve analyst runbooks, investigative procedures, escalation criteria, incident playbooks, and shift-turnover practices
    • Partner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automation
    • Mentor junior analysts, support analyst qualification and exercises, and perform quality review of investigations and case documentation
    • Translate incident lessons learned into improved detections, procedures, training, and defensive recommendations

    Requirements:

    • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
    • Minimum six (6) years of relevant experience in addition to education level
    • Significant hands-on experience conducting cybersecurity investigations and incident response in enterprise environments.
    • Strong knowledge of network and host-based investigation, common adversary tactics, techniques, and procedures, and the MITRE ATT&CK framework
    • Experience developing or improving SOC procedures, incident playbooks, runbooks, or analyst training materials
    • Experience serving as an escalation point, technical lead, or mentor for cyber defense analysts
    • Must possess current DoD 8570 IAT II or IAM II certification
    • Experience working in a DoD or IC environment
    • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

    Equal Opportunity Employer/Veteran/Disabled

    Similar Jobs

    See more jobs