Cyber Triage Analyst Level II

Argo Cyber Systems
  • Arlington, VA
  • Full-time
  • Instant Apply
14 days ago

Job Description

JCDC Cyber Triage Analyst – TS/SCICompany: Argo Cyber Systems, LLCProgram: Engagement Support Services (ESS) – JCDC Cyber OperationsClearance Required: Active TS/SCICitizenship: U.S. Citizenship RequiredSuitability: Must be able to obtain and maintain DHS SuitabilityEmployment Type: Full-TimeExperience Level: Mid-Level | 2–4+ Years Cybersecurity ExperienceAbout Argo Cyber SystemsArgo Cyber Systems, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing advanced cybersecurity services to U.S. Government and commercial customers.Our cybersecurity capabilities include Security Operations Center operations, cyber incident response, threat hunting, cyber threat intelligence, vulnerability management, cloud security, Zero Trust, digital forensics and incident response, penetration testing, and cybersecurity risk and compliance services.Argo Cyber Systems provides opportunities for experienced cybersecurity professionals to work directly on mission-focused programs protecting federal agencies and critical infrastructure from sophisticated cyber threats.About the MissionArgo Cyber Systems is supporting a U.S. Government customer in the rapid deployment and management of secure, cloud-based capabilities supporting cyber incident response, threat hunting, and national-level cybersecurity operations.Under the Engagement Support Services (ESS) program, our team helps ensure cybersecurity analysts have rapid access to the secure tools, infrastructure, and operational environments required to investigate cyber threats affecting federal agencies, state and local governments, and U.S. critical infrastructure.Working on this program means directly supporting the nation's cybersecurity defenders. Our mission is to provide reliable, scalable, and secure capabilities when they are needed most-during active cyber incidents and emerging threat campaigns affecting America's digital infrastructure.Position OverviewArgo Cyber Systems is seeking an experienced JCDC Cyber Triage Analyst to serve as a frontline cyber defender supporting the Joint Cyber Defense Collaborative (JCDC).The Cyber Triage Analyst performs initial analysis and triage of cyber threat reports, indicators of compromise (IOCs), incident notifications, and other cybersecurity information submitted to the JCDC.This is not an entry-level or developmental analyst position.The successful candidate will operate in a role comparable to a Tier 1/Tier 2 SOC Analyst with enhanced Cyber Threat Intelligence (CTI) responsibilities. Analysts are expected to independently research cyber activity, rapidly evaluate technical information, develop defensible analytical conclusions, identify intelligence and information gaps, and recommend appropriate follow-on actions.This position requires strong technical analysis skills combined with the ability to communicate and coordinate effectively with government organizations, private-sector partners, critical infrastructure stakeholders, and other cybersecurity professionals.Key ResponsibilitiesThe JCDC Cyber Triage Analyst will:Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.Analyze technical indicators and artifacts including IP addresses, domain names, URLs, file hashes, network traffic patterns, malware artifacts, and related telemetry.Assess the credibility, severity, scope, and potential operational impact of reported cyber activity.Evaluate potential impacts to federal networks and U.S. critical infrastructure sectors.Enrich IOCs using Threat Intelligence Platforms (TIPs), OSINT resources, commercial intelligence sources, and authorized government-exclusive resources.Correlate indicators with known threat actors, campaigns, malware families, vulnerabilities, tactics, techniques, and procedures (TTPs).Develop concise, defensible cyber triage reports containing analytical findings and actionable recommendations.Determine when incidents or threat activity require escalation or additional technical analysis.Route tickets and analytical findings to appropriate JCDC teams, CISA organizations, or interagency partners.Coordinate with sector-specific analysts, incident responders, threat hunters, intelligence analysts, and interagency liaisons to obtain additional technical and operational context.Maintain complete and accurate documentation within ticketing, case management, and knowledge management systems.Participate in operational shift handoffs and daily cybersecurity briefings.Monitor emerging cyber threat campaigns, adversary activity, vulnerabilities, and trends.Support development and continuous improvement of cyber triage playbooks, workflows, and Standard Operating Procedures (SOPs).Provide appropriate feedback to submitters and partner organizations regarding ticket status, findings, and disposition.Support collaboration across geographically distributed government and contractor teams.Required QualificationsCandidates must meet the following requirements:U.S. Citizenship.Active TS/SCI security clearance.Ability to obtain and maintain DHS Suitability.2–4+ years of progressive cybersecurity experience supporting one or more of the following:Security Operations Center (SOC) operationsCyber Threat Intelligence (CTI)Cyber incident responseNetwork security monitoringThreat huntingCybersecurity operationsDemonstrated ability to independently triage and analyze cybersecurity incidents, alerts, threat reports, or intelligence.Experience analyzing technical indicators such as IP addresses, domains, URLs, file hashes, network traffic, and malware-related artifacts.Experience researching and enriching IOCs using threat intelligence and OSINT resources.Ability to assess the severity, credibility, and potential impact of cyber threats.Ability to document analytical findings and develop concise, actionable recommendations.Strong technical research and analytical reasoning skills.Strong written and verbal communication skills.Ability to work effectively with government personnel, technical analysts, incident responders, intelligence professionals, and partner organizations.Ability to work collaboratively across geographically distributed teams and physical locations.Desired QualificationsHighly qualified candidates may possess experience in several of the following areas:Previous cybersecurity experience supporting CISA, FBI, NSA, DoD, DHS, or another federal cybersecurity or intelligence organization.Understanding of the National Cyber Incident Scoring System (NCISS) and its application to incident prioritization and triage.Knowledge of common cyberattack lifecycle stages, including:Reconnaissance and footprintingScanning and enumerationInitial accessPrivilege escalationPersistenceNetwork exploitation and lateral movementCommand and controlDefense evasion and covering tracksDemonstrated ability to recognize and categorize cybersecurity vulnerabilities and associated attack techniques.Knowledge of Computer Network Defense (CND) policies, procedures, processes, and regulations.Understanding of different operational threat environments, ranging from opportunistic attackers and cybercriminal organizations to sophisticated nation-state actors.Knowledge of system and application security threats and vulnerabilities, including:Buffer overflowsCross-site scripting (XSS)SQL/PL-SQL and other injection attacksMalicious or mobile codeRace conditionsCovert channelsReplay attacksReturn-oriented programming/attacksOther common application and network exploitation techniquesExperience working with SIEM platforms, Threat Intelligence Platforms (TIPs), case management systems, and cybersecurity ticketing platforms.Familiarity with cyber threat intelligence concepts, adversary TTPs, and IOC lifecycle management.Knowledge of U.S. critical infrastructure sectors and associated cyber risks.Familiarity with DHS/CISA cybersecurity products, services, alerts, advisories, and operational processes.Experience working in an operational SOC, watch floor, incident response center, or cyber fusion environment.EducationCandidates must possess one of the following:Bachelor's degree from an accredited college or university in:CybersecurityComputer ScienceComputer EngineeringInformation TechnologyInformation SystemsNetwork EngineeringAnother related technical disciplineORHigh School Diploma or equivalent plus at least four additional years of directly relevant technical cybersecurity experience.Desired CertificationsOne or more of the following certifications is preferred:CompTIA Security+CompTIA CySA+GIAC Certified Incident Handler (GCIH)GIAC Certified Intrusion Analyst (GCIA)GIAC Cyber Threat Intelligence (GCTI)Other comparable cybersecurity, incident response, SOC, or threat intelligence certificationsWhat We're Looking ForThis role is well suited for a cybersecurity professional who can move beyond simply reviewing alerts.We are looking for analysts who can receive incomplete or ambiguous cyber threat information, independently research the available evidence, determine what is technically significant, identify what information is missing, and develop a defensible recommendation for what should happen next.Successful candidates should be comfortable operating in a fast-paced cyber operations environment where accurate analysis, concise communication, sound judgment, and timely escalation directly contribute to the protection of federal systems and U.S. critical infrastructure. Argo Cyber Systems, LLC is an Equal Opportunity Employer. Employment decisions are made based on qualifications, merit, and business requirements consistent with applicable federal, state, and local law.

Job Posted by ApplicantPro

Numbers & Facts

LocationArlington, VA
Job TypeFull-time

Skills

  • (XSS) Cross Site Scriptingunmatched
  • Analysis Skillsunmatched
  • Applications Securityunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • Campaignsunmatched
  • Case Managementunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Forensicsunmatched
  • Computer Network Defense (CND)unmatched
  • Computer Securityunmatched
  • Computer Telephony Integration (CTI)unmatched
  • Continuous Improvementunmatched
  • Customer Support/Serviceunmatched
  • Cyber Threat Huntingunmatched
  • Disability Accommodationsunmatched
  • Documentationunmatched
  • Domain Namesunmatched
  • Establish Prioritiesunmatched
  • Federal Bureau of Investigation (FBI)unmatched
  • Federal Governmentunmatched
  • GCIA - GIAC Certified Intrusion Analystunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • Governmentunmatched
  • Government Contractsunmatched
  • Government Organizationsunmatched
  • Homeland Securityunmatched
  • Huntingunmatched
  • IP (Internet Protocol)unmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Industry/Trade Analysisunmatched
  • Injectionsunmatched
  • Intelligence Agenciesunmatched
  • Internet Securityunmatched
  • Inversion of Control (IoC)unmatched
  • Knowledge Managementunmatched
  • Local Governmentunmatched
  • Malwareunmatched
  • National Security Agency (NSA)unmatched
  • OSINT (Open Source Intelligence)unmatched
  • Online Marketingunmatched
  • Operations Processesunmatched
  • Oracle PL-SQLunmatched
  • Patient Assessmentunmatched
  • Penetration Testingunmatched
  • Presentation/Verbal Skillsunmatched
  • Regulationsunmatched
  • Riskunmatched
  • SQL (Structured Query Language)unmatched
  • Scripting (Scripting Languages)unmatched
  • Security Attacksunmatched
  • Security Clearanceunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Sensitive Compartmented Information (SCI)unmatched
  • Small Businessunmatched
  • Standard Operating Procedures (SOP)unmatched
  • State Governmentunmatched
  • Team Playerunmatched
  • Technical Analysisunmatched
  • Technical Researchunmatched
  • Telemetryunmatched
  • Time Managementunmatched
  • Top Secret Clearanceunmatched
  • United States Citizenunmatched
  • United States Department of Defense (DoD)unmatched
  • Web Infrastructureunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder