Cybersecurity Analyst CDAP - Journeyman

ECS Federal LLC

Washington, DC

JOB DETAILS
SKILLS
Analysis Skills, Cyberspace, DCDC (Data Center Design Consultant), Defense Information Systems Agency (DISA), Ecosystems, Emergency Response, Endpoint Security, Identity Data Management, Information/Data Security (InfoSec), Internet Security, Metadata, Network Administration/Management, Operational Audit, Operational Support, Patient Assessment, Process Improvement, Reporting Skills, Risk, Security Information and Event Management (SIEM), Support Documentation, Telemetry, Trend Analysis, United States Department of Defense (DoD)
LOCATION
Washington, DC
POSTED
7 days ago

Position Summary

ECS is seeking a Cybersecurity Analyst (CDAP) - Journeyman to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this Task 3 role supporting Cybersecurity Operations Support, the Analytic Developer/Insider Threat Analyst develops, implements, and tunes analytic rules and detection logic to identify anomalous user activity, insider threat indicators, and high-risk behavioral patterns across ARNG enterprise environments. The position correlates data from multiple security and user activity sources, performs alert triage and investigative analysis, documents findings with supporting evidence, and supports case development and reporting in coordination with SOC/CIRT, CTIC, defensive cyber, and security engineering teams to strengthen Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM) across the DoDIN-Army-NG area of responsibility.

Please Note: This position is contingent upon contract award.

This role directly supports the ARNG mission to deliver and defend DoDIN services for more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories, including Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The analyst contributes to a 24x7x365 cybersecurity operations environment that coordinates with the NETCOM Global Cyber Center and DISA DCDC and leverages ARNG's Unified Security Information & Event Management (USIEM) analytics ecosystem, integrated SIEM/C2C/DLP analytics, MITRE ATT&CK-based detections, Zeek metadata, Sysmon-informed monitoring, EDR, SOAR, and continuous monitoring processes to improve visibility, detection fidelity, and response across classified and unclassified network environments.

Responsibilities

  • Develop, implement, and tune analytic rules, correlation logic, and behavioral detections to identify anomalous user activity, insider threat indicators, and high-risk patterns across ARNG enterprise environments.
  • Correlate data from multiple security and user activity sources to support triage, investigation, and evidence-based analysis of alerts, suspicious behaviors, and potential insider threat activity.
  • Perform in-depth alert analysis and document investigative findings, recommended actions, and supporting artifacts for case development, reporting, and follow-on response activities.
  • Coordinate with SOC, CIRT, CTIC, defensive cyber, and security engineering personnel to validate findings, refine detection content, and support escalation through Tier 2 incident, problem, and change processes as appropriate.
  • Create and improve MITRE ATT&CK-based analytics within the ARNG USIEM environment to enhance threat-informed detection and centralized visibility.
  • Support integration and refinement of detections using relevant enterprise data sources identified in ENOCS operations, including SIEM/C2C/DLP analytics, Zeek metadata, Sysmon-based monitoring, EDR telemetry, and baseline/trend analysis.
  • Coordinate with USIEM engineers and AESS-aligned endpoint security stakeholders to improve enabling data sources, detection coverage, and analytic effectiveness across classified and unclassified enclaves.
  • Ensure analytic development and investigative activities align with DoD and ARNG cybersecurity policy, insider threat program requirements, RMF controls, eMASS evidence expectations, and continuous monitoring objectives.
  • Contribute to reporting and governance activities that strengthen cyber defense across the DoDIN-Army-NG AOR and support coordination with NETCOM, ARCYBER, USCYBERCOM, and RCC stakeholders when required.

About the Company

E

ECS Federal LLC

ECS was founded in 2001 by experienced IT professionals with a commitment to quality processes, people and performance. Led by our Chairman, Roy Kapani, and an experienced executive leadership team, ECS provides our customers with solutions and services that support their critical needs and further mission objectives. This commitment has paved the way for expansive growth, year over year.

ECS gained market share in 2011 in the Department of Defense and Federal spaces through both organic and acquisition growth. In May, ECS completed its first strategic acquisition with the purchase of OAK Management, Inc., a leading provider of marine environmental services, ship systems engineering, maritime consulting and platform acquisition management. The OAK acquisition kicked off ECS’ intention to add tactical acquisitions as a part of its long term strategy to supplement and expand upon organic growth and to build enterprise value. ECS closed out 2011 with the acquisition of Paradigm Technologies, Inc. The Paradigm transaction added approximately 200 employees to ECS’ existing 900+ employees. Paradigm also added new Defense clients for ECS, including the Missile Defense Agency, the Navy’s Program Executive Officer for Integrated Warfare Systems, the United States Marine Corps, and the U.S. Marshals Service.

In 2012, ECS completed the acquisition of iLuMinA Solutions, Inc. iLuMinA brings large-scale Enterprise Resource Planning (ERP) software implementation and infrastructure design and development to ECS’ expanding capabilities.

ECS will continue to invest in corporate infrastructure and quality processes as we grow and enhance our ability to offer professional excellence to both our customers and our employees.

COMPANY SIZE
50 to 99 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2000
WEBSITE
http://www.ecs-federal.com/