Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetry
Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
Serve as a senior technical escalation point to less expereinced team members and provide hands-on guidance during complex investigations
Lead portions of incident response activities, including scoping, evidence analysis, containment recommendations, technical coordination, and post-incident review
Conduct proactive analysis and threat hunting when warranted to identify related or previously undetected activity
Develop, maintain, and improve analyst runbooks, investigative procedures, escalation criteria, incident playbooks, and shift-turnover practices
Partner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automation
Mentor junior analysts, support analyst qualification and exercises, and perform quality review of investigations and case documentation
Translate incident lessons learned into improved detections, procedures, training, and defensive recommendations
Requirements:
Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
Minimum six (6) years of relevant experience in addition to education level
Significant hands-on experience conducting cybersecurity investigations and incident response in enterprise environments.
Strong knowledge of network and host-based investigation, common adversary tactics, techniques, and procedures, and the MITRE ATT&CK framework
Experience developing or improving SOC procedures, incident playbooks, runbooks, or analyst training materials
Experience serving as an escalation point, technical lead, or mentor for cyber defense analysts
Must possess current DoD 8570 IAT II or IAM II certification
Experience working in a DoD or IC environment
Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Numbers & Facts
Location
Alexandria, VA
Skills
Analysis Skillsunmatched
Automationunmatched
Channel Strategiesunmatched
Computer Securityunmatched
DoD Directive 8140unmatched
DoD Directive 8570unmatched
Documentationunmatched
Firewallsunmatched
Governmentunmatched
Huntingunmatched
IAM - Information Assurance Managementunmatched
IAT - Information Assurance Technicalunmatched
Incident Managementunmatched
Incident Responseunmatched
Integrated Circuits (ICs)unmatched
Internet Securityunmatched
Materials Analysisunmatched
Mentoringunmatched
Procedure Developmentunmatched
Riskunmatched
Security Analysisunmatched
Security Attacksunmatched
Sensitive Compartmented Information (SCI)unmatched
Technical Leadershipunmatched
Telemetryunmatched
Top Secret Clearanceunmatched
United States Department of Defense (DoD)unmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.