Назад
Company hidden
5 дней назад

Cyber Real-Time Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Релокация
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Real-Time Analyst (Cybersecurity): Monitoring and defending Joint Fires Network environments in a 24/7/365 SOC with an accent on real-time alert triage, incident response, SIEM operations, and classified DoD networks. Focus on tuning Corelight and Elastic Defend sensors, developing behavioral threat-hunting playbooks, and executing response procedures in TS/SCI SCIF facilities.

Location: Full-time onsite in Ford Island, Hawaii; telework is not permitted. The role requires 24/7/365 rotating shifts in a secure SCIF. Relocation expenses may be eligible for reimbursement.

Company

hirify.global provides security compliance, program governance, consulting, and customized technology solutions for public sector clients.

What you will do

  • Monitor Joint Fires Network transport components, edge nodes, and management channels around the clock; triage alerts and investigate anomalies.
  • Review syslogs, verify ingestion pipelines, correlate events, and identify malicious activity, configuration drift, and indicators of compromise.
  • Operate Elastic SIEM and Elastic Defend, analyze Kibana dashboards, write KQL queries, and manage incident workflows in JIRA.
  • Support development, testing, and execution of the JFN Incident Response Plan and DIA-aligned TS/SCI incident reporting.
  • Tune Corelight, Darktrace, and related security sensors while developing threat-hunting, containment, and remediation playbooks.
  • Coordinate with NOC engineers, DISA defenders, NIWC data-pipeline engineers, and other mission stakeholders.

Requirements

  • U.S. citizenship and an active Top Secret clearance with current SCI eligibility are required before starting.
  • Level II qualification: a relevant bachelor’s degree and 2+ years of SOC or defensive cyber operations experience, or equivalent associate-degree or experience pathways.
  • An active DoD 8140.03 / DCWF Work Role Code 531 Cyber Defense Analyst certification or qualifying degree at the Intermediate Proficiency Level is required.
  • Hands-on experience in a live 24/7/365 SOC with event correlation, alert triage, intrusion analysis, and SIEM operations.
  • Practical knowledge of Elasticsearch, Logstash, Kibana, Elastic Defend, KQL, JIRA, network protocols, packet inspection, and syslog parsing.
  • Ability and willingness to work rotating days, nights, weekends, and holidays onsite inside a secure SCIF.

Nice to have

  • Experience with DoD IL-6/7 networks, SIPRNet, TS/SCI or JWICS enclaves, C4ISR systems, or joint tactical environments.
  • Experience with Corelight/Zeek, Darktrace MDR, Palo Alto ATP logs, or MITRE ATT&CK detection logic.
  • Level III experience: a technical bachelor’s degree with 4+ years of SOC/CND experience or equivalent pathways.

Culture & Benefits

  • Medical, dental, and vision coverage with multiple medical plan options.
  • Paid time off, paid holidays, and paid parental leave.
  • Pre-tax and Roth retirement savings accounts, life insurance, and disability coverage.
  • Tuition and training reimbursement, flexible and dependent care savings accounts, and an employee assistance program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →