5 дней назад
Cyber Threat Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Threat Analyst (Cybersecurity): Supporting a classified Joint Fires Network SOC by hunting advanced threats, analyzing network telemetry, and developing behavioral detection playbooks with an accent on threat intelligence, incident response, and Elastic SIEM analysis. Focus on mapping adversary TTPs to MITRE ATT&CK, tuning KQL/EQL detections, and handling TS/SCI incidents across tactical operational networks.
Location: Full-time onsite in Ford Island, HI; telework is not permitted. Relocation expenses may be eligible for reimbursement. U.S. citizenship and an active Top Secret clearance with current SCI eligibility are required before the start date.
Company
provides security compliance, program governance, consulting, and customized solutions for public sector clients.
What you will do
- Support defensive cyber operations for the Joint Fires Network Security Operations Center in secure SCIF facilities.
- Design, test, and operationalize threat-hunting playbooks for behavioral anomalies, command and control, lateral movement, and traffic deviations.
- Analyze network telemetry, sensor feeds, syslog audits, NetFlow, proxy logs, and packet captures across operational nodes.
- Develop and tune Elastic Search, Elastic Defend, KQL, and EQL detections while reducing false positives.
- Develop containment strategies, incident documentation, and response playbooks in JIRA.
- Support TS/SCI incident reporting, the JFN Incident Response Plan, CSSP functions, and threat briefings for mission stakeholders.
Requirements
- U.S. citizenship and an active Top Secret clearance with current SCI eligibility are mandatory.
- At least 2 years of relevant experience with a bachelor's degree, 4 years with an associate degree, or 6 years of relevant cyber intelligence experience in lieu of a degree.
- Senior-level consideration requires 4 years with a bachelor's degree, 6 years with an associate degree, or 8 years of relevant experience or military service.
- A valid DoD 8140.03 / DCWF Work Role Code 531 certification or qualifying degree at the Intermediate Proficiency Level is required.
- Experience in threat hunting, cyber threat intelligence, incident analysis, or tier-2/tier-3 SOC operations within a DoD, military, or government environment.
- Ability to work operational shifts and participate in on-call surge or emergency incident escalation.
Nice to have
- Experience with C4ISR systems, tactical operational enclaves, Corelight, Darktrace MDR, or Palo Alto Advanced Threat Prevention.
- Experience using Gemini, Grok, or ChatGPT for threat-hunting data collection and indicator extraction.
- Higher-level certifications such as CASP+ CE, CISSP, GCIA, or GCIH.
Culture & Benefits
- Medical, dental, and vision coverage options.
- Personal time off, paid holidays, and paid parental leave.
- Retirement savings accounts, flexible spending accounts, life insurance, and disability coverage.
- Tuition, training, and certification reimbursement, including access to cyber training pipelines and technical credential support.
- Long-term program support for strategic defense requirements across DISA.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Cyber Threat Hunter
80 000 - 110 000$
11 дней назад
Cyber Security Analyst, Senior (High Level Clearance Required)
108 476 - 184 409$
CoreWeave
10 дней назад
Senior Security Engineer, Detection Engineer
134 000 - 179 000$
CrowdStrike
7 дней назад
Analyst I, Falcon Complete (Cybersecurity)
85 000 - 120 000$
12 дней назад
Tier 3 Security Analyst (AI)
140 000 - 152 000$
6 дней назад
Principal Cyber Threat Intelligence Analyst (AI)
96 500 - 207 500$