Назад
Company hidden
5 дней назад

Cyber Threat Analyst

Формат работы
onsite
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Threat Analyst (Cybersecurity): Supporting a classified Joint Fires Network SOC by hunting advanced threats, analyzing network telemetry, and developing behavioral detection playbooks with an accent on threat intelligence, incident response, and Elastic SIEM analysis. Focus on mapping adversary TTPs to MITRE ATT&CK, tuning KQL/EQL detections, and handling TS/SCI incidents across tactical operational networks.

Location: Full-time onsite in Ford Island, HI; telework is not permitted. Relocation expenses may be eligible for reimbursement. U.S. citizenship and an active Top Secret clearance with current SCI eligibility are required before the start date.

Company

hirify.global provides security compliance, program governance, consulting, and customized solutions for public sector clients.

What you will do

  • Support defensive cyber operations for the Joint Fires Network Security Operations Center in secure SCIF facilities.
  • Design, test, and operationalize threat-hunting playbooks for behavioral anomalies, command and control, lateral movement, and traffic deviations.
  • Analyze network telemetry, sensor feeds, syslog audits, NetFlow, proxy logs, and packet captures across operational nodes.
  • Develop and tune Elastic Search, Elastic Defend, KQL, and EQL detections while reducing false positives.
  • Develop containment strategies, incident documentation, and response playbooks in JIRA.
  • Support TS/SCI incident reporting, the JFN Incident Response Plan, CSSP functions, and threat briefings for mission stakeholders.

Requirements

  • U.S. citizenship and an active Top Secret clearance with current SCI eligibility are mandatory.
  • At least 2 years of relevant experience with a bachelor's degree, 4 years with an associate degree, or 6 years of relevant cyber intelligence experience in lieu of a degree.
  • Senior-level consideration requires 4 years with a bachelor's degree, 6 years with an associate degree, or 8 years of relevant experience or military service.
  • A valid DoD 8140.03 / DCWF Work Role Code 531 certification or qualifying degree at the Intermediate Proficiency Level is required.
  • Experience in threat hunting, cyber threat intelligence, incident analysis, or tier-2/tier-3 SOC operations within a DoD, military, or government environment.
  • Ability to work operational shifts and participate in on-call surge or emergency incident escalation.

Nice to have

  • Experience with C4ISR systems, tactical operational enclaves, Corelight, Darktrace MDR, or Palo Alto Advanced Threat Prevention.
  • Experience using Gemini, Grok, or ChatGPT for threat-hunting data collection and indicator extraction.
  • Higher-level certifications such as CASP+ CE, CISSP, GCIA, or GCIH.

Culture & Benefits

  • Medical, dental, and vision coverage options.
  • Personal time off, paid holidays, and paid parental leave.
  • Retirement savings accounts, flexible spending accounts, life insurance, and disability coverage.
  • Tuition, training, and certification reimbursement, including access to cyber training pipelines and technical credential support.
  • Long-term program support for strategic defense requirements across DISA.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →