Cybersecurity Defense Analyst II
Invictus International Consulting, LLC Alexandria, Virginia, United States
Defense and Space Manufacturing · 201-500 employees
About the role
The analyst will monitor, triage, and investigate security alerts while performing cyber defense analysis across enterprise systems and networks. They are responsible for incident handling, evidence preservation, and communicating findings to stakeholders and management.
What they look for
Requirements
Candidates must possess a bachelor's degree in a technical discipline or equivalent experience, along with at least four years of relevant professional experience. A current DoD 8570 IAT II or IAM II certification and an active TS/SCI clearance are required.
Full description
Title: Cyber Defense Analyst II
Location: Alexandria, VA
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
- Independently monitor, triage, and investigate routine and moderately complex security alerts and suspected incidents.
- Perform cyber defense monitoring and analysis using security information from enterprise systems, networks, security sensors, firewalls, intrusion detection/prevention technologies, endpoint sources, and other available telemetry.
- Analyze log files and network activity to identify anomalous or malicious behavior, determine potential security impact, and document investigative findings in the authorized case or ticketing system
- Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
- Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
- Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
- Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
- Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
- Develop and test investigative hypotheses by correlating network, host, identity, firewall, vulnerability, and threat data
- Identify related activity beyond the initially alerted system and appropriately expand investigative scope
- Execute established incident response and escalation procedures and coordinate with technical teams when containment or remediation action is required
- Identify recurring alert-quality, telemetry, or process issues and recommend improvements to senior analysts
Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum four (4) years of relevant experience in addition to education level
- Working knowledge of TCP/IP, DNS, HTTP/S, authentication, enterprise networking, Windows/Linux security events, and common adversary techniques
- Hands-on experience using SIEM and one or more network, endpoint, firewall, IDS/IPS, or security-analysis technologies
- Ability to independently investigate security activity, distinguish facts from assumptions, and communicate evidence-based conclusions
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Similar roles
-
Senior Cybersecurity Analyst
Orbia Bogota, Capital District, RAP (Especial) Central, Colombia
-
CyberSecurity - Interns
Auctane Wrocław, Lower Silesian Voivodeship, Poland
-
Senior Manager Cybersecurity
Sia Brussels, Brussels-Capital, Belgium
-
Senior Consultant in Cybersecurity
Sia Antwerp, Antwerp, Belgium
-
Senior Security Engineer, AI/ML, National Security, Public Sector
Google Washington, District of Columbia, United States · $174K–$252K/yr
-
Pre-Sales Engineer, Cybersecurity
Hewlett Packard Enterprise Washington, District of Columbia, United States · $146K–$343K/yr