SENTINEL GROUP LLC

Cybersecurity Blue Team Analyst – Senior

SENTINEL GROUP LLC Chantilly, Virginia, United States

Transportation, Logistics, Supply Chain and Storage · 11-50 employees

11 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Cybersecurity Blue Team Analyst leads comprehensive security assessments across complex enterprise environments, including cloud, network, and endpoint infrastructure. They are responsible for identifying systemic risks, developing remediation strategies, and providing technical leadership for incident response and defensive operations.

What they look for

Cybersecurity Vulnerability Management Threat Hunting Incident Response Security Architecture SIEM EDR/XDR Network Security Cloud Security Identity and Access Management Risk Assessment NIST SP 800-53 RMF STIGs Technical Leadership Security Analytics

Requirements

Candidates must have at least 7 years of experience in cybersecurity and hold a Top Secret security clearance. Expert knowledge of enterprise security standards such as NIST SP 800-53, RMF, and STIGs, along with a DoD 8570 IAT Level III certification, is required.

Full description

Minimum Qualifications:

The Senior Cybersecurity Blue Team Analyst serves as a technical authority for cybersecurity assessment and defensive cyber operations across complex enterprise IT environments. The analyst leads assessments of infrastructure, applications, networks, cloud environments, security architectures, and enterprise services; evaluates systemic cybersecurity risk; and develops actionable recommendations to improve the organization's defensive posture.

Responsibilities:

  • Lead comprehensive cybersecurity assessments across complex, heterogeneous enterprise IT environments.
  • Assess security architecture, controls, configurations, operational practices, and telemetry across on-premises, cloud, hybrid, and distributed environments.
  • Evaluate security of enterprise networks, Windows and Linux infrastructure, endpoints, applications, databases, virtualization platforms, cloud services, identity and access management systems, network-security infrastructure, and security-management platforms.
  • Lead vulnerability assessments, configuration reviews, security-control assessments, threat hunts, and defensive cyber assessments.
  • Analyze complex security events and telemetry to identify sophisticated attacks, lateral movement, persistence mechanisms, privilege escalation, data exfiltration, and other adversary behaviors.
  • Correlate information across SIEM, EDR/XDR, network, identity, cloud, application, vulnerability-management, and infrastructure-management platforms.
  • Lead investigations of significant cybersecurity incidents and provide technical direction for containment, eradication, recovery, and lessons learned.
  • Evaluate enterprise attack surfaces and identify systemic weaknesses spanning multiple systems or technology domains.
  • Develop risk-based remediation strategies and prioritize findings based on mission impact, exploitability, exposure, and adversary activity.
  • Lead development and improvement of cybersecurity assessment methodologies, automated assessment capabilities, detection strategies, and defensive analytics.
  • Translate technical findings into actionable recommendations for government and senior technical leadership.
  • Review and approve assessment plans, technical findings, reports, and remediation recommendations developed by other analysts.
  • Mentor and provide technical leadership to entry- and intermediate-level analysts.
  • Serve as a subject-matter expert on enterprise defensive cybersecurity, security assessment, vulnerability management, and threat detection.
  • Track emerging vulnerabilities, attack techniques, adversary TTPs, and changes in enterprise technology to continuously improve assessment and defensive capabilities.

Required Qualifications:

  • 7+ years of experience in cybersecurity, defensive cyber operations, security engineering, information assurance, vulnerability management, or a related field.
  • Demonstrated ability to lead cybersecurity assessments across diverse and complex enterprise IT environments.
  • Expert knowledge of enterprise network architecture, operating systems, cloud computing, virtualization, applications, databases, identity and access management, and cybersecurity technologies.
  • Demonstrated experience with SIEM, EDR/XDR, vulnerability management, network security, threat hunting, incident response, and security analytics technologies.
  • Expert knowledge of NIST SP 800-53, NIST SP 800-37, RMF, STIGs, CIS benchmarks, and related cybersecurity standards and practices.
  • Ability to evaluate technical and architectural risks across multiple interconnected systems and technology domains.
  • Strong technical writing, briefing, analytical, and leadership skills.
  • DoD 8570 IAT Level III certification required.
  • Must hold Top Secret security clearance. Counterintelligence polygraph desired.

Similar roles