Blue Team Lead / Sr Cyber Defense AnalystFort Bragg, NCPOSITION SUMMARY: The Blue Team Lead / Senior Cyber Defense Analyst is responsible for leading advanced cyber defense operations for an Army cyber contract. This role serves as the technical lead for threat detection, threat hunting, incident analysis, and detection engineering, with a focus on identifying and mitigating advanced persistent threats (APTs) and sophisticated cyber intrusions.
Key Responsibilities:- Lead the investigation and analysis of advanced cyber threats, suspected APT activity, and complex security incidents.
- Plan and execute proactive threat hunting operations to identify malicious activity not detected by traditional security controls.
- Develop, test, and maintain detection content, including SIEM correlation rules, YARA rules, Snort/Suricata signatures, and host-based detection policies.
- Collaborate with Cyber Threat Intelligence (CTI) teams to validate and promote new detection signatures into the enterprise security monitoring environment.
- Provide technical leadership during incident response activities and support containment, eradication, and recovery efforts.
- Mentor and provide on-the-job training to Tier 1 and Tier 2 Cyber Defense Analysts, improving team capabilities and operational effectiveness.
- Continuously refine detection strategies and recommend improvements to cyber defense processes, tools, and procedures.
- Prepare technical reports, document findings, and communicate risks and recommendations to leadership.
Preferred Qualifications:- 7+ years experience leading cyber defense, threat hunting, or Security Operations Center (SOC) teams in a DoD or federal environment.
- Strong knowledge of SIEM platforms, network and endpoint detection technologies, and threat detection methodologies.
- Experience creating detection content using tools such as YARA, Snort, Suricata, and host-based security solutions.
- Understanding of adversary tactics, techniques, and procedures (MITRE ATT&CK) and advanced persistent threat (APT) behaviors.
- Active DoD Secret clearance
- Desired certifications: Security+, CASP, CISSP
At Indigo IT, we offer an expansive benefits package for our employees, which includes: Medical, Dental, and Vision coverage options. In addition, we offer 401(k) with company match, Group life and disability, Flex Spending Accounts (FSA), Paid Time Off (PTO), Paid holidays, and Education assistance. We also have in house training programs for employees, we reward thought leadership with bonuses and recognition for publishing, speaking, and innovative thought leadership in our industry.
Pay Range: $125,000 - $150,000 per year