Cyber Analytics Engineer III

RISA

$78K — $86K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship and active TS/SCI clearance required.
  • Ability to obtain and maintain a Government polygraph post-hire.
  • Bachelor's degree plus 6 years relevant experience, or equivalent education and experience combinations accepted.
  • 8+ years of advanced cybersecurity analytics experience required.
  • Certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst needed.
  • Proficiency in data mining or query building in a SIEM environment necessary.
  • Expertise in signature development and tuning along with network protocol analysis is a must.

Responsibilities

  • Analyze trends to predict undiscovered events and develop detection rules.
  • Transform intelligence reports into deployed detection logic.
  • Conduct Purple Team exercises to validate security countermeasures.
  • Collaborate with Cyber Data Analytics on SIEM alert efficiency and false positive evaluation.
  • Assist Cyber Incident Response Team during live events by predicting adversary actions.
  • Document analysis work in the ticketing system for stakeholder access.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) and Roth retirement plan options.
  • Paid Time Off for employee??.
  • 11 paid Federal Holidays.
Full Job Description
Cyber Threat Detection Engineer (SIEM / Signatures)

Location: St. Louis, MO - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Travel: None

Salary Range: $78,000 - $86,000

What You Will Do
  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
  • Turn intelligence and incident reporting into deployed detection logic.
  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.
  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.

What You'll Bring
  • U.S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • 8+ years of related advanced cyber security analytics experience.
  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
  • Data mining or query building in a SIEM.
  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
  • Static file signatures (magic numbers) and good working knowledge of regular expressions.

Nice to Have
  • Hex editor comfort; Python, Bash, or PowerShell scripting.
  • Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

Similar Jobs

More Jobs at RISA

More Aerospace & Defense Jobs

Find similar Cyber Analytics Engineer III jobs: