Cyber Analytics Engineer III

RISA

• $78K — $86K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship and active TS/SCI required.
  • Must pass a Government polygraph post-hire.
  • Bachelor's degree plus 6 years of relevant experience, or equivalent combinations accepted.
  • 8+ years of advanced cyber security analytics experience.
  • DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst certification compliant.
  • Experience with data mining or SIEM query building.
  • Strong skills in signature development, tuning, and network protocol analysis.

Responsibilities

  • Analyze trends to identify previously undiscovered cyber threats.
  • Develop or tune rules, signatures, and scripts based on intelligence data.
  • Run Purple Team exercises to validate existing countermeasures.
  • Collaborate with the Cyber Data Analytics team to evaluate SIEM alert efficiency.
  • Support the Cyber Incident Response Team during live responses to predict adversary actions.
  • Document analyses clearly in the ticketing system for stakeholder access.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) and Roth options available.
  • Generous Paid Time Off.
  • 11 paid Federal Holidays.
Full Job Description
Cyber Threat Detection Engineer (SIEM / Signature Development)

Cyber Security Operations Specialist III - Advanced Cyber Analytics

Location: St. Louis, MO - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Travel: None

Salary Range: $78,000 - $86,000

What You Will Do
  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
  • Turn intelligence and incident reporting into deployed detection logic.
  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.
  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.

What You'll Bring
  • S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • 8+ years of related advanced cyber security analytics experience.
  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
  • Data mining or query building in a SIEM.
  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
  • Static file signatures (magic numbers) and good working knowledge of regular expressions.

Nice to Have
  • Hex editor comfort; Python, Bash, or PowerShell scripting.
  • Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

Similar Jobs

More Jobs at RISA

More Technical Services Jobs

Find similar Cyber Analytics Engineer III jobs: