Cyber Defense Analyst 3

The Swift Group

$49K — $290K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8 years of experience as a Cyber Defense Analyst in relevant programs or contracts.
  • Technical bachelor's degree can substitute for 2 years of experience.
  • 2 years of practical experience with TCP/IP fundamentals.
  • 2 years of experience using tcpdump or Wireshark.
  • 3 years of experience with SIEM suites like Splunk or ArcSight.
  • 3 years of experience in network and threat analysis software utilization.
  • CSSP Analyst baseline certification (e.g., CEH, CySA+).
  • IAT Level I or II certification required.
  • Computing Environment certification for supported systems.
  • Active TS/SCI security clearance with Polygraph required.

Responsibilities

  • Monitor, detect, and analyze anomalous activity using cyber defense tools.
  • Generate and route cybersecurity cases based on event history.
  • Perform advanced threat hunting through manual analysis.
  • Identify cyber-attack phases using knowledge of attack vectors and protocols.
  • Apply techniques for detecting network and host-based intrusions.
  • Analyze malicious activities to identify exploited weaknesses and methods.
  • Perform event correlation from multiple sources to assess attack effectiveness.
  • Lead and mentor team members in cyber defense expertise.

Benefits

  • Comprehensive healthcare benefits.
  • Wellness programs and resources.
  • Financial and retirement plans.
  • Opportunities for education and professional development.
  • Paid time off and holiday benefits.
Full Job Description
We are looking for a Cyber Defense Analyst 3 to join a growing team in Annapolis Junction, MD.

Responsibilities:

  • Use cyber defense tools to monitor, detect, analyze, categorize, and perform initial triage of anomalous activity.
  • Generate cybersecurity cases (including event's history, status, and potential impact for further action) and route as appropriate.
  • Perform advanced manual analysis to hunt previously unidentified threats.
  • Identify cyber-attack phases based on knowledge of common attack vectors and network layers, models and protocols.
  • Apply techniques for detecting host- and network-based intrusions.
  • Analyze malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
  • Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Possess deep knowledge of active directory abuse used by attackers for lateral movement and persistence.
  • Perform after-action reviews of team products to ensure completion of analysis.
  • Lead and mentor team members as a technical expert.


Requirements:

  • Eight (8) years of demonstrated experience as a CDA in programs and contracts of similar scope, type, and complexity.
  • A technical bachelor's degree from an accredited college or university may be substituted for two (2) years of CDA experience.
  • Two (2) years of demonstrated and practical experience in TCP/IP fundamentals.
  • Two (2) years of demonstrated experience with tcpdump or Wireshark.
  • Three (3) years of demonstrated experience using security information and event management suites (such as Splunk, ArcSight, Kibana, LogRhythm).
  • Three (3) years of demonstrated experience in network analysis and threat analysis software utilization.
  • CSSP Analyst baseline certification (e.g., CEH, CySA+, CFR, etc.)
  • IAT Level I or II certification
  • Computing Environment (CE) certification for supported systems
  • Global Information Assurances Certificate (GIAC) OR Global Certified Incident Handler (GCIH)
  • US citizenship and an active TS/SCI with Polygraph security clearance required


Pay Range: $49,996.80 - $290,004.00

Pay ranges are a general guideline and not intended as a guaranteed and/or implied final compensation or salary for this job opening. Determination of official compensation or salary relies on several different factors including, but not limited to: level of position, complexity of job responsibilities, geographic location, work experience, education, certifications, Federal Government contract labor categories, and contract wage rates.

At The Swift Group and Subsidiaries, you will receive comprehensive benefits including but not limited to: healthcare, wellness, financial, retirement, education, and time off benefits.

Similar Jobs

More Jobs at The Swift Group

More Information Technology Jobs

Find similar Cyber Defense Analyst 3 jobs: