Cyber Defense Analyst

G2IT

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Information Assurance, or related field preferred, or 8+ years of relevant experience without a degree.
  • 5+ years focused on the Cyber Defense discipline
  • 3+ years of experience monitoring and investigating cybersecurity tool alerts.
  • Active TS/SCI security clearance required.
  • Experience with SIEM systems like Splunk or Elastic, and NIDPS like Cisco FirePower or Palo Alto NGFW.
  • Knowledge of programming/scripting languages (e.g., Python, PowerShell) and penetration testing tools.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Monitor security tools and analyze alerts for TS/SCI networks.
  • Investigate cybersecurity alerts, escalating as necessary to Tier 2 support.
  • Manage incident tickets within the designated ticketing system.
  • Conduct threat hunting to identify malicious activities.
  • Perform wireless security scans and document findings.
  • Correlate alerts across platforms to detect threats.
  • Deliver cyber defense briefings and support defense exercises.

Benefits

  • Access to cutting-edge cybersecurity technology and tools.
  • Opportunity to work within a mission-focused team.
  • Skill enhancement through participation in cyber defense exercises.
  • Engagement in proactive threat hunting activities.
  • Support for professional development and certifications.
Full Job Description
We are seeking a Cyber Defense Analyst to join a mission focused team supporting the Navy's cybersecurity environment at the Office of Naval Intelligence (ONI) Hopper Global Communications Center (HGCC) in Suitland, MD.

In this role, you will serve on the front line of cyber defense, helping protect critical TS/SCI networks by monitoring and investigating cybersecurity alerts, identifying potential threats, and supporting proactive threat hunting activities. You will apply your experience in the Certified Network Defender (CND) discipline and knowledge of IT systems and networks to analyze security events, manage incident tickets, support intelligence gathering and analysis, and communicate findings to key stakeholders.

Primary Responsibilities
  • Perform first line monitoring of security tools and conduct initial analysis of alerts for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Monitor organizational cybersecurity tools for alerts, anomalies, and indicators of compromise.
  • Investigate and perform initial technical analysis of cybersecurity alerts and events, escalating potential incidents to Tier 2 as appropriate.
  • Create, update, and manage incident and event tickets within the approved ticketing system.
  • Conduct proactive threat hunting activities to identify potential malicious activity and emerging threats.
  • Perform wireless security scans of facilities and document and report findings.
  • Correlate alerts and security events across multiple platforms to identify patterns, trends, and potential threats.
  • Prepare and deliver operational and situational awareness briefings.
  • Support annual cyber defense exercises.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired, with 5+ years of experience.
  • 8+ years of relevant professional experience in lieu of a degree.
  • Active TS/SCI security clearance.
  • 5+ years of concentrated experience in the CND discipline, regardless of degree.
  • 3+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
  • Strong analytical, conceptual, and problem solving skills.

Required Certifications
  • Must possess one of the following certifications: CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, EC Council CEH, GIAC GCIA, GIAC GCIH, GICSP, or Cisco CyberOps.

Similar Jobs

More Jobs at G2IT

More Information Technology Jobs

Find similar Cyber Defense Analyst jobs: