ECS

Cybersecurity Analyst (CDAP) - Journeyman

ECS$80K — $110K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizenship required
  • Secret security clearance eligibility
  • 3+ years of cybersecurity experience
  • Proficiency in detection logic for behavioral indicators and insider threat use cases
  • Experience in data correlation from security or user activity sources
  • Ability to create clear investigative documentation
  • Familiarity with continuous monitoring and RMF security operations

Responsibilities

  • Develop and tune analytic rules to detect anomalous user activity and insider threats
  • Correlate data for alert triage and investigative analysis
  • Document findings and support case development activities
  • Coordinate with various teams for validation and escalations
  • Create MITRE ATT&CK-based analytics for threat detection
  • Integrate detections using enterprise data sources in ENOCS
  • Enhance analytic effectiveness across classified and unclassified environments
  • Support cybersecurity policy compliance and governance activities

Benefits

  • Opportunity to support the Army National Guard's cybersecurity mission
  • Access to a large, diverse user base across multiple states and territories
  • Collaboration with leading cybersecurity teams and technologies
  • Participation in a 24/7 cybersecurity operations environment
  • Opportunity for professional development in a critical national security space
Full Job Description
Position Summary

ECS is seeking a Cybersecurity Analyst (CDAP) - Journeyman to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this Task 3 role supporting Cybersecurity Operations Support, the Analytic Developer/Insider Threat Analyst develops, implements, and tunes analytic rules and detection logic to identify anomalous user activity, insider threat indicators, and high-risk behavioral patterns across ARNG enterprise environments. The position correlates data from multiple security and user activity sources, performs alert triage and investigative analysis, documents findings with supporting evidence, and supports case development and reporting in coordination with SOC/CIRT, CTIC, defensive cyber, and security engineering teams to strengthen Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM) across the DoDIN-Army-NG area of responsibility.

Please Note: This position is contingent upon contract award.

This role directly supports the ARNG mission to deliver and defend DoDIN services for more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories, including Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The analyst contributes to a 24x7x365 cybersecurity operations environment that coordinates with the NETCOM Global Cyber Center and DISA DCDC and leverages ARNG's Unified Security Information & Event Management (USIEM) analytics ecosystem, integrated SIEM/C2C/DLP analytics, MITRE ATT&CK-based detections, Zeek metadata, Sysmon-informed monitoring, EDR, SOAR, and continuous monitoring processes to improve visibility, detection fidelity, and response across classified and unclassified network environments.

Responsibilities

  • Develop, implement, and tune analytic rules, correlation logic, and behavioral detections to identify anomalous user activity, insider threat indicators, and high-risk patterns across ARNG enterprise environments.
  • Correlate data from multiple security and user activity sources to support triage, investigation, and evidence-based analysis of alerts, suspicious behaviors, and potential insider threat activity.
  • Perform in-depth alert analysis and document investigative findings, recommended actions, and supporting artifacts for case development, reporting, and follow-on response activities.
  • Coordinate with SOC, CIRT, CTIC, defensive cyber, and security engineering personnel to validate findings, refine detection content, and support escalation through Tier 2 incident, problem, and change processes as appropriate.
  • Create and improve MITRE ATT&CK-based analytics within the ARNG USIEM environment to enhance threat-informed detection and centralized visibility.
  • Support integration and refinement of detections using relevant enterprise data sources identified in ENOCS operations, including SIEM/C2C/DLP analytics, Zeek metadata, Sysmon-based monitoring, EDR telemetry, and baseline/trend analysis.
  • Coordinate with USIEM engineers and AESS-aligned endpoint security stakeholders to improve enabling data sources, detection coverage, and analytic effectiveness across classified and unclassified enclaves.
  • Ensure analytic development and investigative activities align with DoD and ARNG cybersecurity policy, insider threat program requirements, RMF controls, eMASS evidence expectations, and continuous monitoring objectives.
  • Contribute to reporting and governance activities that strengthen cyber defense across the DoDIN-Army-NG AOR and support coordination with NETCOM, ARCYBER, USCYBERCOM, and RCC stakeholders when required.


Required Qualifications

U.S. Citizenship is required

Security Clearance: Secret Eligible

Required Certifications: DCWF Work Role 462-Control Systems Security Specialist - Basic proficiency; must hold ONE OR MORE of the following: DAF 462 (Basic) (ICS)

Experience: 3+ years of experience in cybersecurity
  • Experience developing and tuning detection logic or analytic content for anomalous activity, behavioral indicators, or insider threat use cases.
  • Experience correlating data from multiple security or user activity sources to support alert triage, investigative analysis, and documented findings.
  • Ability to produce clear investigative documentation, supporting evidence, and reporting suitable for case development and stakeholder review.
  • Experience coordinating with incident response, security operations, cyber intelligence, or security engineering teams to validate findings and improve detection outcomes.
  • Familiarity with continuous monitoring objectives, RMF-aligned security operations, and documenting artifacts that support ongoing cybersecurity compliance.
  • Experience working within enterprise cybersecurity operations supporting classified and unclassified environments.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Aerospace & Defense Jobs

  • Model Based Systems Engineer
    $130K — $150K + paid health insurance & dependents, paid education assistance, *
    Kitty Hawk Technologies
    King George, VA 22485 (King George County)
  • BAE Systems
    Eng Prin - Mech
    $100K — $130K *
    BAE Systems
    Hudson, NH 03051 (Hillsborough County)
  • Genesis Analysis / Software Engineer
    $80K — $120K *
    Mclaurin Aerospace
    Houston, TX 77084 (Harris County)
  • BAE Systems
    Eng II - Elec
    $90K — $120K *
    BAE Systems
    Nashua, NH 03060 (Hillsborough County)
  • BAE Systems
    Eng Sr - Sys
    $90K — $120K *
    BAE Systems
    Huntsville, AL 35810 (Madison County)

Find similar Cybersecurity Analyst (CDAP) - Journeyman jobs: