Cybersecurity Analyst IV

The National Renewable Energy Laboratory (NREL)

$100K — $180K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 9+ years of relevant experience, or Master's with 7+ years, or PhD with 4+ years.
  • One or more professional security certifications (e.g., C|EH, Security+, GIAC, ISC2).
  • Expertise in areas such as network packet analysis, digital forensics, and malware analysis.
  • Technical proficiency across Windows, Mac, and Linux operating systems.
  • Strong troubleshooting and analytical skills.

Responsibilities

  • Mentor colleagues on cybersecurity and incident response.
  • Investigate security alerts and events.
  • Analyze event information to identify intrusion attempts.
  • Lead incident response and recovery efforts.
  • Educate staff on reporting potential security threats.
  • Research and evaluate security tools and tactics.
  • Develop and maintain Cyber Incident Response Procedures.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Short- and long-term disability insurance.
  • Employer-matched 403(b) retirement plan.
  • Generous paid time off and sick leave policies.
  • Tuition reimbursement and potential relocation assistance.
Full Job Description
Posting Title
Cybersecurity Analyst IV

Location
CO - Golden

Position Type
Regular

Hours Per Week
40

Job Description

The cybersecurity analyst monitors NLR's networks and computing systems for suspicious or unwanted activity, investigates the causes and impacts of the activity, and ensures any related security issues are remediated. The cybersecurity analyst excels at using a combination of technical tools, analysis techniques, intuition, and soft skills to identify, investigate, respond to, and report instances of or trends in anomalous activity. Strong leadership, mentoring, analysis, decision making, and communication skills, including the ability to relay highly technical information to non-technical audiences, and the ability to retain composure under pressure, are a must. This position is primarily virtual but reasonable proximity to NLR's Golden, CO campus is preferred to support onsite activity.

  • Mentor and share knowledge with teammates in the areas of cybersecurity analysis, digital forensics, intelligence analysis, incident response, insider threat detection, employee investigations, and incident reporting/documentation.
  • Respond to alerts and investigate security events.
  • Recognize successful and unsuccessful intrusion attempts through analysis of relevant event information.
  • Perform incident response, analysis, and recovery actions.
  • Provide Cyber Incident Response Team (CIRT) leadership.
  • Regularly interact with and educate NLR colleagues who report suspected security threats.
  • Research and evaluate security tools and attacker tactics, techniques, and procedures to improve NLR's ability to detect and respond to malicious activity.
  • Develop, maintain, and evolve the Cyber Incident Response Procedure and supporting operating procedures.
  • Perform forensic tasks to understand the scope and impact of an incident and to collect, preserve and analyze evidence collected during incidents and authorized internal investigations.
  • Provide input and support to security tool engineering efforts that enhance detection, analysis, and automation capabilities.
  • Define mechanisms for reporting trends in security events and incidents observed within NLR information systems for management risk awareness and to support continuous monitoring of NLR's security posture.
  • Initiates, leads, and/or is a primary contributor to projects that improve the effectiveness and efficiency of NLR's cybersecurity program, including but not limited to workflow improvements, management tool enhancements, program or NLR strategic initiatives, and user awareness training.


Basic Qualifications
Relevant Bachelor's Degree and 9 or more years of experience or equivalent relevant education/experience. Or, relevant Master's Degree and 7 or more years of experience or equivalent relevant education/experience. Or, relevant PhD and 4 or more years of experience or equivalent relevant education/experience. Applies extensive IS expertise in specific field and has full knowledge of related disciplines. Evaluates new hardware, software, systems tools and applications and makes procurement recommendations. Excellent leadership and project management skills. Skilled in analytical techniques, practices and problem solving. Extensive programming and architecture abilities with various computer software programs and information systems.

* Must meet educational requirements prior to employment start date.

Additional Required Qualifications
  • One or more professional security certifications, such as C|EH, Security+, GIAC (SANS), or ISC2 certifications.
  • Subject matter expertise in a multiple of the following areas: network packet and protocol analysis, forensic analysis, e-discovery, insider threat analysis, malware analysis, data enrichment and aggregation, security intelligence analysis, threat hunting.
  • Technical background in multiple disciplines, including experience with: Windows, Mac and Linux operating systems, including system administration; TCP/IP networking concepts, protocols and architecture; security measures/defense-in-depth; security and availability monitoring.
  • In-depth understanding of common cybersecurity concepts and threats and ability to apply that knowledge to strengthen the security operations function.
  • Strong troubleshooting skills with ability to synthesize multiple related data points into a coherent understanding of an event or series of related events.
  • Ability to relay technical information to non-technical audiences in a relatable, effective manner.


Preferred Qualifications
  • Experience includes at least five years in an Information Technology role working in security analysis or incident response.
  • Experience managing or configuring Splunk or other SIEM platform(s).
  • Experience performing investigations and analysis with an enterprise EDR platform.
  • Experience performing incident response in virtualized and cloud computing environments.
  • Experience automating tasks with a SOAR platform.
  • Experience configuring and maintaining incident response triage and tracking systems, workflows, and playbooks.


Standard Requirements for All Cyber Positions
  • Ability to perform research, read documentation, and independently learn new skills.
  • Ability to work both alone and as part of a collaborative team.
  • Demonstrated skills in critical thinking and problem solving.
  • Excellent communication skills, including active listening, ability to prepare and deliver presentations, and clear written correspondence and documentation.
  • DOE Q Clearance: Must be able to obtain and maintain a DOE Q Security Clearance. Eligibility requirements: To obtain a clearance, an individual must be at least 18 years of age and a U.S. citizen. See DOE O 472.2A for additional information.


Job Application Submission Window

The anticipated closing window for application submission is up to 30 days and may be extended as needed.

Annual Salary Range (based on full-time 40 hours per week)
Job Profile: IT Professional IV / Annual Salary Range: $100,400 - $180,700

NLR takes into consideration a candidate's education, training, and experience, expected quality and quantity of work, required travel (if any), external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. In compliance with the Colorado Equal Pay for Equal Work Act, a potential new employee's salary history will not be used in compensation decisions.

Benefits Summary
Benefits include medical, dental, and vision insurance; short*- and long-term disability insurance; pension benefits*; 403(b) Employee Savings Plan with employer match*; life and accidental death and dismemberment (AD&D) insurance; personal time off (PTO) and sick leave; paid holidays; and tuition reimbursement*. NLR employees may be eligible for, but are not guaranteed, performance-, merit-, and achievement- based awards that include a monetary component. Some positions may be eligible for relocation expense reimbursement. Limited-term positions are not eligible for long-term disability or tuition reimbursement.

* Based on eligibility rules

Badging Requirement
NLR is subject to Department of Energy (DOE) access restrictions. All employees must also be able to obtain and maintain a federal Personal Identity Verification (PIV) card as required by Homeland Security Presidential Directive 12 (HSPD-12), which includes a favorable background investigation.

Similar Jobs

More Jobs at The National Renewable Energy Laboratory (NREL)

More Information Technology Jobs

Find similar Cybersecurity Analyst IV jobs: