Cybersecurity Defense Analyst II

Invictus International Consulting, LLC

$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a technical discipline, or 4 years of additional relevant experience in lieu of a degree
  • Minimum of 4 years of relevant cybersecurity experience
  • Knowledge of TCP/IP, DNS, HTTP/S, authentication methods, and enterprise networking
  • Hands-on experience with SIEM and related security technologies
  • Ability to conduct independent investigations and articulate evidence-based findings
  • Current DoD 8570 IAT II or IAM II certification
  • Experience in a DoD or Intelligence Community environment

Responsibilities

  • Monitor and triage security alerts and incidents independently
  • Analyze cybersecurity data from various enterprise systems and security tools
  • Document findings of investigations within a ticketing system
  • Handle incident triage including validation and escalation
  • Support all phases of incident response from detection to reporting
  • Correlate data from multiple sources to identify security threats
  • Communicate incident findings and recommended actions to stakeholders

Benefits

  • Opportunities for professional development and certification
  • Supportive work environment promoting innovation and collaboration
  • Engagement with high-level government and technical teams
  • Access to advanced security technologies and methodologies
  • Work in a mission-critical cybersecurity role
Full Job Description
Title: Cyber Defense Analyst II

Location: Alexandria, VA

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details:
  • Independently monitor, triage, and investigate routine and moderately complex security alerts and suspected incidents.
  • Perform cyber defense monitoring and analysis using security information from enterprise systems, networks, security sensors, firewalls, intrusion detection/prevention technologies, endpoint sources, and other available telemetry.
  • Analyze log files and network activity to identify anomalous or malicious behavior, determine potential security impact, and document investigative findings in the authorized case or ticketing system
  • Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
  • Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
  • Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
  • Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
  • Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
  • Develop and test investigative hypotheses by correlating network, host, identity, firewall, vulnerability, and threat data
  • Identify related activity beyond the initially alerted system and appropriately expand investigative scope
  • Execute established incident response and escalation procedures and coordinate with technical teams when containment or remediation action is required
  • Identify recurring alert-quality, telemetry, or process issues and recommend improvements to senior analysts


Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Working knowledge of TCP/IP, DNS, HTTP/S, authentication, enterprise networking, Windows/Linux security events, and common adversary techniques
  • Hands-on experience using SIEM and one or more network, endpoint, firewall, IDS/IPS, or security-analysis technologies
  • Ability to independently investigate security activity, distinguish facts from assumptions, and communicate evidence-based conclusions
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph


Similar Jobs

More Jobs at Invictus International Consulting, LLC

More Information Technology Jobs

Find similar Cybersecurity Defense Analyst II jobs: