Host Based Systems Analyst III

ARSIEM$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • BS in Computer Science, Cybersecurity, or related field; or HS Diploma with 7+ years of relevant experience.
  • 5+ years of experience in cyber forensic investigations with leading tools and techniques.
  • Strong understanding of SaaS, PaaS, and IaaS in cloud environments and hybrid identity security.
  • Expertise in acquiring forensically sound evidence and analyzing attacks.
  • Knowledge of M365/Azure and hybrid identity threats.
  • Knowledge of AWS, IAM, and cloud identity security best practices.

Responsibilities

  • Conduct forensic analysis from cloud platforms to identify compromise activity.
  • Investigate incidents targeting cloud and hybrid identity.
  • Correlate cloud events and network telemetry to validate IOCs and reconstruct timelines.
  • Develop detection logic using cloud-native tools and scripting.
  • Produce technical reports and support incident response procedures.
  • Enhance threat emulation and investigative capabilities for cloud projects.
  • Coordinate with teams and stakeholders on alerts and findings.

Benefits

  • $3,500 referral bonus for successful new candidate placements.
  • Commitment to Equal Opportunity and Affirmative Action employment practices.
  • Use of AI tools to enhance the hiring process while retaining human judgment.
Full Job Description
ARSIEM is looking for a Cyber Network Defense Analyst (CNDA) with Cloud Forensics experience. This position will support one of our Government clients in Arlington, VA.

Responsibilities

  • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
  • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
  • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
  • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
  • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
  • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
  • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.


Minimum Qualifications

  • BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 7+ years relevant experience.
  • 5+ years of experience in cyber forensic investigations with leading tools and techniques.
  • Strong understanding of SaaS, PaaS, and IaaS in cloud environments and hybrid identity security.
  • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
  • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
  • Knowledge of AWS, IAM, and best practices for cloud identity security.


Preferred Qualifications

  • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
  • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
  • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).
  • GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS, or Microsoft Cloud/Security certifications.


Clearance Requirement: This position requires an Active TS/SCI clearance and the ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability.

Candidate Referral: Do you know someone who would be GREAT at this role? If you do, ARSIEM has a way for you to earn a bonus through our referral program for persons presenting NEW (not in our resume database) candidates who are successfully placed on one of our projects. The bonus for this position is $3,500, and the referrer is eligible to receive the sum for any applicant we place within 12 months of referral. The bonus is paid after the referred employee reaches 6 months of employment.

Similar Jobs

More Jobs at ARSIEM

  • Android-Savvy CNO Developer
    $130K — $145K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Information Technology
    In-Person
  • Android-Savvy CNO Developer
    $130K — $145K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Information Technology
    In-Person
  • Network-Savvy CNO Developer
    $181K — $203K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Information Technology
    In-Person
  • 361 - AI Engineer
    $126K — $141K *
    Linthicum Heights, MD 21090 (Anne Arundel County)
    Information Technology
    In-Person
  • 658 Cloud Software Engineer 3
    $185K — $210K *
    Annapolis, MD 21401 (Anne Arundel County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Host Based Systems Analyst III jobs: