Jobs · Information Technology · Alabama

Senior Cyber Defense Analyst / Incident Responder IRES - SSFB/HSV

Amentum · Redstone Arsenal, AL · 3 wk ago
On-siteInformation TechnologyFull-time

Location: Schriever Space Force Base, Colorado Springs, CO or Redstone Arsenal, Huntsville, AL. Must possess an active DoD Top Secret with SCI eligibility. No relocation assistance or remote/telework available. Rotating shift in a 24/7 operational environment; up to 10% travel required.

About the role

The Senior Cyber Defense Analyst / Incident Responder supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The candidate will provide oversight and guidance on the MDA Cybersecurity Service Provider - Computer Emergency Response Team’s (MDA CSSP-CERT) Cyber Defense and Incident Response program and serve as the primary point of contact for junior and mid-level Cyber Defense Analysts.

Responsibilities

  • Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
  • Conduct proactive and reactive cybersecurity duties on customer networks to improve enterprise-wide security posture.
  • Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents in accordance with CJCSM 6510.01B.
  • Lead event/incident investigations from start to conclusion, including data gathering, analysis, and reporting while preserving and protecting incident artifacts, evidence, and chain of custody.
  • Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
  • Support a Cyber Defense Analyst and Cyber Defense Incident Responder training plan by instructing, evaluating, and mentoring junior and mid-level analysts.
  • Support the development, establishment, review, and update of DCO procedures, processes, manuals, and other documentation.
  • Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and develop SIEM content/signatures to detect known attack patterns, making recommendations for improvements.
  • Coordinate with CSSP-CERT subscribers to develop current configurations, rules, and signatures for cybersecurity-related toolsets.
  • Coordinate with CSSP-CERT subscribers to notify, investigate, and remediate discrepancies in security logging and CSSP-CERT alignment.
  • Provide standardized and targeted training in support of CSSP-CERT subscriber cyber defense and incident response programs.
  • Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document findings in accordance with CJCSM 6510.01B guidelines.
  • Provide support to internal and external Insider Threat and law enforcement/counterintelligence (LE/CI) agencies during cyber incidents/investigations.
  • Use most MS Office applications (Word, Excel, PowerPoint, and Visio) effectively.
  • Multi-task and prioritize various projects and assignments in a dynamic work environment to meet scheduled/unscheduled customer requests.

Requirements

  • 6+ years of combined experience performing the full life-cycle of incident response and enterprise-level monitoring and analysis of events.
  • 2+ years of experience in management or leadership in a team environment.
  • Active DoD Top Secret with SCI eligibility.
  • One of the following certifications: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP.

Qualifications

  • Master’s degree or higher in Cybersecurity, Computer Science, or a related field (desired).
  • Advanced cybersecurity certifications such as:
    • Offensive Security: OSCP, PNPT, GPEN
    • Forensics/Incident Response: GCFA, GCFE, GCIH, EC-Council Certified Hacking Forensic Investigator (CHFI)
    • Threat Hunting/Analysis: GIAC Certified Cyber Threat Intelligence (GCTI)
  • Experience with security analysis and solutions in a WAN/LAN environment, including routers, switches, network devices, and operating systems (e.g., Windows, Linux).
  • Experience with Security Operations Centers (SOC)/DCO tools/applications such as firewalls, IDS/IPS, Network Security Manager, forward proxy, spam firewall, etc.
  • Experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred).
  • Experience analyzing network and host-based threats (ESS preferred).
  • Ability to mentor and train personnel in an evolving, high-paced environment.
  • Familiarity with DoD Security Operations Centers (SOC) and DCO/Cybersecurity Service Provider (CSSP)-guiding security policies and procedures.
  • Demonstrable experience in offensive security operations, such as penetration testing, red teaming, or exploit development.
  • Experience with advanced digital forensics, including host-based and memory analysis.
  • Proficiency in scripting and data analysis with languages such as Python, PowerShell, Bash, or KQL to automate tasks and parse large datasets.
  • Familiarity with the intelligence cycle and its application to cybersecurity operations.
  • Experience with hunt-centric security platforms, including industry-standard EDR, SIEM, and SOAR tools.
  • Familiarity with the application of Artificial Intelligence (AI) and Large Language Models (LLMs) in cybersecurity, including leveraging AI-driven security tools and critically assessing their output.

Pay

$145,000 – $152,000 per year.

Benefits

  • Health, dental, and vision insurance.
  • Paid time off and holidays.
  • Retirement benefits (including 401(k) matching).
  • Educational reimbursement.
  • Parental leave.
  • Employee stock purchase plan.
  • Tax-saving options.
  • Disability and life insurance.
  • Pet insurance.

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Similar jobs