Lead advanced cyber defense operations by monitoring, analyzing, and responding to security events across mission critical systems and networks.
Translate threat intelligence and incident data into actionable defensive measures, ensuring the organization maintains a strong cybersecurity posture against sophisticated adversaries.
Conduct deep dive analysis of security alerts, network traffic, and system logs to identify malicious activity and potential intrusions.
Guide incident response efforts, develop analytic techniques, and refine detection content to improve visibility and response effectiveness.
May also contribute to threat hunting activities, collaborate with engineering teams to enhance defensive tooling, and support the development of playbooks, procedures, and reporting.
Mentor and coach junior analysts, providing technical guidance, reviewing analytic work, and helping develop team expertise.
Validate detections, assess security gaps, recommend improvements, and ensure all defensive activities align with DoD cybersecurity policies, operational requirements, and mission focused defensive strategies.
Requirements
Information Assurance Engineer 2: 2 years relevant experience with Bachelors in related field; 0 years experience with Masters in related field; or High School Diploma or equivalent and 6 years relevant experience.
Information Assurance Engineer 3: 5 years relevant experience with Bachelors in related field; 3 years relevant experience with Masters in related field; or High School Diploma or equivalent and 9 years relevant experience.
Information Assurance Engineer 4: 9 years relevant experience with Bachelors in related field; 7 years relevant experience with Masters in related field; or High School Diploma or equivalent and 13 years relevant experience.
Progressive hands-on experience developing and executing a continuous monitoring and analysis strategy for hosted information systems.
Experience using Splunk software or an equivalent Security Information and Event Management (SIEM) product for continuous monitoring, incident reviews, investigations, and event correlations.
Current IAT level II certification (Sec+, CYSA, etc.) or ability to obtain within 90 days of starting position.
Active TS/SCI government security clearance required to start, candidate must willing to obtain and maintain a CI poly.