Threat Detection & Response Analyst

4 hours, 58 minutes ago
Contract
Senior
Cybersecurity
Skyepoint Decisions

Skyepoint Decisions

Skyepoint Decisions specializes in providing comprehensive IT solutions for the federal government, focusing on cybersecurity architecture, critical infrastructure operations, and applications development and maintenance to support a secure and mobile ...

Internet Software & Services
51-250
Founded 2009

Description

  • Conduct proactive threat hunting using intelligence-driven and hypothesis-based methods.
  • Analyze threat actor tactics, techniques, and procedures to identify potential compromise.
  • Map adversary behaviors and indicators to the MITRE ATT&CK framework.
  • Monitor security tools, dashboards, and alerts for suspicious activity and threats.
  • Analyze endpoint, network, cloud, and security monitoring data.
  • Triage security alerts to determine validity, severity, and impact.
  • Investigate cybersecurity incidents, security events, and anomalous activity.
  • Perform forensic review of logs, alerts, and system data to determine root cause and scope.
  • Correlate information from multiple security tools and data sources.
  • Document findings, recommendations, and lessons learned, and support post-incident reviews and corrective actions.
  • Support RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
  • Assist with audit readiness and security assessment activities as needed.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or SOC environments.
  • Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
  • Experience investigating cybersecurity incidents and analyzing security events.
  • Knowledge of cyber threat TTPs, SOC processes, incident response methodologies, network security concepts, and endpoint security technologies.
  • Familiarity with NIST RMF (SP 800-37), NIST SP 800-53 Rev. 5, FISMA, and federal cybersecurity requirements.
  • Strong analytical, troubleshooting, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.
  • Preferred certifications include Security+, CySA+, GCIH, GCIA, CISSP, CEH, GSEC, CASP+, or CISM.
  • Experience supporting HHS or other federal civilian agencies.
  • Experience working in a SOC environment.
  • Knowledge of MITRE ATT&CK Framework methodologies.
  • Experience supporting cloud security operations in Azure, AWS, or Google Cloud.
  • Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
  • Experience protecting healthcare, biomedical, or research-focused environments.

Benefits

  • Salary range of $95,000 to $110,000.
  • Certification incentive program.
  • PTO.
  • Floating federal holiday options.
  • Health insurance options including HMO and High Deductible plans with HSAs.
  • Flexible Spending Accounts (FSAs).
  • Dental, vision, short-term disability, long-term disability, and life insurance.
  • 401(k) match.
  • Flexible work environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Threat Investigator

Discord 1K-5K Internet Software & Services

Discord is hiring a Threat Investigator on its Violent Actors Team to lead investigations into violent and extremist networks and strengthen detection and enforcement within Trust & Safety.

Machine Learning
4 hours, 58 minutes ago

Asset Protection Officer

RIDE 51-250 Automotive

Asset Protection Officer at RIDE Coach and Bus responsible for protecting company premises, staff, and visitors through surveillance, access control, and incident response.

5 hours, 12 minutes ago

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

5 hours, 57 minutes ago

Client Due Dilligence Analyst (DDQ)

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a DDQ Analyst to support its global sales process by managing client due diligence questionnaires and related compliance workflows for an enterprise SaaS platform.

Cybersecurity
1 day, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers