Senior Cyber Defense Analyst / Incident Responder IRES - SSFB/HSV

Amentum
Huntsville, CO
Category Security
Job Description
Role Overview

The Senior Cyber Defense Analyst / Incident Responder supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The candidate will perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties, lead event/incident investigations, and analyze correlated asset, threat, and vulnerability data. The role requires experience with most MS Office applications, multi-tasking, and prioritizing projects in a dynamic work environment.

What You Will Do

The candidate will provide oversight and guidance on the MDA Cybersecurity Service Provider - Computer Emergency Response Team’s (MDA CSSP-CERT’s) Cyber Defense and Incident Response program, perform cybersecurity duties on customer networks, and support a Cyber Defense Analyst and Cyber Defense Incident Responder training plan.

Why It Might Be a Fit

The successful candidate will have experience with most MS Office applications, be able to multi-task and prioritize various projects and assignments, and be willing to travel 25% of the time. The candidate should have 6 or more years of combined experience performing the full life-cycle of incident response and enterprise-level monitoring and analysis of events, and an active DoW Top Secret with SCI Eligibility.

Requirements

  • 6 or more years of combined experience performing the full life-cycle of incident response and enterprise-level monitoring and analysis of events
  • 2 or more years of experience in management or leadership in a team environment
  • Active DoW Top Secret with SCI Eligibility
  • One of the following certifications: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP
  • Experience with security analysis and solutions in a WAN/LAN environment
  • Experience with other Security Operations Centers (SOC)/DCO tools/applications
  • Experience analyzing security compliance scans performed across a WAN (ACAS/Nessus preferred)
  • Experience analyzing network and host-based threats (ESS preferred)
  • Ability to mentor and train personnel in an evolving, high-paced environment
  • Familiarity with DoD Security Operations Centers (SOC)
  • Familiarity with DCO/Cybersecurity Service Provider (CSSP)-guiding security policies and procedures
  • Experience with advanced digital forensics, including host-based and memory analysis
  • Proficiency in scripting and data analysis with languages such as Python, PowerShell, Bash, or KQL
  • Familiarity with the intelligence cycle and its application to cybersecurity operations
  • Experience with hunt-centric security platforms, including industry-standard Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and Security Orchestration, Automation, and Response (SOAR) tools
  • Familiarity with the application of Artificial Intelligence (AI) and Large Language Models (LLMs) in cybersecurity

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
]]>