Computer Network Defense Analyst
$90,000–$130,000 year
On-siteColumbus, Ohio, United States
Job Summary
Monitor, analyze, investigate, and respond to cybersecurity events, alerts, and incidents affecting enterprise networks, systems, applications, and data. Perform proactive threat hunting and cybersecurity analysis utilizing SIEM platforms, IDS/IPS, system logs, packet captures, and forensic tools to identify malicious activity. Conduct incident triage, root cause analysis, containment, eradication, recovery, and post-incident reporting while ensuring compliance with established Standard Operating Procedures. Develop, tune, and maintain cybersecurity detection capabilities, including SIEM correlation rules, IDS/IPS signatures, and other defensive security countermeasures. Prepare incident reports, After Action Reports, lessons learned documentation, and operational metrics. Coordinate cybersecurity incident reporting, escalation, and notifications with government stakeholders. Support cybersecurity readiness through tabletop exercises, continuous process improvement, and cybersecurity awareness training.
Required Qualifications
- Top Secret security clearance with SCI eligibility
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical discipline
- Five (5) or more years supporting Cyber Network Defense (CND), SOC, Incident Response, or Defensive Cyber Operations
- Two (2) or more years of performing incident investigation, root cause analysis, and network or system log analysis
- Experience utilizing SIEM platforms, IDS/IPS technologies, packet analysis, threat intelligence, and cybersecurity monitoring tools
- Strong understanding of Incident Response methodologies, malware analysis, threat hunting, digital forensics, and enterprise cyber defense principles
- Strong written and verbal communication skills
Desired Qualifications
- Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD organizations
- Experience supporting Cyber Security Service Provider (CSSP), Security Operations Center (SOC), or Computer Emergency Response Team (CERT) operations
- Knowledge of MITRE ATT&CK, NIST SP 800-61, NIST SP 800-53, DISA STIGs, and DoD cybersecurity policies
- Experience developing SIEM correlation rules, IDS/IPS signatures, or enterprise detection capabilities
- Experience with PowerShell, Python, Bash, Perl, or similar scripting
- Experience participating in cybersecurity exercises and developing After Action Reports (AARs)
- Professional certifications such as Security+, CySA+, CEH, GCIH, GCFA, CISSP, or equivalent
- Security Operations Center (SOC) operations
- Computer Network Defense (CND)
- Incident Response
- Threat Hunting
- SIEM administration and monitoring
- IDS/IPS analysis
- Malware Analysis
- Digital Forensics
- Packet Analysis
- Threat Intelligence
- PowerShell, Python, Bash
- Technical documentation and reporting
- NIST and DoD cybersecurity standards
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.