
Principal Cyber Threat Analyst
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in United States.
• Conduct analytical triage of cyber incidents utilizing commercial and custom applications, systems, and tools.
• Analyze both host- and network-based logs.
• Correlate network indicators along with PCAP data.
• Perform forensic analysis of system images.
• Create event timelines and execute root cause analysis.
• Prepare comprehensive written analyses of events.
• Present findings to both technical and non-technical audiences.
• Conduct all-source research on cyber threat actors and intrusion sets, including Advanced Persistent Threats (APTs).
• Assess technical and intelligence reports regarding cyber threat activities.
• Contribute to informational and analytic products that enhance situational awareness and provide early warnings of current and emerging cyber threats and risks.
• Analyze incidents, threats, risks, impacts, consequences, vulnerabilities, tactics, techniques, procedures, and other indicators.
• Collaborate daily with Information & Research team members and Strategic Counterintelligence analysts to coordinate threat mitigation efforts.
• Identify and counter advanced cybersecurity threats across the Northrop Grumman Managed Network (NGMN).
• 5 years of relevant experience with a Bachelor of Science degree; OR 3 years with a Master’s degree; OR 1 year with a PhD.
• Capability to obtain and maintain a U.S. Government Top Secret level security clearance as a condition of continued employment.
• U.S. Citizenship is mandatory for positions requiring government clearance.
• Proficiency in preparing and analyzing data and figures.
• Experience with two or more analysis tools commonly utilized in a SOC/CIRT or similar investigative setting.
• Minimum of 2 years of experience performing log data analysis in support of intrusion analysis or cybersecurity operations.
• At least 4 years of experience with Python, PowerShell, or other scripting languages.
• Ability to produce detailed written analyses and briefings for technical and non-technical audiences.
• Proven awareness of current endpoint and network exploits.
• Familiarity with methodologies and tools for computer network exploitation.
• Understanding of network communication protocols across all layers of the OSI model.
• Experience handling large datasets, high-performance computing systems, and artificial intelligence (AI) tools.
• Experience with endpoint detection and response technologies.
• Familiarity with cyber threat intelligence methodologies.
• Proficiency in Linux/Unix and Windows systems, including shell scripting (Bash, PowerShell).
• Awareness of current cybersecurity threats impacting U.S. defense contractors or the U.S. Government.
• One or more preferred technical certifications or equivalent: GCED, GCIH, GCIA, GCFA, GREM, CFCE, EnCE, ACE, CCNA, CISSP, etc.
• Flexible work arrangements.
• Exceptional learning opportunities.
• Exposure to a diverse range of projects and clients.
• Supportive team environment.
• Comprehensive benefits and healthcare.
• Life and disability insurance.
• Savings plan.
• Company-paid holidays.
• Paid time off (PTO) for vacation and personal business.
• 9/80 work schedule.
• 401k matching program.
• Potential eligibility for overtime.
• Potential eligibility for shift differential.
• Potential eligibility for discretionary bonus.
• Potential eligibility for long-term incentives for Vice President or Director positions.
Beshenich Muir & Associates
TRM Labs
Instituto Hardware BR HBR
GE Vernova
Get handpicked remote jobs straight to your inbox weekly.