
Senior Cyber Defense Analyst
Posted Aug 24

Posted Aug 24
This is a fully remote position, open to applicants in United States.
• Analyze network and host activities related to both successful and unsuccessful intrusions by sophisticated attackers.
• Conduct network traffic analysis utilizing raw packet data, net flow, IDS, and outputs from custom sensors.
• Assist with enterprise incident response initiatives.
• Develop and implement custom signatures to counter highly dynamic threats.
• Utilize advanced forensic tools and techniques for reconstructing attacks and gathering intelligence.
• Investigate emerging cyber threats and evaluate attacker methodologies, tactics, system vulnerabilities, and indicators of attacks and exploits.
• Contribute to threat intelligence reports and briefings, enhancing situational awareness of cyber threats affecting global network infrastructure.
• Engage in threat hunting operations by employing adversary tactics, techniques, procedures, and indicators of attack.
• Collaborate through information-sharing networks and professional relationships.
• Provide on-call incident response support outside of core hours as necessary.
• Mentor junior analysts on both technical and conceptual levels.
• Lead small teams on projects and incident response activities.
• Propel advanced countermeasures to completion.
• Train the team on defending against new threat vectors.
• Assist in the integration of hyperautomation and agentic AI into the detection, triage, and response lifecycle, including intelligent orchestration, signal correlation, and expedited investigative workflows.
• Must be a U.S. Citizen and qualified to obtain DoD Secret clearance.
• Bachelor’s Degree and 8–12 years of relevant experience in cybersecurity or network defense; or an equivalent combination of education and relevant experience along with pertinent certifications (CISSP, SANS GIAC, CEH, etc.) may be accepted in place of a degree.
• Experience in conventional network or host-based intrusion analysis, digital forensics, or malware analysis.
• Proven experience conducting “deep dive” analysis and correlation of log data from various sources including PCAP and forensic artifacts.
• Experience in leading and participating in incident response efforts.
• Strong grasp of Operating Systems and Network Protocols.
• Proficient with Microsoft Windows administrative tools and the Unix/Linux command line interface.
• Preferred: familiarity with behavioral-based threat models, such as ATT&CK, Cyber Kill Chain, Diamond Model, etc.
• Preferred experience with Splunk or similar SIEM platforms.
• Knowledge of Perl and Python.
• Previous roles as a Threat Researcher and/or Intelligence Analyst.
• Experience with dynamic malware analysis and reverse engineering.
• Background in cryptography or cryptanalysis.
• Experience in cybersecurity engineering.
• Experience defending extensive cloud infrastructures (AWS, Azure, etc.).
• Ability to create, modify, and implement Snort and YARA signatures.
• Published research papers at conferences or through other channels.
• Working knowledge of CNE, CNA, and CND tools and techniques.
• In-depth understanding of advanced cyber threats targeting enterprises and their associated tools, tactics, and procedures.
• Experience applying threat and data modeling, advanced data correlation, and statistical analysis to generate alerts, notable events, investigative dashboards, and metrics-driven reports.
• Comprehensive health and wellness programs.
• Opportunities for professional development and certifications.
• Flexible work arrangements.
• Competitive salary and performance-based bonuses.
XTB online investing
Clinton Health Access Initiative, Inc.
VALCE Talent Solutions
Get handpicked remote jobs straight to your inbox weekly.