CareerPlanSign in

Host Based Systems Analyst II

Arlington, VA💼 Full-time🗓 2026-01-06 → 2026-09-25

Core

Front-line Cyber Network Defense Analyst providing digital forensics, incident response, and proactive hunting for malicious cyber activity to protect government client networks.

Role type

Cyber Network Defense Analyst (CNDA)

Builds

Cyber defense monitoring, incident response, and threat detection capabilities for government agencies

Domain

Cybersecurity / Government Contracting

Deliverable

production ML models | product features | dashboards & analysis | client delivery

Required skills

Network traffic analysis, incident handling, signature development, packet-level analysis, IDS validation, TTP identification, network topology examination, anomaly detection, metadata analysis, attack reconstruction, OS fingerprinting detection

Preferred skills

Python programming, SiLK tool suite usage, advanced math/science background

Technologies

Snort, Arcsight, SEIM solutions, protocol analyzers, Carnegie Mellon SiLK

Responsibilities

Characterize and analyze network traffic to identify anomalous activity and potential threats; Coordinate with enterprise-wide cyber defense staff to validate network alerts; Document and escalate incidents including event history, status, and potential impact; Perform cyber defense trend analysis and reporting; Receive and analyze network alerts from various sources to determine possible causes; Provide timely detection, identification, and alerting of possible attacks/intrusions and distinguish them from benign activities; Use cyber defense tools for continual monitoring and analysis of system activity; Analyze identified malicious activity to determine weaknesses exploited and effects on systems; Determine tactics, techniques, and procedures (TTPs) for intrusion sets; Examine network topologies to understand data flows; Identify and analyze anomalies in network traffic using metadata; Validate intrusion detection system (IDS) alerts against network traffic using packet analysis tools; Identify applications and operating systems of network devices based on traffic; Reconstruct malicious attacks based on network traffic; Identify network mapping and OS fingerprinting activities; Assist in constructing signatures for cyber defense tools; Notify managers and responders of suspected incidents with event details; Prepare and update manuals, instructions, and operating procedures; Evaluate established methods and prepare recommendations for changes; Plan and carry out complex assignments and develop new methods; Conduct analyses and recommend resolution of complex issues; Evaluate the effectiveness of installed systems and services

Seniority

Mid-Senior level, hands-on IC

Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.