Cyber Defense Analyst II
Core
Monitor, investigate, and respond to security events across classified enclaves, mission ground systems, and labs for Blue National Security.
Role type
Cyber Defense Analyst (SOC/Incident Response)
Builds
Security monitoring and incident response capabilities for national security systems
Domain
National Security / Cyber Defense
Deliverable
client delivery
Required skills
Security operations, incident response, SIEM, EDR, network protocols, Windows/Linux fundamentals, MITRE ATT&CK, technical writing
Preferred skills
Military cyber experience, scripting (Python/PowerShell/Bash), query languages (KQL/SPL), forensics, malware triage
Technologies
SIEM, EDR, network sensors, audit logs
Responsibilities
Monitor and triage security events and alerts, investigate incidents by pivoting across host/network/identity data, serve as first responder during incidents, participate in structured threat hunts, support audit and insider threat reviews, stand watch during mission events, assist with sensor deployment and log source onboarding, tune detection rules, improve response playbooks, automate recurring tasks
Seniority
Mid-level, hands-on IC