Full-Time

Cybersecurity Intrusion Detection Analyst

Posted on 1/9/2026

Deadline 1/9/27
Bowhead

Bowhead

1,001-5,000 employees

Federal contracting arm delivering IT services

No salary listed

Vicksburg, MS, USA

In Person

US Citizenship, US Top Secret Clearance Required

Category
IT & Security (1)
Requirements
  • Bachelor's degree or equivalent experience
  • At least 5 years intrusion detection experience
  • At least 2 years relevant IT and/or System administrator experience and 3 years relevant Information Security experience
  • Must have the certifications for DoD 8570 Information Assurance Technical (IAT) Level II minimally
  • Must have the certifications for DoD 8570 Cyber Security Service Provider (CSSP)-Analyst or CSSP-Incident Responder
  • Must have the ability to earn DoD 8570 computing environment certification within 6 months
  • Understanding of network hardware devices and experience configuring Access Control Lists or other Firewall or Router configuration experience
  • Ability to demonstrate strong knowledge of computer security concepts
  • Ability to communicate effectively, interpret regulatory guidance and identified vulnerabilities to a wide audience
  • Advanced knowledge of network technologies and protocols
  • Advanced understanding of current threats and trends present in the Information Security and Technology field
  • Must complete the specified Joint Qualification Requirement training within 180 days of date of hire, unless otherwise specified
  • SECURITY CLEARANCE REQUIRED: Must currently hold and be able to maintain an active Secret clearance with the ability to obtain a Top Secret/SCI. US Citizenship is a requirement for Secret clearance at this location
Responsibilities
  • Provides leadership and supervision to the incident response staff and performs highly technical customer support to organization users
  • Manages the incident response and threat detection function
  • Proactively analyzes network and systems traffic, event logs, and threat intelligence data, to properly identify and triage susceptibility of core campus technical assets, determine likelihood of exploitation and implement and/or refine preventative and detective security controls
  • Participates in the development and monitoring of policies and procedures for department or department operations
  • Assesses, analyzes, and consults on the security of information assets - networks, endpoints, databases, applications, services, platforms, environments, etc. Contributes to asset inventory and categorization processes
  • Receive and distribute AS&W information
  • Conduct AS&W activities to develop appropriate response (receives and archive task orders, directives, and other required actions,
  • Maintain internal and external source location information)
  • Coordinate AS&W information from other sources to aid in analysis of alerts
  • Analyze the Intrusion Detection System alerts to identify unauthorized or anomalous activity
  • Identify, documents, and reports unauthorized activity/attacks (including IP addresses and ports, attack vector, and attack timeframe) in all incidents and reports per HPCMP CSSP sops
  • Take action, if appropriate, to prevent or mitigate potential impact to the DODIN based on cyber threats, and develop and distribute countermeasures and interim guidance to prevent or mitigate threats and/or attacks on DODIN
  • Monitor a platform capable of performing information security continuous monitoring (ISCM) for the purposes of detecting cyber intrusions, attacks, anomalous behavior, and possible insider threats
  • Collect intrusion artifacts (e.g., source code, malware, and trojans)
  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation
  • Report incidents and events within proper channels and within timelines identified in the CJCSM 6510.01B
  • Provide a 24/7x365 event/incident handling and analysis capability
  • Provide operations log accessible to personnel documenting all mandated reportable cyber events/incidents
  • Analyze detected cyber events to identify incidents
  • Categorize and characterize cyber incidents
  • Notify affected Subscribers of cyber incidents and collect assessments of mission impact for the loss of the system during the incident response process
  • Analyze cyber incidents to develop specific responses
  • Distribute tailored countermeasures or interim guidance to Subscribers to eradicate and prevent cyber incidents across all subscribers
  • Perform forensic analysis of systems and malware in cases where subscribers lack the capability and ensure relevant IOCs are shared with Warning Intelligence
  • Mitigate operational and/or technical impact due to cyber incidents
  • Contain the spread of malware to prevent further damage to IT systems through detection, analysis, and execution of containment measures

Bowhead, via UIC Government Services (UICGS), provides federal contracting and government services to defense and civilian agencies. It offers IT, logistics and marine services, engineering, program management, and development and support of military training and modeling and simulations. It coordinates a family of subsidiary companies to tailor end-to-end solutions, including operations and maintenance and lifecycle support. Its goal is to help federal agencies meet missions by delivering reliable, integrated contracting services and mission-ready programs.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Alexandria, Virginia

Founded

1999

Simplify Jobs

Simplify's Take

What believers are saying

  • GSA OASIS and 8(a) STARS III enable flexible federal IT contracting.
  • 3,000 employees support nearly 300 contracts for scalability.
  • Iñupiat values drive tailored engineering and logistics solutions.

What critics are saying

  • 8(a) certification expires upon $150M revenue in 12-24 months.
  • Delta integration fails, causing revenue loss in 6-18 months.
  • DoD concentration eliminates 60-80% revenue on contract loss.

What makes Bowhead unique

  • Bowhead leverages Alaska Native Corporation status for sole-source contracts.
  • Bowhead operates 30+ subsidiaries across six business lines like IT and manufacturing.
  • 2024 Delta acquisition adds military training and DoD space expertise.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Sick Leave

Paid Holidays

Company News

GovCon Wire
Dec 4th, 2024
UIC Acquires Delta Solutions & Strategies

Ukpeagvik Inupiat Corp. (UIC) has acquired a majority interest in Delta Solutions & Strategies, a service-disabled veteran-owned small business. Delta is now part of UIC's Bowhead Family of Companies within its government services division. The acquisition, led by UIC COO Jeevan Pokharel, aims to enhance Bowhead’s growth in the Department of Defense and space sectors. Delta will gain access to more DOD and federal contracts, expanding its market and expertise.

INACTIVE