Full-Time

Senior Cyber Defense Analyst

Posted on 9/9/2026

CALNET

CALNET

No salary listed

No H1B Sponsorship

Fort Liberty, NC, USA

In Person

US Citizenship, US Top Secret Clearance Required

Bachelor's

Category
Cybersecurity (1)
Required Skills
Suricata
Zeek
Malware Analysis
Requirements
  • A bachelor's degree in an IT field is preferred.
  • U.S. citizenship and an active Secret clearance are required.
  • At least 5 years of IT infrastructure experience is required.
Responsibilities
  • Provide 24/7/365 Blue Team services for cyberspace security incident investigation and mitigation on NIPRNet and SIPRNet supported networks.
  • Perform all Blue Team functions in accordance with CJCSM 6510.01B, AR 25-2, current ARCYBER and supported Regional Cyber Center tactics, techniques, and procedures and standard operating procedures, and the current Department of Defense Cybersecurity Services Evaluator Scoring Matrix.
  • Ingest, correlate, and analyze sensor and host data from across the supported enterprise and scale staffing and tradecraft to maintain the required operational tempo.
  • Conduct continuous monitoring using the enterprise Security Information and Event Management platform, currently Elastic SIEM, and supporting big-data analytics and detection tooling.
  • Analyze and correlate anomalous events across SIEM, host-based security, endpoint detection, full packet capture, NetFlow, intrusion detection and prevention systems, proxy logs, router and firewall system logs, and boundary devices.
  • Perform exploratory and in-depth analysis of host-based audit logs, captured network traffic, malware artifacts, and incident report trends to characterize threats and identify Advanced Persistent Threat activity.
  • Develop, document, and refine a definable, repeatable triage process and support analytic scripts to enable consistent escalation across the analyst team.
  • Maintain and update SIEM correlation rules, watchlists, and detection logic, and coordinate signature submissions with ARCYBER signature working groups for global implementation where appropriate.
  • Execute critical blocks within two hours of notification or detection, or within the period determined by event criticality, to mitigate ongoing threat activity within the area of responsibility.
  • Execute immediate action steps within 24 hours to mitigate threats when the operational impact of delay would exceed acceptable risk.
  • Coordinate network configuration changes such as IP blocking, access control list modification, and signature deployment with the applicable Theater Signal Command, DoDIN-A staff, and supported Regional Cyber Center.
  • Submit internal defensive measure recommendations, including operational impact analysis and risk justification, to the appropriate Configuration Control Board or Designated Approving Authority when the contractor does not control the sensor grid.
  • Capture and perform initial analysis of volatile data, log data, and captured network traffic.
  • Maintain incident chain of custody in accordance with ARCYBER F&MA procedures and coordinate shipment of original forensic evidence to ARCYBER F&MA for imaging when required.
  • Maintain quality control of incident records to ensure CJCSM 6510.01B compliance.
  • Conduct incident trend analyses and ensure all investigation data is submitted to the designated ARCYBER incident-handling portal with the most current action visible.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A