Host Based Systems Analyst II
Job description
About the role
The Cyber Network Defense Analyst position, advertised by ARSIEM Corporation, is a frontline role dedicated to digital forensics and incident response (DFIR) within U.S. government environments. Based in Arlington, Virginia, this full-time position is compensated at $132,774.00 per year and represents a career path within long-term programs that emphasize continuity, mentorship, and client trust. The role is centered on host-based analysis, where the analyst owns the complete lifecycle of digital evidence, from initial detection through final closure. Success in this position requires the ability to design repeatable, compliant processes that convert complex log data into clear, chronological narratives suitable for formal stakeholder briefings. The analyst's judgment directly influences client outcomes and shapes the team's methodology for artifact collection and analysis.
What you'll do
- Triage and guide incoming tickets by rapidly assessing reports to identify which host systems represent genuine security risks.
- Build and maintain repeatable procedures that convert unstructured log data into defensible timelines that meet strict government standards.
- Conduct proactive hunting of malicious cyber activity within government network environments to detect advanced threats and indicators of compromise.
- Shape artifact collection methodology in alignment with internal policies and specific client requirements to ensure defensibility and compliance.
- Perform quality assurance on team output to verify clarity, accuracy, and direct support of underlying data before delivery.
- Guard the chain of custody to ensure digital evidence remains uncompromised from the point of capture through storage, analysis, and final reporting.
- Package findings with sufficient context and detail to be actionable for both technical and non-technical audiences during formal briefings and presentations.
- Partner directly with client contacts to confirm that analysis addresses the specific questions, concerns, and objectives raised during investigations.
- Adjust monitoring detection logic and rules based on emerging patterns observed in network traffic and host behavior to improve detection fidelity.
- Convert complex technical findings into clear, precise reports that remain understandable to readers without technical backgrounds without sacrificing accuracy or completeness.
- Stay current with evolving adversary tactics, techniques, and procedures (TTPs) to ensure investigations remain efficient, effective, and aligned with current threat landscapes.
- Collaborate closely with monitoring tools and telemetry sources to refine the organization's security posture based on observed network activity and host-level anomalies.
- Follow up on earlier findings within long-term programs to refine conclusions, validate remediation effectiveness, and ensure continuity of client outcomes over time.
- Translate messy, unstructured log data into structured, repeatable processes that support defensible conclusions and informed stakeholder decision-making.
Requirements
- Possess a minimum of three to five years of focused experience conducting host-based analysis within government or regulated environments.
- Hold a current Top Secret security clearance with eligibility for reinvestigation to meet the stringent standards required for this level of government work.
- Demonstrate the ability to examine digital images and system logs to identify indicators of compromise, correlate events, and reconstruct attack timelines.
- Link small data clues together to identify larger attack campaigns, objectives, and attacker intent during complex investigations.
- Translate complex technical findings into clear, precise reports that maintain accuracy while being accessible to non-technical readers, including officials and decision-makers.
- Maintain strict adherence to evidence integrity standards throughout the entire analysis lifecycle, ensuring chain-of-custody documentation is complete and verifiable.
- Follow government compliance requirements and client-specific standards when designing and executing analysis processes, reports, and recommendations.
- Show commitment to professional development by staying engaged with training, industry publications, and evolving cyber threats to keep investigative methodologies current and effective.
- Exhibit strong judgment and ownership in shaping team processes, ensuring that methodologies satisfy both client expectations and regulatory mandates.
- Communicate effectively in written and verbal formats, providing concise and structured updates that convey technical details to diverse audiences.
Application Details
Interested candidates are invited to apply through the official portal with a current resume, proof of eligibility for a Top Secret clearance, and examples of prior host-based analysis or DFIR work within government contexts. ARSIEM Corporation is an equal opportunity employer.