Network Based Systems Analyst III
Job description
About the role
The hire will own the complex analysis of network telemetry and host-based artifacts to identify indicators of compromise and potential malicious activity across government information systems. This role requires the evaluation of network traffic patterns, protocol behaviors, and log data to detect anomalies that may signify an active intrusion or compromise. The individual will correlate events across multiple data sources to build a comprehensive picture of the threat landscape facing the network environment. They will recommend and implement proactive containment measures designed to disrupt adversarial campaigns before objectives are achieved. The position demands close collaboration with cyber defense teams to ensure that detection logic and response procedures remain aligned with evolving tactics, techniques, and procedures. The hire will contribute to the development of detection signatures and analytic models that enhance the overall security posture of the enterprise. This role serves as a critical technical authority guiding incident response efforts and supporting the refinement of security monitoring processes. The individual is expected to mentor junior analysts and provide clear, concise technical communication to both technical and executive stakeholders.
Key facts
What you'll do
Analyze network traffic and host-based indicators to identify patterns of malicious behavior and potential compromise.
Evaluate system baselines and user activity to distinguish normal operational behavior from suspicious or anomalous events.
Correlate disparate data sources including logs, network flows, and endpoint telemetry to form a complete understanding of incident timelines.
Develop and refine detection rules and analytic models to improve visibility into advanced persistent threats and covert operations.
Conduct in-depth digital media analysis to determine the scope of compromise and preserve evidence for further investigation.
Recommend network segmentation and architectural changes to limit lateral movement and reduce the attack surface.
Isolate affected systems and coordinate with network engineering teams to implement containment strategies.
Consult with law enforcement and counterintelligence organizations to ensure appropriate reporting and evidence handling procedures.
Develop and deploy eradication tools and scripts to remove malicious artifacts and restore system integrity.
Track threat actor behaviors and update playbooks based on emerging techniques observed in the operational environment.
Validate the effectiveness of implemented controls through continuous monitoring and targeted testing of detection capabilities.
Maintain detailed documentation of investigations, findings, and remediation steps to support audit requirements and knowledge transfer.
Support the creation of threat intelligence reports that communicate risks and trends to technical and non-technical audiences.
Ensure all activities adhere to strict government compliance standards and data handling regulations.
Requirements
Must be a United States Citizen due to the sensitive nature of the government contract and the access to classified information.
Must possess a current Top Secret security clearance with the ability to obtain and maintain a TS/SCI clearance with polygraph.
Must have a demonstrated history of working in a government or defense contractor environment requiring the handling of classified information.
Must have extensive experience in network defense operations and the analysis of network traffic to identify threats.
Must be proficient in the use of network monitoring tools, intrusion detection systems, and log analysis platforms.
Must have strong knowledge of network protocols, routing, and switching fundamentals to understand how malicious traffic traverses the network.
Must have experience with digital forensics and incident response methodologies to effectively investigate and remediate security incidents.
Must be able to write clear technical reports and communicate findings to both technical teams and executive leadership.
Nice to have
Experience with Security Information and Event Management (SIEM) platforms such as Splunk, QRadar, or ArcSight.
Familiarity with threat hunting methodologies and frameworks such as MITRE ATT&CK.
Knowledge of common malware analysis techniques and the ability to interpret indicators of compromise.
Experience with automation and scripting using Python or PowerShell to streamline analysis and response tasks.
Understanding of cloud network architectures and the shared responsibility model for cloud security.
Practical notes
This is a full-time position based in Arlington, VA.
The role requires United States citizenship and the ability to maintain a Top Secret security clearance.
Travel may be required to support client engagements as needed.
Candidates must be able to pass a government polygraph examination as part of the hiring process.
This position is directly engaged with supporting the operational needs of a U.S. Government client.