A Cyber Defense Analyst supporting Department of Defense missions monitors, detects, and responds to cybersecurity threats across classified and sensitive networks from a fully remote CONUS position. Day to day, this role centers on ingesting and analyzing security event data through SIEM platforms, triaging alerts, and conducting thorough log analysis to distinguish genuine threats from noise. When incidents are confirmed, the analyst leads or supports structured incident response efforts — containing threats, documenting findings, and coordinating remediation with system owners and security leadership. Routine vulnerability assessments round out the workload, helping teams understand exposure and prioritize hardening efforts before adversaries can exploit gaps. Candidates must bring at least two years of hands-on experience with these disciplines and demonstrate proficiency with SIEM tooling, log parsing, and vulnerability scanning workflows in operational environments. An active Secret clearance is required from day one, as the work directly supports defense-sector customers handling controlled and sensitive information. This is a technical, mission-focused role suited to analysts who are methodical under pressure and comfortable working independently in a remote setting.
What you'll do
- Monitor SIEM dashboards and triage security alerts to distinguish true positives from false positives across DoD-connected environments
- Execute end-to-end incident response procedures including containment, eradication, recovery, and post-incident reporting
- Perform in-depth log analysis across network, endpoint, and application sources to reconstruct threat actor activity and attack timelines
- Conduct recurring vulnerability assessments and communicate prioritized findings and remediation recommendations to system owners
- Hunt for indicators of compromise and emerging threat patterns using threat intelligence feeds and internal telemetry
- Document incidents, analysis findings, and response actions in accordance with federal reporting requirements and SOC standard operating procedures
- Collaborate with engineering and system administration teams to validate patch status and validate security control effectiveness
Required skills
- SIEM
- incident response
- log analysis
- vulnerability assessment