it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

110 jobs found

Email me jobs like this
Refine Search
Current Search
cybersecurity analyst
Information Security Analyst
MassMutual Springfield, Massachusetts
The Opportunity As a Mastery Level Security Operations Center (SOC) analyst you'll have an opportunity to be part of a growing team of highly technical Cybersecurity analysts who are passionate about protecting MassMutual's assets and customers by leveraging Agentic capabilities, problem solving skills and innovative technology solutions. In this role, as well as all roles within MassMutual, you will demonstrate accountability, agility, a dedication to be inclusive, a strong business acumen, and will show courage, even in the most difficult situations. We also highly value strong communication skills, a passion for learning, leadership traits, resilience, and self-awareness. The Team As a member of the SOC team, you will work in close collaboration with fellow security analysts, engineers, and other IT security specialists throughout the firm including the Security Operations Center, Threat Intelligence, Offensive Security, Security Platforms Support, Network Security, Endpoint Security and IAM teams The Impact: Perform advanced Malware analysis and extract Indicators of Compromise (IOCs) to feed our Threat Intelligence Platform Develop and deploy SOAR automations accelerating internal SOC processes. Work closely with our Data Science Team to build Agentic capabilities Work collaboratively with our Security Intelligence team to enrich and enhance prevention, detection, and threat hunting capabilities Optimize alerting platforms through rule development and tuning of existing alerting logic Act as team lead, mentor Junior Analysts, be a go to escalation point for other SOC analysts Perform QA responsibilities ensuring thorough analysis and documentation The Minimum Qualifications 8 + years' experience working in a Security Operation Center or similar cyber security technical role. 1 + year's experience working with Artificial Intelligence models to enhance SOC capabilities. 2 + years experience writing in Python. 2 + years experience working with SOAR platforms Able to support off hours escalations The Ideal Qualifications Bachelor's degree in cyber security Certifications: CISSP, CISM, CISA, GCIH, GCFR Relevant Cyber Security GIAC Certification such as CISM, CEH, GCIH, GCDA or similar Knowledge of and practical experience with the MITRE ATT&CK framework Mastery of Python, PowerShell or other scripting languages Experience working with a SIEM platform mining large datasets Understanding of web application vulnerabilities including XSS, CSRF, SQL Injection, command injection and serialization attacks Interest in continuous learning and a passion for Cybersecurity Experience and confidence communicating with and presenting to senior leadership Strong analytical and problem-solving skills Advanced technical expertise developing security automations In depth knowledge of operating systems process relationships and file structures (Windows, Mac, Linux). Functional experience developing new detections for alerting platforms Expert level knowledge of Cybersecurity attack and defense techniques Strong understanding of web authentication flows such as SAML and OAUTH In depth knowledge of cloud environments such as AWS and Azure. Deep understanding of TCP/IP, DNS, HTTP/S, and packet-level analysis. Understanding of living off the land techniques used by adversaries, using tools such as PowerShell, WMIC, Task Scheduler, Windows Registry etc. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
09/07/2026
Full time
The Opportunity As a Mastery Level Security Operations Center (SOC) analyst you'll have an opportunity to be part of a growing team of highly technical Cybersecurity analysts who are passionate about protecting MassMutual's assets and customers by leveraging Agentic capabilities, problem solving skills and innovative technology solutions. In this role, as well as all roles within MassMutual, you will demonstrate accountability, agility, a dedication to be inclusive, a strong business acumen, and will show courage, even in the most difficult situations. We also highly value strong communication skills, a passion for learning, leadership traits, resilience, and self-awareness. The Team As a member of the SOC team, you will work in close collaboration with fellow security analysts, engineers, and other IT security specialists throughout the firm including the Security Operations Center, Threat Intelligence, Offensive Security, Security Platforms Support, Network Security, Endpoint Security and IAM teams The Impact: Perform advanced Malware analysis and extract Indicators of Compromise (IOCs) to feed our Threat Intelligence Platform Develop and deploy SOAR automations accelerating internal SOC processes. Work closely with our Data Science Team to build Agentic capabilities Work collaboratively with our Security Intelligence team to enrich and enhance prevention, detection, and threat hunting capabilities Optimize alerting platforms through rule development and tuning of existing alerting logic Act as team lead, mentor Junior Analysts, be a go to escalation point for other SOC analysts Perform QA responsibilities ensuring thorough analysis and documentation The Minimum Qualifications 8 + years' experience working in a Security Operation Center or similar cyber security technical role. 1 + year's experience working with Artificial Intelligence models to enhance SOC capabilities. 2 + years experience writing in Python. 2 + years experience working with SOAR platforms Able to support off hours escalations The Ideal Qualifications Bachelor's degree in cyber security Certifications: CISSP, CISM, CISA, GCIH, GCFR Relevant Cyber Security GIAC Certification such as CISM, CEH, GCIH, GCDA or similar Knowledge of and practical experience with the MITRE ATT&CK framework Mastery of Python, PowerShell or other scripting languages Experience working with a SIEM platform mining large datasets Understanding of web application vulnerabilities including XSS, CSRF, SQL Injection, command injection and serialization attacks Interest in continuous learning and a passion for Cybersecurity Experience and confidence communicating with and presenting to senior leadership Strong analytical and problem-solving skills Advanced technical expertise developing security automations In depth knowledge of operating systems process relationships and file structures (Windows, Mac, Linux). Functional experience developing new detections for alerting platforms Expert level knowledge of Cybersecurity attack and defense techniques Strong understanding of web authentication flows such as SAML and OAUTH In depth knowledge of cloud environments such as AWS and Azure. Deep understanding of TCP/IP, DNS, HTTP/S, and packet-level analysis. Understanding of living off the land techniques used by adversaries, using tools such as PowerShell, WMIC, Task Scheduler, Windows Registry etc. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
Chinese Cryptologic Language Analyst (CLA) Training Developer
Darkstar Intelligence LLC Goodfellow Afb, Texas
Job Description Job Description Description: DarkStar Intelligence is seeking a Chinese Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic Chinese language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Chinese reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Chinese reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range $75,000 - $85,000 annually The listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
09/07/2026
Full time
Job Description Job Description Description: DarkStar Intelligence is seeking a Chinese Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic Chinese language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Chinese reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Chinese reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range $75,000 - $85,000 annually The listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
Program Analyst with Active Secret Clearance
BTI Shaw A F B, South Carolina
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Program Analyst provides analytical and program management support for USARCENT logistics operations. This position collects and analyzes logistics and program data, monitors requirements and performance, prepares reports and briefings, and supports the planning and execution of logistics programs and initiatives. The Program Analyst works with government personnel and other stakeholders to identify trends, risks, and operational issues and provides recommendations that support mission readiness, program efficiency, and informed decision-making. Key Responsibilities Provide program analysis and management support for USARCENT logistics operations, programs, and initiatives. Collect, validate, organize, and analyze logistics, operational, and program performance data. Track program requirements, milestones, deliverables, schedules, performance measures, and action items. Develop reports, presentations, briefings, dashboards, and other analytical products for government leadership. Identify logistics trends, performance gaps, risks, and emerging issues that may affect program execution. Provide findings and recommendations to improve logistics processes, operational efficiency, and program performance. Support the development, coordination, implementation, and evaluation of logistics plans and initiatives. Monitor program activities to ensure requirements and objectives are completed accurately and on schedule. Coordinate with government stakeholders, logistics personnel, functional teams, and other organizations to obtain information and resolve program-related issues. Maintain accurate program documentation, records, data files, and status reports. Support meetings, working groups, planning sessions, and program reviews by preparing materials, recording action items, and monitoring follow-up activities. Assist with developing and improving standard operating procedures, workflows, and performance-tracking processes. Ensure all work complies with applicable USARCENT policies, security requirements, and administrative procedures. Perform additional program analysis and logistics support duties as assigned. Required Qualifications Bachelor's degree in Business Administration, Logistics, Supply Chain Management, Management, or a related field. Minimum of five years of relevant professional experience. Demonstrated experience in program analysis and logistics operations or program support. Experience collecting, analyzing, and presenting program or logistics data. Ability to develop clear reports, briefings, presentations, and recommendations for leadership. Strong analytical, organizational, communication, and problem-solving skills. Ability to manage multiple requirements, deadlines, and priorities in a mission-focused environment. Proficiency with Microsoft Office applications, including Excel, PowerPoint, Word, and Outlook. Ability to work effectively with government personnel and cross-functional teams. Must possess and maintain an active Secret security clearance. Preferred Qualifications Lean Six Sigma certification. Project Management Professional (PMP) certification. Previous experience supporting the U.S. Army, Department of Defense, USARCENT, or another federal government organization. Experience supporting logistics planning, performance measurement, process improvement, or supply chain initiatives. Powered by JazzHR kWFIzPQ2zP
09/07/2026
Full time
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Program Analyst provides analytical and program management support for USARCENT logistics operations. This position collects and analyzes logistics and program data, monitors requirements and performance, prepares reports and briefings, and supports the planning and execution of logistics programs and initiatives. The Program Analyst works with government personnel and other stakeholders to identify trends, risks, and operational issues and provides recommendations that support mission readiness, program efficiency, and informed decision-making. Key Responsibilities Provide program analysis and management support for USARCENT logistics operations, programs, and initiatives. Collect, validate, organize, and analyze logistics, operational, and program performance data. Track program requirements, milestones, deliverables, schedules, performance measures, and action items. Develop reports, presentations, briefings, dashboards, and other analytical products for government leadership. Identify logistics trends, performance gaps, risks, and emerging issues that may affect program execution. Provide findings and recommendations to improve logistics processes, operational efficiency, and program performance. Support the development, coordination, implementation, and evaluation of logistics plans and initiatives. Monitor program activities to ensure requirements and objectives are completed accurately and on schedule. Coordinate with government stakeholders, logistics personnel, functional teams, and other organizations to obtain information and resolve program-related issues. Maintain accurate program documentation, records, data files, and status reports. Support meetings, working groups, planning sessions, and program reviews by preparing materials, recording action items, and monitoring follow-up activities. Assist with developing and improving standard operating procedures, workflows, and performance-tracking processes. Ensure all work complies with applicable USARCENT policies, security requirements, and administrative procedures. Perform additional program analysis and logistics support duties as assigned. Required Qualifications Bachelor's degree in Business Administration, Logistics, Supply Chain Management, Management, or a related field. Minimum of five years of relevant professional experience. Demonstrated experience in program analysis and logistics operations or program support. Experience collecting, analyzing, and presenting program or logistics data. Ability to develop clear reports, briefings, presentations, and recommendations for leadership. Strong analytical, organizational, communication, and problem-solving skills. Ability to manage multiple requirements, deadlines, and priorities in a mission-focused environment. Proficiency with Microsoft Office applications, including Excel, PowerPoint, Word, and Outlook. Ability to work effectively with government personnel and cross-functional teams. Must possess and maintain an active Secret security clearance. Preferred Qualifications Lean Six Sigma certification. Project Management Professional (PMP) certification. Previous experience supporting the U.S. Army, Department of Defense, USARCENT, or another federal government organization. Experience supporting logistics planning, performance measurement, process improvement, or supply chain initiatives. Powered by JazzHR kWFIzPQ2zP
Arabic Cryptologic Language Analyst (CLA) Training Developer
Darkstar Intelligence LLC Goodfellow Afb, Texas
Job Description Job Description Description: DarkStar Intelligence is seeking an Arabic Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Arabic reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Arabic reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range $75,000 - $78,000 annually the listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
09/07/2026
Full time
Job Description Job Description Description: DarkStar Intelligence is seeking an Arabic Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Arabic reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Arabic reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range $75,000 - $78,000 annually the listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
Korean Cryptologic Language Analyst Training Developer
Darkstar Intelligence LLC Goodfellow Afb, Texas
Job Description Job Description Description: DarkStar Intelligence is seeking a Korean Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic Korean language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Korean reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Korean reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range: $75,000 - $78,000 annually the listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
09/07/2026
Full time
Job Description Job Description Description: DarkStar Intelligence is seeking a Korean Cryptologic Language Analyst (CLA) Training Developer to design, develop, and deliver cryptologic training programs aligned with NSA/CSS and DoD standards. This role focuses on preparing future SIGINT language analysts through hands-on, scenario-based, and blended learning techniques. In this role, you will ensure training materials accurately reflect operational duties and enable mission success. U.S. citizenship is required. Responsibilities Clarify and document operational requirements, training objectives, and material scope. Prioritize requirements for training development in collaboration with stakeholders. Conduct research using classified and unclassified resources to source authentic Korean language content. Develop training materials covering transcription, translation, and analysis of operational exercises. Collaborate with instructors, government personnel, and contractor teams to produce domain-specific training content. Utilize tools such as Audacity, Adobe Creative Suite, and Adobe Premier to create blended learning experiences. Design and implement practical evaluations to measure student mastery of objectives. Recommend tools and applications to enhance training effectiveness. Requirements: Active TS/SCI security clearance with Full-Scope Polygraph eligibility (CI Poly or CCA accepted while awaiting FS adjudication). Bachelor's degree in Language, Area Studies, Education, Instructional Systems Design (ISD), Intelligence, or related field; OR four (4) additional years of relevant practical experience in lieu of degree (for a total of nine years of experience). One year of ISD experience within the last four years, including synchronous/asynchronous methods and adult instruction using web-based tools (e.g., Centra, Blackboard, Questionmark, SumTotal). Native-level proficiency and minimum ILR level 4 in Korean reading, listening, and speaking, with ILR level 2 in English; OR native English proficiency with ILR level 2+ in Korean reading and listening (proficiency documented within the last five years). Five years of experience as a language analyst, including three years in SIGINT/IC roles, and at least one year of experience developing or updating training materials in line with ISD principles. Desired Qualifications Advanced proficiency with training technologies and eLearning platforms. Experience with blended learning and immersive training design for linguists. Prior NSA, DoD, or Intelligence Community training development experience. Demonstrated expertise in SIGINT operations and mission readiness training. Salary Range: $75,000 - $78,000 annually the listed pay range is intended as a general guideline and does not represent a guaranteed salary. Final compensation will be determined based on the role's responsibilities, the candidate's education, experience, and skill set, internal equity, market data, and applicable laws or agreements. DarkStar Intelligence provides a competitive and comprehensive benefits package designed to support the well-being and long-term success of our full-time employees. Who We Are DarkStar Intelligence delivers mission-critical support to national security operations across intelligence, cybersecurity, technology, and operational support domains. We partner with government customers to strengthen decision advantage, enhance operational readiness, and advance mission success in complex and evolving threat environments. Why Work at DarkStar? At DarkStar Intelligence, you'll contribute directly to high-impact national security missions while growing your professional capabilities in a collaborative, performance-driven environment. We offer competitive compensation, comprehensive benefits, and opportunities for continuous development within a mission-focused team culture. ADA Accommodations Statement DarkStar Intelligence is committed to providing reasonable accommodations to qualified individuals with disabilities in accordance with applicable laws. Equal Employment Opportunity Statement DarkStar Intelligence is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected status under applicable federal, state, or local law. E-Verify Participation DarkStar Intelligence participates in the federal E-Verify program to confirm employment eligibility of all newly hired employees in accordance with applicable law. Benefits Overview DarkStar Intelligence offers a comprehensive benefits package, which may include: Medical, dental, and vision coverage Paid time off (PTO) and holidays 401(k) retirement plan options Professional development and training opportunities
Sr. Cybersecurity Analyst
Summa Katy, Texas
Job Description Job Description Title: Sr. Cyber Security Analyst Location: Katy, TX- 100% onsite Duration: Direct Hire Work Requirements: US Citizen, GC Holders, or Authorized to Work in the US. Summary We are seeking a Senior Cyber Security Analyst to support and strengthen enterprise-wide security initiatives. This individual will be responsible for vulnerability management, threat analysis, cloud security, and incident response while working cross-functionally with IT and business teams. This role is ideal for someone who is hands-on, analytical, and comfortable working across infrastructure, applications, and cloud environments while helping mature the organization's overall security posture. Responsibilities Support enterprise-wide vulnerability management and remediation efforts Perform advanced threat analysis and risk modeling Implement and manage enterprise security controls Support cloud security initiatives across public cloud environments Perform application security reviews for web and mobile applications Participate in CSIRT incident response and investigations Serve as security SME for IT and business initiatives Collaborate with IT security and compliance teams Analyze security logs and tools to detect and mitigate threats Support endpoint protection and threat management initiatives Complete vulnerability remediation and security-related IT tickets Present security solutions and recommendations to leadership Qualifications Required 7+ years of Information Security experience in enterprise environments Experience with vulnerability management and threat analysis Strong knowledge of endpoint security and incident response Experience with security assessments and risk analysis Knowledge of networking, databases, virtualization, and server hardware Experience with IAM, SSO, MFA, and identity solutions Experience working with multiple operating systems (Windows, Linux, Mac, iSeries) Experience working cross-functionally with IT and leadership Preferred Security certifications such as: CISSP CEH CCNA CompTIA Security+/Cloud+ AWS / Cloud Certifications Experience with offshore teams Cloud security experience (IaaS, PaaS, SaaS) Equal Employment Opportunity Statement Summa Staffing Technologies and our client are equal opportunity employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic under applicable law.
09/07/2026
Full time
Job Description Job Description Title: Sr. Cyber Security Analyst Location: Katy, TX- 100% onsite Duration: Direct Hire Work Requirements: US Citizen, GC Holders, or Authorized to Work in the US. Summary We are seeking a Senior Cyber Security Analyst to support and strengthen enterprise-wide security initiatives. This individual will be responsible for vulnerability management, threat analysis, cloud security, and incident response while working cross-functionally with IT and business teams. This role is ideal for someone who is hands-on, analytical, and comfortable working across infrastructure, applications, and cloud environments while helping mature the organization's overall security posture. Responsibilities Support enterprise-wide vulnerability management and remediation efforts Perform advanced threat analysis and risk modeling Implement and manage enterprise security controls Support cloud security initiatives across public cloud environments Perform application security reviews for web and mobile applications Participate in CSIRT incident response and investigations Serve as security SME for IT and business initiatives Collaborate with IT security and compliance teams Analyze security logs and tools to detect and mitigate threats Support endpoint protection and threat management initiatives Complete vulnerability remediation and security-related IT tickets Present security solutions and recommendations to leadership Qualifications Required 7+ years of Information Security experience in enterprise environments Experience with vulnerability management and threat analysis Strong knowledge of endpoint security and incident response Experience with security assessments and risk analysis Knowledge of networking, databases, virtualization, and server hardware Experience with IAM, SSO, MFA, and identity solutions Experience working with multiple operating systems (Windows, Linux, Mac, iSeries) Experience working cross-functionally with IT and leadership Preferred Security certifications such as: CISSP CEH CCNA CompTIA Security+/Cloud+ AWS / Cloud Certifications Experience with offshore teams Cloud security experience (IaaS, PaaS, SaaS) Equal Employment Opportunity Statement Summa Staffing Technologies and our client are equal opportunity employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic under applicable law.
Cybersecurity Analyst
Empire State Albany, New York
Job Description Job Description Applicants MUST submit a cover letter with resume to be considered. This position will require in-office presence. Hybrid work schedules may be possible based on specific job duties and consistent with ESD policy. Minorities, women, and individuals with disabilities are encouraged to apply . Please contact Human Resources if you require an accommodation. BASIC FUNCTION: Liaise with ESD's Security and Network teams to monitor critical information security infrastructure in support of ESD's business requirements. Applicants must possess a proficient knowledge of current Information and Cybersecurity Standards as well as network infrastructure technologies and be able to work both independently and in a team environment. WORK PERFORMED: Assist with monitoring, deployment, administration, and troubleshooting network security solutions Assist with performing vulnerability and penetration tests on endpoints and information systems and mitigate identified risk Monitor network traffic and security solutions for suspicious behavior and troubleshoot / escalate issues as needed Assist ESD's Cyber Incident Response Team (CIRT) to Perform Forensic analysis on suspicious network behavior and potentially compromised systems Assist with monitoring ESD's SIEM solutions Assist with managing ESD's Data Encryption Services solution Manage ESD's patch management solution and apply application, endpoint, server and security appliance critical updates and patches Work with ESD's Security team to support and administrate ESD's Next Gen anti-virus solutions Assist with managing ESD's Secure File Transfer Solution and Treasury secure bank file transmissions Assist with managing ESD's MFA and SSO solutions Assist with all critical system security requests to include granting or restricting access to ESD's critical business systems Create and maintain documentation, flowcharts, diagrams and Standard Operating Procedures (SOP's) for ESD's Security Infrastructure Assist with daily monitoring of critical security infrastructure Active member of ESD's Cybersecurity Incident Response Team Collaborate on Cybersecurity Policies and Procedures Assist ESD's Help Desk with incident management as directed Assist with IT Disaster Recovery efforts, testing and documentation Perform other related duties and / or projects as directed by IT Management MINIMUM REQUIREMENTS: Education Level required: bachelor's degree in an IT related discipline with minimum of 3 years' experience in related field; Or a 2-year degree with a minimum of 5 years' experience; Or any equivalent combination of experience and/or education from which comparable knowledge, skills and abilities have been achieved. Security certifications (currently held or in progress.)
09/07/2026
Full time
Job Description Job Description Applicants MUST submit a cover letter with resume to be considered. This position will require in-office presence. Hybrid work schedules may be possible based on specific job duties and consistent with ESD policy. Minorities, women, and individuals with disabilities are encouraged to apply . Please contact Human Resources if you require an accommodation. BASIC FUNCTION: Liaise with ESD's Security and Network teams to monitor critical information security infrastructure in support of ESD's business requirements. Applicants must possess a proficient knowledge of current Information and Cybersecurity Standards as well as network infrastructure technologies and be able to work both independently and in a team environment. WORK PERFORMED: Assist with monitoring, deployment, administration, and troubleshooting network security solutions Assist with performing vulnerability and penetration tests on endpoints and information systems and mitigate identified risk Monitor network traffic and security solutions for suspicious behavior and troubleshoot / escalate issues as needed Assist ESD's Cyber Incident Response Team (CIRT) to Perform Forensic analysis on suspicious network behavior and potentially compromised systems Assist with monitoring ESD's SIEM solutions Assist with managing ESD's Data Encryption Services solution Manage ESD's patch management solution and apply application, endpoint, server and security appliance critical updates and patches Work with ESD's Security team to support and administrate ESD's Next Gen anti-virus solutions Assist with managing ESD's Secure File Transfer Solution and Treasury secure bank file transmissions Assist with managing ESD's MFA and SSO solutions Assist with all critical system security requests to include granting or restricting access to ESD's critical business systems Create and maintain documentation, flowcharts, diagrams and Standard Operating Procedures (SOP's) for ESD's Security Infrastructure Assist with daily monitoring of critical security infrastructure Active member of ESD's Cybersecurity Incident Response Team Collaborate on Cybersecurity Policies and Procedures Assist ESD's Help Desk with incident management as directed Assist with IT Disaster Recovery efforts, testing and documentation Perform other related duties and / or projects as directed by IT Management MINIMUM REQUIREMENTS: Education Level required: bachelor's degree in an IT related discipline with minimum of 3 years' experience in related field; Or a 2-year degree with a minimum of 5 years' experience; Or any equivalent combination of experience and/or education from which comparable knowledge, skills and abilities have been achieved. Security certifications (currently held or in progress.)
Senior Cyber Security Analyst - Governance (Disaster Recovery, Business Impact)
Vytwo Prosper, Texas
Job Description Job Description Role: Senior Cyber Security Analyst - Governance (Disaster Recovery, Business Impact) Location: Minneapolis, MN - Hybrid Rate: Depends on Experience Job Description The Senior Cyber Security Analyst - Governance (Disaster Recovery) is responsible for governing and overseeing the organization's disaster recovery (DR) program to ensure the resilience and recoverability of critical IT systems. This role provides independent governance oversight across Business Impact Analyses (BIAs), disaster recovery planning, testing, risk management, and continuous improvement activities. The position partners with application owners, technology teams, and risk and audit stakeholders to ensure disaster recovery requirements are consistently implemented, tested, and maintained in alignment with enterprise standards and industry frameworks such as ISO 22301 and NIST SP 800-34. The role also serves as a trusted advisor to application owners, supporting the development and ongoing maintenance of application-level disaster recovery plans. Key Responsibilities Disaster Recovery Governance Govern execution of the enterprise disaster recovery framework to ensure recoverability expectations are defined, implemented, and sustained for in-scope systems. Apply and enforce disaster recovery governance standards, processes, and controls across the organization. Maintain oversight of disaster recovery scope, critical system classifications, recovery objectives, and assurance requirements. Business Impact Analysis (BIA) Oversight Govern the completion and ongoing maintenance of Business Impact Analyses (BIAs) to identify critical applications, recovery objectives, and system dependencies. Review and challenge BIAs for quality, consistency, and alignment with enterprise resilience requirements. Ensure BIAs remain current and reflect changes in business operations, technology, and risk. Disaster Recovery Testing & Exercises Provide governance oversight of periodic disaster recovery simulations, tabletop exercises, and recovery tests. Evaluate testing outcomes to assess the organization's ability to recover systems within defined recovery objectives. Identify testing gaps, trends, and weaknesses, and recommend improvements to testing practices. Risk, Issues, and Corrective Action Maintain oversight of disaster recovery-related risks, findings, and corrective action plans. Ensure issues identified through BIAs, testing, or audits are documented, assigned, tracked, and remediated. Monitor remediation progress and escalate risks or delays as appropriate. Audit & Continuous Improvement Support internal and external audits related to disaster recovery by coordinating evidence and preparing governance documentation. Ensure disaster recovery governance activities are audit-ready and defensible. Drive continuous improvement by identifying recurring issues and recommending process or control enhancements. Advisory & Stakeholder Engagement Provide guidance and consultation to application owners on disaster recovery planning and alignment with enterprise standards. Act as an escalation point for complex disaster recovery planning or governance issues. Collaborate with IT, infrastructure, cloud, and business continuity teams to promote consistent implementation of disaster recovery requirements. Required Qualifications Bachelor's degree in Information Technology, Cybersecurity, Risk Management, Business Continuity, or a related field (or equivalent experience). 4-6 years of experience in cybersecurity governance, IT risk management, disaster recovery, business continuity, or technology audit. Experience governing or assessing BIAs, disaster recovery planning, recovery testing, and issue remediation. Working knowledge of disaster recovery and resilience frameworks such as ISO 22301 and NIST SP 800-34. Strong analytical, documentation, and stakeholder communication skills. Preferred Qualifications Experience in a large, complex, or regulated enterprise environment. Familiarity with GRC tools, risk registers, or audit management platforms. Relevant certifications (preferred but not required): CBCP, CISA, CRISC, CISSP. Key Competencies Governance judgment: ability to apply policy and standards pragmatically while maintaining control integrity. Risk-based thinking: ability to assess recoverability gaps in terms of business impact. Influence without authority: effectively challenging and guiding stakeholders to improve resilience outcomes. Program discipline: strong follow-through on tracking, issue management, and audit readiness. Clear communication: translating technical disaster recovery concepts into actionable governance expectations.
09/07/2026
Full time
Job Description Job Description Role: Senior Cyber Security Analyst - Governance (Disaster Recovery, Business Impact) Location: Minneapolis, MN - Hybrid Rate: Depends on Experience Job Description The Senior Cyber Security Analyst - Governance (Disaster Recovery) is responsible for governing and overseeing the organization's disaster recovery (DR) program to ensure the resilience and recoverability of critical IT systems. This role provides independent governance oversight across Business Impact Analyses (BIAs), disaster recovery planning, testing, risk management, and continuous improvement activities. The position partners with application owners, technology teams, and risk and audit stakeholders to ensure disaster recovery requirements are consistently implemented, tested, and maintained in alignment with enterprise standards and industry frameworks such as ISO 22301 and NIST SP 800-34. The role also serves as a trusted advisor to application owners, supporting the development and ongoing maintenance of application-level disaster recovery plans. Key Responsibilities Disaster Recovery Governance Govern execution of the enterprise disaster recovery framework to ensure recoverability expectations are defined, implemented, and sustained for in-scope systems. Apply and enforce disaster recovery governance standards, processes, and controls across the organization. Maintain oversight of disaster recovery scope, critical system classifications, recovery objectives, and assurance requirements. Business Impact Analysis (BIA) Oversight Govern the completion and ongoing maintenance of Business Impact Analyses (BIAs) to identify critical applications, recovery objectives, and system dependencies. Review and challenge BIAs for quality, consistency, and alignment with enterprise resilience requirements. Ensure BIAs remain current and reflect changes in business operations, technology, and risk. Disaster Recovery Testing & Exercises Provide governance oversight of periodic disaster recovery simulations, tabletop exercises, and recovery tests. Evaluate testing outcomes to assess the organization's ability to recover systems within defined recovery objectives. Identify testing gaps, trends, and weaknesses, and recommend improvements to testing practices. Risk, Issues, and Corrective Action Maintain oversight of disaster recovery-related risks, findings, and corrective action plans. Ensure issues identified through BIAs, testing, or audits are documented, assigned, tracked, and remediated. Monitor remediation progress and escalate risks or delays as appropriate. Audit & Continuous Improvement Support internal and external audits related to disaster recovery by coordinating evidence and preparing governance documentation. Ensure disaster recovery governance activities are audit-ready and defensible. Drive continuous improvement by identifying recurring issues and recommending process or control enhancements. Advisory & Stakeholder Engagement Provide guidance and consultation to application owners on disaster recovery planning and alignment with enterprise standards. Act as an escalation point for complex disaster recovery planning or governance issues. Collaborate with IT, infrastructure, cloud, and business continuity teams to promote consistent implementation of disaster recovery requirements. Required Qualifications Bachelor's degree in Information Technology, Cybersecurity, Risk Management, Business Continuity, or a related field (or equivalent experience). 4-6 years of experience in cybersecurity governance, IT risk management, disaster recovery, business continuity, or technology audit. Experience governing or assessing BIAs, disaster recovery planning, recovery testing, and issue remediation. Working knowledge of disaster recovery and resilience frameworks such as ISO 22301 and NIST SP 800-34. Strong analytical, documentation, and stakeholder communication skills. Preferred Qualifications Experience in a large, complex, or regulated enterprise environment. Familiarity with GRC tools, risk registers, or audit management platforms. Relevant certifications (preferred but not required): CBCP, CISA, CRISC, CISSP. Key Competencies Governance judgment: ability to apply policy and standards pragmatically while maintaining control integrity. Risk-based thinking: ability to assess recoverability gaps in terms of business impact. Influence without authority: effectively challenging and guiding stakeholders to improve resilience outcomes. Program discipline: strong follow-through on tracking, issue management, and audit readiness. Clear communication: translating technical disaster recovery concepts into actionable governance expectations.
Cyber Security Analyst
Addison Group Grapeland, Texas
Job Description Job Description Salary: $100,000-$110,000 Location: Houston, Hybrid Cybersecurity Analyst We are seeking a Cybersecurity Analyst to join a growing IT security team and help protect the organization's systems, data, and technology environment. This role will focus heavily on security monitoring, threat detection, investigation, and incident response . The ideal candidate has hands-on cybersecurity experience and can independently recognize suspicious activity, investigate potential threats, determine the appropriate response, and escalate when necessary. Key Responsibilities: Monitor and investigate security alerts across endpoints, identity, email, cloud, and network environments Identify, triage, and respond to potential cybersecurity threats and suspicious activity Manage and work through SOC/security tickets from investigation through resolution or escalation Assist with incident response, threat hunting, vulnerability remediation, and security documentation Monitor Microsoft 365, Entra ID, endpoint security, privileged access, and application permissions Support vulnerability management, penetration testing remediation, and risk assessments Administer and optimize cybersecurity tools and technologies Develop or support security automation using PowerShell and Microsoft Graph API Assist with cloud security initiatives, including vulnerability remediation using Wiz or similar platforms Support security frameworks and best practices, including NIST CSF, CIS Controls, and Microsoft Security Best Practices Collaborate with IT and business teams while staying current on emerging cybersecurity threats Qualifications: 2-3+ years of hands-on cybersecurity, SOC, or security-focused systems administration experience Strong troubleshooting, analytical, and problem-solving skills Experience investigating, triaging, and responding to cybersecurity threats Working knowledge of networking, Windows Server, Active Directory, and Microsoft 365 Associate or Bachelor's degree in Cybersecurity, IT, or a related field and/or relevant cybersecurity certification Strong communication skills with the ability to clearly document and explain security findings Preferred Experience: Microsoft Defender, Entra ID, Sentinel, Purview, and Intune PowerShell and Microsoft Graph API CrowdStrike, Fortinet, or Endpoint Central Azure and cloud security platforms such as Wiz Security+, CySA+, SC-200, SC-300, AZ-500, CISSP, or similar certifications What We're Looking For: Someone who can go beyond simply escalating alerts. This person should be comfortable investigating suspicious activity, determining what is happening, assessing the potential risk, and taking the appropriate next steps.
09/07/2026
Full time
Job Description Job Description Salary: $100,000-$110,000 Location: Houston, Hybrid Cybersecurity Analyst We are seeking a Cybersecurity Analyst to join a growing IT security team and help protect the organization's systems, data, and technology environment. This role will focus heavily on security monitoring, threat detection, investigation, and incident response . The ideal candidate has hands-on cybersecurity experience and can independently recognize suspicious activity, investigate potential threats, determine the appropriate response, and escalate when necessary. Key Responsibilities: Monitor and investigate security alerts across endpoints, identity, email, cloud, and network environments Identify, triage, and respond to potential cybersecurity threats and suspicious activity Manage and work through SOC/security tickets from investigation through resolution or escalation Assist with incident response, threat hunting, vulnerability remediation, and security documentation Monitor Microsoft 365, Entra ID, endpoint security, privileged access, and application permissions Support vulnerability management, penetration testing remediation, and risk assessments Administer and optimize cybersecurity tools and technologies Develop or support security automation using PowerShell and Microsoft Graph API Assist with cloud security initiatives, including vulnerability remediation using Wiz or similar platforms Support security frameworks and best practices, including NIST CSF, CIS Controls, and Microsoft Security Best Practices Collaborate with IT and business teams while staying current on emerging cybersecurity threats Qualifications: 2-3+ years of hands-on cybersecurity, SOC, or security-focused systems administration experience Strong troubleshooting, analytical, and problem-solving skills Experience investigating, triaging, and responding to cybersecurity threats Working knowledge of networking, Windows Server, Active Directory, and Microsoft 365 Associate or Bachelor's degree in Cybersecurity, IT, or a related field and/or relevant cybersecurity certification Strong communication skills with the ability to clearly document and explain security findings Preferred Experience: Microsoft Defender, Entra ID, Sentinel, Purview, and Intune PowerShell and Microsoft Graph API CrowdStrike, Fortinet, or Endpoint Central Azure and cloud security platforms such as Wiz Security+, CySA+, SC-200, SC-300, AZ-500, CISSP, or similar certifications What We're Looking For: Someone who can go beyond simply escalating alerts. This person should be comfortable investigating suspicious activity, determining what is happening, assessing the potential risk, and taking the appropriate next steps.
Cybersecurity Analyst
FIRST SERVICE CREDIT UNION Grapeland, Texas
Job Description Job Description Role: As a Cybersecurity Analyst, you will protect the Credit Union's information assets, systems, and member data through proactive monitoring, risk management, incident response, security governance, and continuous improvement activities. The position supports cybersecurity operations, regulatory compliance, vendor risk management, and cyber resilience initiatives aligned with NIST Cybersecurity Framework (CSF), CIS Controls, FFIEC guidance, and NCUA expectations. The Cybersecurity Analyst partners with technology and business teams to integrate security into all business processes and technology solutions Essential Functions & Responsibilities: Monitor and investigate security events, alerts, and anomalous activity. Analyze threats using SIEM, EDR, NGAV, and threat intelligence sources. Participate in detection, containment, eradication, and recovery activities for cybersecurity incidents. Maintain cybersecurity playbooks and incident response procedures. Support cyber investigations and forensic evidence collection activities. Produce incident reports, dashboards, and security metrics. Coordinate vulnerability identification, assessment, remediation, and validation processes. Assist in managing endpoint security technologies including EDR, NGAV, MDM, and hardening tools. Validate secure configurations for servers, workstations, cloud services, and network infrastructure. Administer and support cybersecurity platforms including Fortinet security products (FortiGate, FortiManager, FortiAnalyzer, FortiAuthenticator, FortiClient, and FortiEMS) to enhance network security, visibility, and threat detection capabilities. Support identity security initiatives including MFA, SSO, PAM, and privileged account governance. Assist with penetration testing activities and remediation of identified security vulnerabilities and assessment findings. Assist in maintaining cybersecurity policies, standards, procedures, and guidelines. Support risk assessments and cybersecurity control reviews. Assist with NCUA examinations, internal audits, external audits, and regulatory reviews. Track corrective actions and remediation plans resulting from audits and assessments. Maintain cybersecurity documentation and evidence repositories Participate in security reviews of vendors, fintech partners, and service providers. Review SOC reports, penetration testing reports, SIG questionnaires, and security attestations. Assist with third-party due diligence and ongoing monitoring activities. Identify and document vendor-related cybersecurity risks. Support cybersecurity awareness and phishing simulation programs. Participate in incident response tabletop exercises. Assist with disaster recovery and business continuity testing activities. Research emerging threats and communicate relevant risks to management. Recommend improvements to strengthen the Credit Union's cybersecurity maturity. Maintain effective detection and response capabilities for security incidents. Performance Measurements: To identify opportunities to improve services to the company and/or its customers through use of new products and technologies. Support successful completion of internal audits, external audits, and NCUA examinations. Improve cybersecurity maturity through measurable control enhancements. Deliver accurate and timely reporting of cybersecurity metrics and risks. Maintain positive relationships with internal departments, members, auditors, and vendors. Contribute to cybersecurity awareness and employee engagement initiatives. Knowledge and Skills Experience: 3-5 years of cybersecurity, information security, or related IT experience. Financial services or credit union experience preferred. Experience working with security technologies and security operations processes. Education: College degree in Computer Science, Information Security, Cyber Security, or equivalent. Interpersonal Skills: Strong verbal and written communication skills are required. Must be able to build effective working relationships with employees, management, vendors, auditors, and regulators. Ability to communicate technical and cybersecurity-related concepts to both technical and non-technical audiences. Requires professionalism, sound judgment, discretion, and the ability to handle sensitive and confidential information. Other Skills: SIEM platforms, Vulnerability Management Platforms, IAM/PAM Technologies, Email Security Solutions, Data Loss Prevention (DLP), Security Awareness Platforms, Security Automation & Orchestration (SOAR).
09/07/2026
Full time
Job Description Job Description Role: As a Cybersecurity Analyst, you will protect the Credit Union's information assets, systems, and member data through proactive monitoring, risk management, incident response, security governance, and continuous improvement activities. The position supports cybersecurity operations, regulatory compliance, vendor risk management, and cyber resilience initiatives aligned with NIST Cybersecurity Framework (CSF), CIS Controls, FFIEC guidance, and NCUA expectations. The Cybersecurity Analyst partners with technology and business teams to integrate security into all business processes and technology solutions Essential Functions & Responsibilities: Monitor and investigate security events, alerts, and anomalous activity. Analyze threats using SIEM, EDR, NGAV, and threat intelligence sources. Participate in detection, containment, eradication, and recovery activities for cybersecurity incidents. Maintain cybersecurity playbooks and incident response procedures. Support cyber investigations and forensic evidence collection activities. Produce incident reports, dashboards, and security metrics. Coordinate vulnerability identification, assessment, remediation, and validation processes. Assist in managing endpoint security technologies including EDR, NGAV, MDM, and hardening tools. Validate secure configurations for servers, workstations, cloud services, and network infrastructure. Administer and support cybersecurity platforms including Fortinet security products (FortiGate, FortiManager, FortiAnalyzer, FortiAuthenticator, FortiClient, and FortiEMS) to enhance network security, visibility, and threat detection capabilities. Support identity security initiatives including MFA, SSO, PAM, and privileged account governance. Assist with penetration testing activities and remediation of identified security vulnerabilities and assessment findings. Assist in maintaining cybersecurity policies, standards, procedures, and guidelines. Support risk assessments and cybersecurity control reviews. Assist with NCUA examinations, internal audits, external audits, and regulatory reviews. Track corrective actions and remediation plans resulting from audits and assessments. Maintain cybersecurity documentation and evidence repositories Participate in security reviews of vendors, fintech partners, and service providers. Review SOC reports, penetration testing reports, SIG questionnaires, and security attestations. Assist with third-party due diligence and ongoing monitoring activities. Identify and document vendor-related cybersecurity risks. Support cybersecurity awareness and phishing simulation programs. Participate in incident response tabletop exercises. Assist with disaster recovery and business continuity testing activities. Research emerging threats and communicate relevant risks to management. Recommend improvements to strengthen the Credit Union's cybersecurity maturity. Maintain effective detection and response capabilities for security incidents. Performance Measurements: To identify opportunities to improve services to the company and/or its customers through use of new products and technologies. Support successful completion of internal audits, external audits, and NCUA examinations. Improve cybersecurity maturity through measurable control enhancements. Deliver accurate and timely reporting of cybersecurity metrics and risks. Maintain positive relationships with internal departments, members, auditors, and vendors. Contribute to cybersecurity awareness and employee engagement initiatives. Knowledge and Skills Experience: 3-5 years of cybersecurity, information security, or related IT experience. Financial services or credit union experience preferred. Experience working with security technologies and security operations processes. Education: College degree in Computer Science, Information Security, Cyber Security, or equivalent. Interpersonal Skills: Strong verbal and written communication skills are required. Must be able to build effective working relationships with employees, management, vendors, auditors, and regulators. Ability to communicate technical and cybersecurity-related concepts to both technical and non-technical audiences. Requires professionalism, sound judgment, discretion, and the ability to handle sensitive and confidential information. Other Skills: SIEM platforms, Vulnerability Management Platforms, IAM/PAM Technologies, Email Security Solutions, Data Loss Prevention (DLP), Security Awareness Platforms, Security Automation & Orchestration (SOAR).
Cybersecurity Analyst
Divine Global Solutions Columbia, South Carolina
Job Description Job Description Benefits/Perks Competitive Compensation Flexible Scheduling Career Growth Opportunities Job Summary We are seeking a skilled Cybersecurity Analyst to join our team. As the Cybersecurity Analyst, you will be responsible for identifying any vulnerabilities in our networks and preventing unauthorized access to our data. The ideal candidate is honest, reliable, and has a proven track record in computer security. Responsibilities Audit and assess security risks and IT policies Create company-wide best practices for IT security policies 5+ years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis. Create data recovery plans Maintain information security policy and procedure documentation 3+ years of hands-on experience working with data protection technologies such as data loss prevention (DLP), insider risk management tools, and data security posture management for AI (DSPM for AI). Install and configure security software Document any security breaches and report on damage caused 3+ years of experience reviewing and triaging data related security alerts, analyzing access and movement of sensitive information, documenting findings, and escalating incidents according to established procedures. Review and stay up-to-date on privacy and security laws and regulations 3+ years of collaborating with technical and nontechnical teams to resolve security issues and supporting Educate colleagues on information security management Qualifications A bachelor's degree in Computer Science or a related field is preferred Previous experience as a Cybersecurity Analyst, Computer Security Specialist, or similar role is preferred Strong troubleshooting and analytical skills Ability to work well as part of a team Strong written and verbal communication skills Knowledge of C++ and PHP languages are preferred Knowledge of risk management methodologies and security frameworks Familiarity with intrusion detection/prevention systems Familiarity with public key infrastructure (PKI) and cryptographic protocols (e.g. SSL/ TLS)
09/07/2026
Full time
Job Description Job Description Benefits/Perks Competitive Compensation Flexible Scheduling Career Growth Opportunities Job Summary We are seeking a skilled Cybersecurity Analyst to join our team. As the Cybersecurity Analyst, you will be responsible for identifying any vulnerabilities in our networks and preventing unauthorized access to our data. The ideal candidate is honest, reliable, and has a proven track record in computer security. Responsibilities Audit and assess security risks and IT policies Create company-wide best practices for IT security policies 5+ years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis. Create data recovery plans Maintain information security policy and procedure documentation 3+ years of hands-on experience working with data protection technologies such as data loss prevention (DLP), insider risk management tools, and data security posture management for AI (DSPM for AI). Install and configure security software Document any security breaches and report on damage caused 3+ years of experience reviewing and triaging data related security alerts, analyzing access and movement of sensitive information, documenting findings, and escalating incidents according to established procedures. Review and stay up-to-date on privacy and security laws and regulations 3+ years of collaborating with technical and nontechnical teams to resolve security issues and supporting Educate colleagues on information security management Qualifications A bachelor's degree in Computer Science or a related field is preferred Previous experience as a Cybersecurity Analyst, Computer Security Specialist, or similar role is preferred Strong troubleshooting and analytical skills Ability to work well as part of a team Strong written and verbal communication skills Knowledge of C++ and PHP languages are preferred Knowledge of risk management methodologies and security frameworks Familiarity with intrusion detection/prevention systems Familiarity with public key infrastructure (PKI) and cryptographic protocols (e.g. SSL/ TLS)
Cybersecurity Analyst (3959)
Navarro Inc. Ballston Spa, New York
Job Description Job Description Navarro Research and Engineering is recruiting a Cybersecurity Analyst in West Mifflin, PA or West Milton, NY. An active DOE clearance or DOD equivalent is required to be considered for this opportunity. Navarro is an award-winning provider of turnkey solutions, delivering comprehensive nuclear, environmental and technical services to federal agencies, commercial enterprises and private clients across the United States. Our expertise supports organizations such as the Department of Energy, the National Nuclear Security Administration, the Department of Defense and NASA, while also extending to commercial industries and private sector partners facing complex engineering, technical and environmental challenges. Navarro specializes in nuclear operations, environmental remediation, D&D, waste management, advanced energy, facilities management and technical and professional services. For more information, please visit The Naval Nuclear Laboratory develops advanced naval nuclear propulsion technology for the safety and reliability of our Navy's submarine and aircraft fleet. Our company is looking for a Cybersecurity subcontractor professional to join our team. The subcontractor will be responsible for execution of all aspects of the National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). This includes assisting information system owners with development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the existing RSAArcher application on the Naval Nuclear Propulsion Network (NNPP Net) to support information system authorization. Additionally, the subcontractor will assist in the development of Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process. Job Location is Bettis or Knolls. Requirements At least four years of combined experience in the following roles; security control validator, security control assessor, Information System Security Officer (ISSO), or Information System Security Manager (ISSM) At least two years of experience supporting development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a) At least two years of experience working with Federal Risk and Authorization Management Program (FedRAMP) Security+ Certification Desired Knowledge, Skills, and Abilities Experience with the RSA Archer application At least two years of experience working on IT security project teams At least one year of experience managing IT projects Knowledge of IT infrastructure and services (Data Centers, physical and virtual servers, local and wide area networking components, cloud Infrastructure/Platform/Software as a Service, etc.) Knowledge of security policies such as NIST Special Publications, Security Technical Implementation Guides (STIGs), DOD Cloud Computing Security Resource Guide (SRG) Knowledge of infrastructure security, endpoint protection, vulnerability management tools Previous work authorizing information systems within a classified DoE or DoD environment Familiarity with NIST 800-171 Certified Information Systems Security Professional (CISSP) certification Certificate of Cloud Security Knowledge (CCSK) certification Due to the nature of the government contract requirements and/or clearances requirements, US citizenship is required. Navarro is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, religion, color, national origin, age, disability, veteran's status, or any classification protected by applicable state or local law. EEO Employer/Vet/Disabled Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation & Public Holidays) Short Term & Long-Term Disability
09/07/2026
Full time
Job Description Job Description Navarro Research and Engineering is recruiting a Cybersecurity Analyst in West Mifflin, PA or West Milton, NY. An active DOE clearance or DOD equivalent is required to be considered for this opportunity. Navarro is an award-winning provider of turnkey solutions, delivering comprehensive nuclear, environmental and technical services to federal agencies, commercial enterprises and private clients across the United States. Our expertise supports organizations such as the Department of Energy, the National Nuclear Security Administration, the Department of Defense and NASA, while also extending to commercial industries and private sector partners facing complex engineering, technical and environmental challenges. Navarro specializes in nuclear operations, environmental remediation, D&D, waste management, advanced energy, facilities management and technical and professional services. For more information, please visit The Naval Nuclear Laboratory develops advanced naval nuclear propulsion technology for the safety and reliability of our Navy's submarine and aircraft fleet. Our company is looking for a Cybersecurity subcontractor professional to join our team. The subcontractor will be responsible for execution of all aspects of the National Institute of Standards and Technology (NIST) directives to support the Risk Management Framework (RMF). This includes assisting information system owners with development of System Security Plans (SSPs) and Security Assessment Reports (SARs) using the existing RSAArcher application on the Naval Nuclear Propulsion Network (NNPP Net) to support information system authorization. Additionally, the subcontractor will assist in the development of Plans of Action and Milestone (POA&Ms) and Risk Based Decisions (RBDs) for deficiencies found during the information system authorization process. Job Location is Bettis or Knolls. Requirements At least four years of combined experience in the following roles; security control validator, security control assessor, Information System Security Officer (ISSO), or Information System Security Manager (ISSM) At least two years of experience supporting development of information system security authorization packages in accordance with Risk Management Framework (NIST 800-37, 800-53, 800-53a) At least two years of experience working with Federal Risk and Authorization Management Program (FedRAMP) Security+ Certification Desired Knowledge, Skills, and Abilities Experience with the RSA Archer application At least two years of experience working on IT security project teams At least one year of experience managing IT projects Knowledge of IT infrastructure and services (Data Centers, physical and virtual servers, local and wide area networking components, cloud Infrastructure/Platform/Software as a Service, etc.) Knowledge of security policies such as NIST Special Publications, Security Technical Implementation Guides (STIGs), DOD Cloud Computing Security Resource Guide (SRG) Knowledge of infrastructure security, endpoint protection, vulnerability management tools Previous work authorizing information systems within a classified DoE or DoD environment Familiarity with NIST 800-171 Certified Information Systems Security Professional (CISSP) certification Certificate of Cloud Security Knowledge (CCSK) certification Due to the nature of the government contract requirements and/or clearances requirements, US citizenship is required. Navarro is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, religion, color, national origin, age, disability, veteran's status, or any classification protected by applicable state or local law. EEO Employer/Vet/Disabled Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation & Public Holidays) Short Term & Long-Term Disability
Sr. Automation & Cybersecurity Engineer
Actus Consulting Group Plano, Texas
Job Description Job Description Summary: The Senior Automation & Cybersecurity Engineer is a hands-on technical leader responsible for designing, building, and scaling automation that powers the Security Operations Center (SOC). This role owns automated detection, enrichment, triage, response, and AI-assisted workflows that reduce analyst toil, improve signal quality, and strengthen incident response. The ideal candidate combines strong engineering fundamentals-scripting, API integration, SIEM/SOAR development, and cloud automation-with practical cybersecurity judgment. They will partner with detection engineers, incident responders, analysts, and platform owners to convert repeatable processes into reliable, governed automation and safely pilot emerging AI and agentic capabilities. Essential Functions: Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence. Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse. Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations. Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls. Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns. Competencies: Develops scalable and reliable security automation that improves SOC efficiency and operational effectiveness. Applies sound cybersecurity judgment to design secure, governed, and auditable automation and AI-assisted workflows. Collaborates effectively with cross-functional teams to improve detection, response, and operational processes. Continuously improves workflows by reducing manual effort, false positives, and analyst workload through automation. Provides technical leadership through mentoring, code reviews, and the promotion of engineering best practices. Evaluates and implements emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight. Requirements 6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred) Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns. Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies. Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics. Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production. Preferred Qualifications: Experience with Tines for SOC automation and agentic workflow orchestration. Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation. Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines. Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation. Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.
09/07/2026
Full time
Job Description Job Description Summary: The Senior Automation & Cybersecurity Engineer is a hands-on technical leader responsible for designing, building, and scaling automation that powers the Security Operations Center (SOC). This role owns automated detection, enrichment, triage, response, and AI-assisted workflows that reduce analyst toil, improve signal quality, and strengthen incident response. The ideal candidate combines strong engineering fundamentals-scripting, API integration, SIEM/SOAR development, and cloud automation-with practical cybersecurity judgment. They will partner with detection engineers, incident responders, analysts, and platform owners to convert repeatable processes into reliable, governed automation and safely pilot emerging AI and agentic capabilities. Essential Functions: Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence. Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse. Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations. Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls. Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns. Competencies: Develops scalable and reliable security automation that improves SOC efficiency and operational effectiveness. Applies sound cybersecurity judgment to design secure, governed, and auditable automation and AI-assisted workflows. Collaborates effectively with cross-functional teams to improve detection, response, and operational processes. Continuously improves workflows by reducing manual effort, false positives, and analyst workload through automation. Provides technical leadership through mentoring, code reviews, and the promotion of engineering best practices. Evaluates and implements emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight. Requirements 6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred) Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns. Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies. Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics. Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production. Preferred Qualifications: Experience with Tines for SOC automation and agentic workflow orchestration. Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation. Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines. Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation. Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.
Cybersecurity Digital Forensics Investigator
Integra Dallas, Texas
Job Description Job Description Location: DFW Department: DEPADM The Opportunity The Cybersecurity Digital Forensics Investigator is responsible for conducting cybersecurity investigations involving company-owned cellphones, computers, tablets, electronic devices, cloud services, applications, and digital records. This position collects, preserves, analyzes, documents, and tracks digital evidence while maintaining strict chain-of-custody and confidentiality requirements. The role works closely with internal Cybersecurity, Information Technology, Human Resources, Legal, Compliance, Corporate Security, and executive leadership teams. The investigator may also coordinate with federal law enforcement agencies, government investigators, outside legal counsel, and approved third-party forensic specialists. This position requires strong technical expertise, sound professional judgment, exceptional attention to detail, and the ability to handle sensitive investigations in a confidential, legally defensible, and impartial manner. What you will do? Digital Forensics and Cybersecurity Investigations Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices. Investigate suspected data theft, unauthorized access, insider threats, cybersecurity incidents, policy violations, fraud, intellectual property theft, and misuse of company technology. Acquire and preserve forensic images and other digital evidence using approved forensic tools and legally defensible procedures. Analyze mobile-device data, including call records, text messages, application data, device logs, photographs, files, location-related artifacts, and system activity, when authorized. Examine Windows, macOS, iOS, Android, cloud, email, network, and application artifacts relevant to investigations. Recover, correlate, and analyze deleted, hidden, encrypted, or otherwise protected information when legally authorized and technically feasible. Develop investigation timelines by correlating information from devices, security systems, access records, network logs, email, cloud services, and other authorized sources. Identify indicators of compromise, suspicious behavior, unauthorized data transfers, and potential violations of company policies or applicable laws. Support incident-response activities, including evidence collection, containment analysis, root-cause investigation, and post-incident reporting. Evidence Management and Chain of Custody Collect, label, preserve, store, transfer, and track digital evidence according to established chain-of-custody procedures. Maintain complete and accurate evidence logs, forensic notes, investigation records, device inventories, and custody documentation. Protect the integrity, authenticity, confidentiality, and availability of all evidence throughout the investigation lifecycle. Verify forensic images and collected data using industry-standard hashing and validation techniques. Ensure evidence is stored securely and accessed only by authorized personnel. Maintain investigation case files in accordance with company retention requirements, legal-hold instructions, contractual obligations, and applicable regulations. Document every investigative action sufficiently to support internal reviews, legal proceedings, regulatory inquiries, or law-enforcement requests. Federal Agency and Legal Coordination Serve as a technical liaison between the company and authorized federal law enforcement or government investigation teams. Coordinate the secure exchange of approved digital evidence, forensic reports, technical findings, and supporting documentation. Respond to authorized subpoenas, warrants, preservation requests, legal holds, and government information requests in coordination with Legal and executive leadership. Support interviews, technical briefings, case reviews, and evidence presentations involving internal stakeholders, outside counsel, or government investigators. Explain technical findings clearly to investigators, attorneys, executives, and other nontechnical audiences. Provide factual testimony, declarations, affidavits, or expert technical support when authorized and required. Maintain professional independence and ensure that investigative conclusions are based on documented evidence. Investigation Data Tracking and Reporting Maintain a centralized system for tracking investigation cases, devices, evidence, activities, findings, deadlines, and case status. Create detailed forensic reports that clearly describe the scope, methodology, tools used, evidence examined, findings, limitations, and conclusions. Working knowledge of forensic imaging, evidence validation, file systems, operating-system artifacts, network logs, and security-event data. Experience coordinating sensitive investigations with Legal, Human Resources, Compliance, Corporate Security, or government agencies. Ability to handle highly confidential, privileged, personal, and legally sensitive information. Strong written, verbal, analytical, interviewing, and presentation skills. Ability to obtain and maintain any security clearance, background investigation, or federal eligibility requirement applicable to the position. Required Qualifications Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, Criminal Justice, or a related field. A minimum of 7 years of experience in cybersecurity, digital forensics, incident response, law enforcement investigations, corporate investigations, or a related discipline. At least 3 years of hands-on experience conducting digital forensic examinations or cybersecurity investigations. Demonstrated experience investigating mobile devices, computers, email systems, cloud environments, and electronic records. Experience maintaining chain-of-custody documentation and producing legally defensible investigation reports. Preferred Qualifications One or more of the following certifications is preferred: Certified Information Systems Security Professional - CISSP GIAC Certified Forensic Examiner - GCFE GIAC Certified Forensic Analyst - GCFA GIAC Advanced Smartphone Forensics - GASF Certified Computer Examiner - CCE EnCase Certified Examiner - EnCE Certified Cyber Forensics Professional - CCFP or equivalent Cellebrite Certified Mobile Examiner - CCME How we support you We believe your best work happens when you feel supported - professionally, personally, and financially. That's why we offer a range of benefits designed to help you thrive, stay healthy, and plan for the future. Performance-driven rewards - Competitive pay with incentive opportunities that recognize your results and contributions. Comprehensive healthcare - Medical, dental, and vision coverage that supports you and your family's total well-being. Security and peace of mind - Life and disability insurance programs that provide protection when it matters most. Flexible benefits options - A variety of voluntary benefits so you can personalize coverage to fit your needs. Time to recharge - Generous paid time off to relax, travel, and maintain a healthy work-life balance. Investing in your growth - Education assistance and tuition support to help you build skills and advance your career. Planning for the future - Retirement and savings programs that help you achieve long-term financial confidence. Come build with us At Integra, we're driven by a vision to transform the data center industry. We specialize in delivering optimized turnkey solutions that bring together speed, quality, and reliability - helping our clients build and operate the mission-critical infrastructure that powers today's digital world. Integra is a vertically integrated company - owning and managing every phase of the process from site selection and design to manufacturing, procurement, commissioning, and warranty. This approach allows us to move faster, solve challenges more efficiently, and deliver exceptional outcomes for our partners. What truly sets Integra apart is our people. We are a team of problem-solvers, engineers, builders, and operators who thrive on tackling complex challenges and delivering results. Our culture values collaboration, accountability, and continuous improvement - because in a rapidly evolving digital landscape, excellence and adaptability matter. Joining Integra means being part of a company that is shaping the future of data center infrastructure. If you're passionate about innovation, impact, and building systems the world depends on, you'll find the opportunity to grow and make a difference here. Equal Opportunity Statement Integra provides equal employment opportunities for all people. No employee or applicant for employment will be discriminated against because of race, creed, origin, marital status, sexual orientation, age, otherwise qualified disabled or veteran status or any other characteristic protected by law. If you are a qualified applicant who requires reasonable accommodation to complete a job application, pre-employment testing, a job interview or to otherwise participate in the hiring process . click apply for full job details
09/07/2026
Full time
Job Description Job Description Location: DFW Department: DEPADM The Opportunity The Cybersecurity Digital Forensics Investigator is responsible for conducting cybersecurity investigations involving company-owned cellphones, computers, tablets, electronic devices, cloud services, applications, and digital records. This position collects, preserves, analyzes, documents, and tracks digital evidence while maintaining strict chain-of-custody and confidentiality requirements. The role works closely with internal Cybersecurity, Information Technology, Human Resources, Legal, Compliance, Corporate Security, and executive leadership teams. The investigator may also coordinate with federal law enforcement agencies, government investigators, outside legal counsel, and approved third-party forensic specialists. This position requires strong technical expertise, sound professional judgment, exceptional attention to detail, and the ability to handle sensitive investigations in a confidential, legally defensible, and impartial manner. What you will do? Digital Forensics and Cybersecurity Investigations Conduct cybersecurity and digital forensic investigations involving cellphones, laptops, desktops, tablets, removable media, servers, email systems, cloud platforms, and other electronic devices. Investigate suspected data theft, unauthorized access, insider threats, cybersecurity incidents, policy violations, fraud, intellectual property theft, and misuse of company technology. Acquire and preserve forensic images and other digital evidence using approved forensic tools and legally defensible procedures. Analyze mobile-device data, including call records, text messages, application data, device logs, photographs, files, location-related artifacts, and system activity, when authorized. Examine Windows, macOS, iOS, Android, cloud, email, network, and application artifacts relevant to investigations. Recover, correlate, and analyze deleted, hidden, encrypted, or otherwise protected information when legally authorized and technically feasible. Develop investigation timelines by correlating information from devices, security systems, access records, network logs, email, cloud services, and other authorized sources. Identify indicators of compromise, suspicious behavior, unauthorized data transfers, and potential violations of company policies or applicable laws. Support incident-response activities, including evidence collection, containment analysis, root-cause investigation, and post-incident reporting. Evidence Management and Chain of Custody Collect, label, preserve, store, transfer, and track digital evidence according to established chain-of-custody procedures. Maintain complete and accurate evidence logs, forensic notes, investigation records, device inventories, and custody documentation. Protect the integrity, authenticity, confidentiality, and availability of all evidence throughout the investigation lifecycle. Verify forensic images and collected data using industry-standard hashing and validation techniques. Ensure evidence is stored securely and accessed only by authorized personnel. Maintain investigation case files in accordance with company retention requirements, legal-hold instructions, contractual obligations, and applicable regulations. Document every investigative action sufficiently to support internal reviews, legal proceedings, regulatory inquiries, or law-enforcement requests. Federal Agency and Legal Coordination Serve as a technical liaison between the company and authorized federal law enforcement or government investigation teams. Coordinate the secure exchange of approved digital evidence, forensic reports, technical findings, and supporting documentation. Respond to authorized subpoenas, warrants, preservation requests, legal holds, and government information requests in coordination with Legal and executive leadership. Support interviews, technical briefings, case reviews, and evidence presentations involving internal stakeholders, outside counsel, or government investigators. Explain technical findings clearly to investigators, attorneys, executives, and other nontechnical audiences. Provide factual testimony, declarations, affidavits, or expert technical support when authorized and required. Maintain professional independence and ensure that investigative conclusions are based on documented evidence. Investigation Data Tracking and Reporting Maintain a centralized system for tracking investigation cases, devices, evidence, activities, findings, deadlines, and case status. Create detailed forensic reports that clearly describe the scope, methodology, tools used, evidence examined, findings, limitations, and conclusions. Working knowledge of forensic imaging, evidence validation, file systems, operating-system artifacts, network logs, and security-event data. Experience coordinating sensitive investigations with Legal, Human Resources, Compliance, Corporate Security, or government agencies. Ability to handle highly confidential, privileged, personal, and legally sensitive information. Strong written, verbal, analytical, interviewing, and presentation skills. Ability to obtain and maintain any security clearance, background investigation, or federal eligibility requirement applicable to the position. Required Qualifications Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, Criminal Justice, or a related field. A minimum of 7 years of experience in cybersecurity, digital forensics, incident response, law enforcement investigations, corporate investigations, or a related discipline. At least 3 years of hands-on experience conducting digital forensic examinations or cybersecurity investigations. Demonstrated experience investigating mobile devices, computers, email systems, cloud environments, and electronic records. Experience maintaining chain-of-custody documentation and producing legally defensible investigation reports. Preferred Qualifications One or more of the following certifications is preferred: Certified Information Systems Security Professional - CISSP GIAC Certified Forensic Examiner - GCFE GIAC Certified Forensic Analyst - GCFA GIAC Advanced Smartphone Forensics - GASF Certified Computer Examiner - CCE EnCase Certified Examiner - EnCE Certified Cyber Forensics Professional - CCFP or equivalent Cellebrite Certified Mobile Examiner - CCME How we support you We believe your best work happens when you feel supported - professionally, personally, and financially. That's why we offer a range of benefits designed to help you thrive, stay healthy, and plan for the future. Performance-driven rewards - Competitive pay with incentive opportunities that recognize your results and contributions. Comprehensive healthcare - Medical, dental, and vision coverage that supports you and your family's total well-being. Security and peace of mind - Life and disability insurance programs that provide protection when it matters most. Flexible benefits options - A variety of voluntary benefits so you can personalize coverage to fit your needs. Time to recharge - Generous paid time off to relax, travel, and maintain a healthy work-life balance. Investing in your growth - Education assistance and tuition support to help you build skills and advance your career. Planning for the future - Retirement and savings programs that help you achieve long-term financial confidence. Come build with us At Integra, we're driven by a vision to transform the data center industry. We specialize in delivering optimized turnkey solutions that bring together speed, quality, and reliability - helping our clients build and operate the mission-critical infrastructure that powers today's digital world. Integra is a vertically integrated company - owning and managing every phase of the process from site selection and design to manufacturing, procurement, commissioning, and warranty. This approach allows us to move faster, solve challenges more efficiently, and deliver exceptional outcomes for our partners. What truly sets Integra apart is our people. We are a team of problem-solvers, engineers, builders, and operators who thrive on tackling complex challenges and delivering results. Our culture values collaboration, accountability, and continuous improvement - because in a rapidly evolving digital landscape, excellence and adaptability matter. Joining Integra means being part of a company that is shaping the future of data center infrastructure. If you're passionate about innovation, impact, and building systems the world depends on, you'll find the opportunity to grow and make a difference here. Equal Opportunity Statement Integra provides equal employment opportunities for all people. No employee or applicant for employment will be discriminated against because of race, creed, origin, marital status, sexual orientation, age, otherwise qualified disabled or veteran status or any other characteristic protected by law. If you are a qualified applicant who requires reasonable accommodation to complete a job application, pre-employment testing, a job interview or to otherwise participate in the hiring process . click apply for full job details
Cybersecurity Analyst/Engineer
Patriot Contract Services Houston, Texas
Job Description Job Description Patriot Maritime are maritime government contracting companies providing management, crewing, and vessel support services to the U.S. government under contracts with MARAD and the Military Sealift Command (MSC). With approximately 83 shoreside employees and operations across multiple vessel programs - including the Ready Reserve Force (RRF), Watson-class vessels, Bob Hope vessels, and other federal maritime programs - Patriot operates at the intersection of commercial maritime expertise and federal government contracting. Headquartered in Houston, TX, our team supports the nation's strategic sealift mission and military readiness. Patriot is seeking an experienced Cybersecurity Analyst / Engineer to build, operate, and mature the organization's information security program. The complexity of Patriot's environment - hybrid Azure/on-premises infrastructure, an active ERP migration, federal government contract obligations, and ISO 27001, NIST and CMMC compliance requirements - demands someone with demonstrable, hands-on experience who can operate independently, interface with executive leadership, and drive measurable improvement in the company's security posture. The ideal candidate is equally comfortable producing executive risk dashboards as they are configuring Conditional Access policies, tuning Sentinel detection rules, or leading an incident response tabletop. They bring a government contractor mindset: documentation-first, audit-ready, and compliance-aware. KEY RESPONSIBILITIES Security Operations & Monitoring Own and operate security monitoring using Microsoft Sentinel or equivalent SIEM; tune detection rules, triage alerts, and lead response to security events Manage Defender for Endpoint, Defender for Cloud, and Microsoft Secure Score - driving measurable posture improvements on a recurring basis Monitor identity security events, privileged access activity, and anomalous sign-in patterns via Microsoft Entra ID Vulnerability Management & Remediation Conduct regular vulnerability scanning across endpoints, servers, and cloud resources; manage a remediation pipeline in coordination with IT and third-party vendors Track remediation status, exceptions, and risk acceptance decisions with documented evidence for compliance and audit purposes Incident Response & Business Continuity Develop, maintain, and test Incident Response (IR) and Disaster Recovery (DR) plans; lead tabletop exercises with IT and operations stakeholders Serve as the primary point of contact for security incidents; coordinate containment, investigation, and post-incident remediation Compliance & ISO 27001/NIST/CMMC Administration Administer and mature the ISO 27001 control environment; maintain a current Statement of Applicability, evidence library, and audit trail Support DFARS/CMMC readiness efforts as contract requirements evolve, coordinating with Legal and external advisors as needed Enforce and document adherence to NIST CSF and relevant federal compliance frameworks across PCS and ASM environments Identity, Access & Endpoint Controls Review and enforce Conditional Access policies, MFA enrollment, and privileged access controls; ensure Entra ID configurations align with least-privilege principles Oversee endpoint compliance posture (Intune/MEM) and enforce security baselines across Windows endpoints Vendor Risk & Security Awareness Conduct third-party and vendor security risk assessments; maintain a vendor risk register and drive remediation of identified gaps Develop and deliver security awareness training and phishing simulation programs for all shore-based personnel Design and deliver targeted anti-fraud training for Finance, Accounting, and HR staff covering business email compromise (BEC), invoice fraud, payroll diversion, and vendor impersonation schemes Cyber Fraud Monitoring & Prevention Monitor email, financial, and payroll systems for indicators of business email compromise, invoice manipulation, wire fraud, and vendor/banking-detail change schemes Partner with Finance, Accounting, and HR to establish and enforce verification controls for wire transfers, vendor payment changes, and payroll modifications Configure and maintain email authentication and anti-spoofing controls (SPF, DKIM, DMARC) and mailflow rules to reduce phishing and impersonation exposure Investigate suspected fraud incidents in coordination with Finance, Legal, and law enforcement as needed; support recovery efforts and post-incident control improvements Stay current on emerging cyber fraud tactics (deepfake/voice-cloning impersonation, social engineering, account takeover) and proactively adapt controls and training accordingly Reporting & Executive Communication Produce recurring executive security dashboards and risk metrics for President, CFO, and senior leadership review Translate technical risk into business language; contribute to contract-level security disclosures and compliance reporting as required REQUIRED QUALIFICATIONS 3-5+ years of hands-on experience in cybersecurity or information security engineering; mid-to-senior level background required Demonstrated experience in a federal government contractor, defense, or similarly regulated environment strongly preferred Prior experience with CMMC framework requirements is required Hands-on proficiency with the Microsoft security stack: Sentinel (SIEM/SOAR), Defender for Endpoint, Defender for Cloud, Entra ID, and Conditional Access Working knowledge of Azure security services, cloud posture management (CSPM), and hybrid infrastructure environments Working knowledge of NIST CSF, ISO 27001, DFARS , and CMMC 2.0 framework requirements Ability to maintain audit-ready documentation, evidence libraries, and control mapping artifacts Strong written and oral communication skills; ability to translate technical risk into business-level language for executive audiences Demonstrated experience identifying, investigating, and mitigating cyber-enabled fraud, including business email compromise (BEC), invoice fraud, and payment diversion schemes PREFERRED QUALIFICATIONS CISSP, CISM, CompTIA Security+, or Microsoft SC-200 / SC-300 certification (candidates with equivalent demonstrated experience will be considered) Experience with vulnerability scanning platforms (e.g., Nessus, Qualys, Defender Vulnerability Management) and endpoint management via Intune/MEM Familiarity with ERP security configurations or experience supporting an active ERP migration environment Experience in a maritime, transportation, or DoD-adjacent operating environment Certified Fraud Examiner (CFE) or equivalent fraud investigation/financial crimes credential Security clearance eligibility (Secret preferred) Patriot offers a competitive total compensation package commensurate with experience, including: Comprehensive health benefits: Medical, Dental, and Vision Life insurance and disability coverage 401(k) retirement plan with employer contribution Paid time off, holidays, and sick leave per company policy
09/07/2026
Full time
Job Description Job Description Patriot Maritime are maritime government contracting companies providing management, crewing, and vessel support services to the U.S. government under contracts with MARAD and the Military Sealift Command (MSC). With approximately 83 shoreside employees and operations across multiple vessel programs - including the Ready Reserve Force (RRF), Watson-class vessels, Bob Hope vessels, and other federal maritime programs - Patriot operates at the intersection of commercial maritime expertise and federal government contracting. Headquartered in Houston, TX, our team supports the nation's strategic sealift mission and military readiness. Patriot is seeking an experienced Cybersecurity Analyst / Engineer to build, operate, and mature the organization's information security program. The complexity of Patriot's environment - hybrid Azure/on-premises infrastructure, an active ERP migration, federal government contract obligations, and ISO 27001, NIST and CMMC compliance requirements - demands someone with demonstrable, hands-on experience who can operate independently, interface with executive leadership, and drive measurable improvement in the company's security posture. The ideal candidate is equally comfortable producing executive risk dashboards as they are configuring Conditional Access policies, tuning Sentinel detection rules, or leading an incident response tabletop. They bring a government contractor mindset: documentation-first, audit-ready, and compliance-aware. KEY RESPONSIBILITIES Security Operations & Monitoring Own and operate security monitoring using Microsoft Sentinel or equivalent SIEM; tune detection rules, triage alerts, and lead response to security events Manage Defender for Endpoint, Defender for Cloud, and Microsoft Secure Score - driving measurable posture improvements on a recurring basis Monitor identity security events, privileged access activity, and anomalous sign-in patterns via Microsoft Entra ID Vulnerability Management & Remediation Conduct regular vulnerability scanning across endpoints, servers, and cloud resources; manage a remediation pipeline in coordination with IT and third-party vendors Track remediation status, exceptions, and risk acceptance decisions with documented evidence for compliance and audit purposes Incident Response & Business Continuity Develop, maintain, and test Incident Response (IR) and Disaster Recovery (DR) plans; lead tabletop exercises with IT and operations stakeholders Serve as the primary point of contact for security incidents; coordinate containment, investigation, and post-incident remediation Compliance & ISO 27001/NIST/CMMC Administration Administer and mature the ISO 27001 control environment; maintain a current Statement of Applicability, evidence library, and audit trail Support DFARS/CMMC readiness efforts as contract requirements evolve, coordinating with Legal and external advisors as needed Enforce and document adherence to NIST CSF and relevant federal compliance frameworks across PCS and ASM environments Identity, Access & Endpoint Controls Review and enforce Conditional Access policies, MFA enrollment, and privileged access controls; ensure Entra ID configurations align with least-privilege principles Oversee endpoint compliance posture (Intune/MEM) and enforce security baselines across Windows endpoints Vendor Risk & Security Awareness Conduct third-party and vendor security risk assessments; maintain a vendor risk register and drive remediation of identified gaps Develop and deliver security awareness training and phishing simulation programs for all shore-based personnel Design and deliver targeted anti-fraud training for Finance, Accounting, and HR staff covering business email compromise (BEC), invoice fraud, payroll diversion, and vendor impersonation schemes Cyber Fraud Monitoring & Prevention Monitor email, financial, and payroll systems for indicators of business email compromise, invoice manipulation, wire fraud, and vendor/banking-detail change schemes Partner with Finance, Accounting, and HR to establish and enforce verification controls for wire transfers, vendor payment changes, and payroll modifications Configure and maintain email authentication and anti-spoofing controls (SPF, DKIM, DMARC) and mailflow rules to reduce phishing and impersonation exposure Investigate suspected fraud incidents in coordination with Finance, Legal, and law enforcement as needed; support recovery efforts and post-incident control improvements Stay current on emerging cyber fraud tactics (deepfake/voice-cloning impersonation, social engineering, account takeover) and proactively adapt controls and training accordingly Reporting & Executive Communication Produce recurring executive security dashboards and risk metrics for President, CFO, and senior leadership review Translate technical risk into business language; contribute to contract-level security disclosures and compliance reporting as required REQUIRED QUALIFICATIONS 3-5+ years of hands-on experience in cybersecurity or information security engineering; mid-to-senior level background required Demonstrated experience in a federal government contractor, defense, or similarly regulated environment strongly preferred Prior experience with CMMC framework requirements is required Hands-on proficiency with the Microsoft security stack: Sentinel (SIEM/SOAR), Defender for Endpoint, Defender for Cloud, Entra ID, and Conditional Access Working knowledge of Azure security services, cloud posture management (CSPM), and hybrid infrastructure environments Working knowledge of NIST CSF, ISO 27001, DFARS , and CMMC 2.0 framework requirements Ability to maintain audit-ready documentation, evidence libraries, and control mapping artifacts Strong written and oral communication skills; ability to translate technical risk into business-level language for executive audiences Demonstrated experience identifying, investigating, and mitigating cyber-enabled fraud, including business email compromise (BEC), invoice fraud, and payment diversion schemes PREFERRED QUALIFICATIONS CISSP, CISM, CompTIA Security+, or Microsoft SC-200 / SC-300 certification (candidates with equivalent demonstrated experience will be considered) Experience with vulnerability scanning platforms (e.g., Nessus, Qualys, Defender Vulnerability Management) and endpoint management via Intune/MEM Familiarity with ERP security configurations or experience supporting an active ERP migration environment Experience in a maritime, transportation, or DoD-adjacent operating environment Certified Fraud Examiner (CFE) or equivalent fraud investigation/financial crimes credential Security clearance eligibility (Secret preferred) Patriot offers a competitive total compensation package commensurate with experience, including: Comprehensive health benefits: Medical, Dental, and Vision Life insurance and disability coverage 401(k) retirement plan with employer contribution Paid time off, holidays, and sick leave per company policy
Senior Automation & Cybersecurity Engineer
Cinter Career Plano, Texas
Job Description Job Description ︎ Job Details Job Title: Senior Automation & Cybersecurity Engineer Client: Japanese IT Company Working Location: Plano TX Working Style: W-2 No C2C Employment Type: Full-time Salary: DOE Visa Support: NO Working Hours: Business Hours (CT) Language: English ︎ Key Responsibilities Design, build, and maintain security automation across SIEM/SOAR platforms to streamline alert enrichment, correlation, incident response, and case management. Develop automation and integrations using Python, PowerShell, APIs, and cloud-native technologies with production-quality monitoring, documentation, and error handling. Collaborate with SOC analysts, detection engineers, and incident responders to automate repetitive tasks, improve detection quality, and reduce false positives. Design and implement AI-assisted and agentic security workflows for investigation, enrichment, summarization, and decision support while ensuring human oversight and governance. Partner with security, infrastructure, compliance, and platform teams to establish automation standards, perform code reviews, and mentor junior engineers. Continuously improve SOC operational efficiency by identifying opportunities to automate manual processes and enhance incident response capabilities. Evaluate and implement emerging AI and automation technologies to strengthen security operations. ︎ The Right Candidate Will Possess 6-9 years of cybersecurity engineering experience, including hands-on experience with security automation and SOC engineering. Strong software engineering mindset with the ability to build scalable, reliable, and maintainable automation solutions. Experience working collaboratively with cross-functional security and infrastructure teams. Excellent analytical and problem-solving skills with the ability to improve operational efficiency through automation. Strong communication, documentation, and mentoring abilities. Interest in leveraging AI technologies to modernize security operations while maintaining appropriate governance and security controls. ︎ Required Qualifications & Skills 6-9 years of cybersecurity engineering experience, including 3-4 years in security automation, SIEM/SOAR development, or SOC engineering. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field preferred. Strong proficiency with Python, PowerShell, REST APIs, cloud automation, and integration development. Hands-on experience with enterprise SIEM/SOAR platforms, preferably Microsoft Sentinel. Experience with Microsoft Defender XDR, Azure Logic Apps, or similar Microsoft security technologies. Solid understanding of threat detection, logging pipelines, incident response workflows, alert tuning, and security operations metrics. Excellent documentation, communication, and collaboration skills. Preferred Qualifications Experience with Tines for SOC automation and workflow orchestration. Experience building Agentic SOC solutions using AI/LLM technologies. Knowledge of Detection-as-Code, CI/CD pipelines, MITRE ATT&CK, ASIM, Sigma Rules, or observability platforms. Experience with AI/ML-assisted security tools, prompt engineering, and intelligent agents. Relevant certifications such as: Microsoft Cybersecurity Architect Microsoft Azure Security Engineer Associate GIAC Security Automation Certification No C2C: We do not accept Corp-to-Corp (C2C) arrangements for this position. Powered by JazzHR bW5HrkhDbR
09/07/2026
Full time
Job Description Job Description ︎ Job Details Job Title: Senior Automation & Cybersecurity Engineer Client: Japanese IT Company Working Location: Plano TX Working Style: W-2 No C2C Employment Type: Full-time Salary: DOE Visa Support: NO Working Hours: Business Hours (CT) Language: English ︎ Key Responsibilities Design, build, and maintain security automation across SIEM/SOAR platforms to streamline alert enrichment, correlation, incident response, and case management. Develop automation and integrations using Python, PowerShell, APIs, and cloud-native technologies with production-quality monitoring, documentation, and error handling. Collaborate with SOC analysts, detection engineers, and incident responders to automate repetitive tasks, improve detection quality, and reduce false positives. Design and implement AI-assisted and agentic security workflows for investigation, enrichment, summarization, and decision support while ensuring human oversight and governance. Partner with security, infrastructure, compliance, and platform teams to establish automation standards, perform code reviews, and mentor junior engineers. Continuously improve SOC operational efficiency by identifying opportunities to automate manual processes and enhance incident response capabilities. Evaluate and implement emerging AI and automation technologies to strengthen security operations. ︎ The Right Candidate Will Possess 6-9 years of cybersecurity engineering experience, including hands-on experience with security automation and SOC engineering. Strong software engineering mindset with the ability to build scalable, reliable, and maintainable automation solutions. Experience working collaboratively with cross-functional security and infrastructure teams. Excellent analytical and problem-solving skills with the ability to improve operational efficiency through automation. Strong communication, documentation, and mentoring abilities. Interest in leveraging AI technologies to modernize security operations while maintaining appropriate governance and security controls. ︎ Required Qualifications & Skills 6-9 years of cybersecurity engineering experience, including 3-4 years in security automation, SIEM/SOAR development, or SOC engineering. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field preferred. Strong proficiency with Python, PowerShell, REST APIs, cloud automation, and integration development. Hands-on experience with enterprise SIEM/SOAR platforms, preferably Microsoft Sentinel. Experience with Microsoft Defender XDR, Azure Logic Apps, or similar Microsoft security technologies. Solid understanding of threat detection, logging pipelines, incident response workflows, alert tuning, and security operations metrics. Excellent documentation, communication, and collaboration skills. Preferred Qualifications Experience with Tines for SOC automation and workflow orchestration. Experience building Agentic SOC solutions using AI/LLM technologies. Knowledge of Detection-as-Code, CI/CD pipelines, MITRE ATT&CK, ASIM, Sigma Rules, or observability platforms. Experience with AI/ML-assisted security tools, prompt engineering, and intelligent agents. Relevant certifications such as: Microsoft Cybersecurity Architect Microsoft Azure Security Engineer Associate GIAC Security Automation Certification No C2C: We do not accept Corp-to-Corp (C2C) arrangements for this position. Powered by JazzHR bW5HrkhDbR
Cyber Security Analyst
ScriptPro LLC Shawnee Mission, Kansas
Job Description Job Description Who is ScriptPro? Imagine working at a place where innovation meets impact, and every day brings new opportunities to revolutionize the pharmacy industry! At ScriptPro, you'll be part of a dynamic team that's at the cutting edge of technology, creating solutions that make a real difference in people's lives. ScriptPro develops, sells, and supports state of the art robotics and services in thousands of pharmacy settings around the United States and Canada. ScriptPro's Information Assurance department plays a key role in protecting our products, systems, and customer data while supporting the company's security and compliance initiatives. The team helps build a secure technology environment through risk awareness, proactive monitoring, and strong security practices. This is a great opportunity for security-minded professionals who enjoy continuous learning, teamwork, and making a meaningful impact in a highly regulated pharmaceutical technology environment. Job Summary: The Cyber Security Analyst supports ScriptPro's security and compliance initiatives by helping manage projects, documentation, reporting, and audit readiness across multiple cybersecurity frameworks. This individual will partner with internal teams and customers to coordinate security efforts, track progress, and ensure compliance activities are properly documented and completed. Additional responsibilities include supporting risk management, vulnerability scanning, continuous monitoring, and product security initiatives. The Cyber Security Analyst plays an important role in helping identify, communicate, and resolve security and compliance gaps across ScriptPro's products and environments. Reporting Relationship: Manager, Security Operations Shift: General business hours are Monday through Friday, 8:00 AM to 5:00 PM CST. The position requires availability for on-call duties outside regular hours, including nights, weekends, and holidays. This role is primarily performed remotely, though Kansas City Metro employees may have on-campus requirements according to departmental policy and business need. Generally, all positions may be fully performed on-campus in Mission, KS. Regular, punctual, and predictable attendance is an essential function of every job at ScriptPro. Scope of the Role: Manage and track infrastructure, security, and product certification projects, ensuring full lifecycle execution across Risk Management Framework (RMF), Federal Risk and Authorization Management Program (FedRAMP), Payment Card Industry (PCI), Health Information Trust Alliance (HITRUST), International Organization for Standardization (ISO), and National Institute of Standards and Technology (NIST) frameworks Develop, maintain, and deliver project documentation for Customer Service, DevOps, Information Assurance, and Executive leadership teams Prepare and present monthly reports covering system compliance, security KPIs, audit readiness, and project status Serve as a liaison between internal teams and customers, ensuring clear communication and alignment throughout complex security and compliance initiatives Coordinate project schedules, facilitate cross-departmental tasks, and ensure all project phases are properly documented and completed Support security programs aligned to Risk Management Framework (RMF) Step 1-6, Security Technical Implementation Guide (STIG) compliance, Assured Compliance Assessment Solution (ACAS)/Security Content Automation Protocol (SCAP) scanning, and NIST 800-53/171 control implementation Contribute to FedRAMP Moderate/High authorization packages, System Security Plan (SSP) development, Plan of Action and Milestones (POA&M) management, and continuous monitoring activities Assist with multi-framework compliance efforts including PCI DSS v4.0, HITRUST CSF, ISO 27001, Open Worldwide Application Security Project (OWASP) Top 10, and International Electrotechnical Commission (IEC) 62443 Represent Information Assurance in internal and external meetings, proactively resolving conflicts and guiding teams through ambiguity Perform other duties as assigned Required Qualifications: Bachelor's degree in Computer Science, Business, or a related discipline preferred 5+ years of related experience in cybersecurity, auditing, penetration testing, or Microsoft Server OS and SQL database management Proficient with Microsoft Windows technology, Microsoft Office Suite, and Microsoft Teams Proven ability to meet deadlines, manage workload, and maintain productivity under pressure Highly collaborative mindset with a focus on shared goals and team success Strong interpersonal skills with the ability to build relationships and collaborate across cross-functional teams and all organizational levels Strong attention to detail, excellent organizational and time management skills Strong analytical and critical thinking skills with the ability to assess complex problems and identify root causes Highly motivated, adaptable, and able to thrive in a dynamic, fast-paced, and evolving environment Preferred Qualifications: Obtained industry certifications, including Security+, Cybersecurity Analyst+ (CySA+), or equivalent Knowledge of ScriptPro products and processes Knowledge of the software development lifecycle process Government or Department of Defense IT experience or clearance Remote Work Requirements: Must have high-speed reliable internet access with a hard-wired connection Must have a distraction free home office workspace Must be willing to participate in video virtual meetings (camera on) Benefits: At ScriptPro, we believe that our employees are our greatest asset. That's why we are committed to fostering a workplace that prioritizes and enhances your personal health and well-being. Health: Medical, Dental, Vision, Short-Term Disability, Company Paid Life Insurance & Long-Term Disability, 24/7 on campus Gym, and Vitality Wellness Program that helps lower your premium costs Well-being: Paid Time Off (PTO), Parental Leave, nine (9) paid holidays, paid volunteer hours, Employee Assistance Program, company-sponsored events and team-building activities, 401(k) Retirement Plan with company match, financial investment services, employee discounts on products and services. Employment Conditions: It is ScriptPro's policy to run a comprehensive background check post job offer and you must be able to obtain Department of Defense security clearance after date of hire. See Standard Form 85 to preview requirements. This position includes responsibilities for ensuring compliance with cybersecurity and privacy policies to support the safeguarding sensitive data, including personally identifiable information (PII) and Protected Health Information (PHI). Completion of annual cybersecurity and privacy awareness training is required, as the role aligns with the organization's security posture and risk management practices. All duties are defined in accordance with standardizations to ensure consistency and accountability of the policies. Working Conditions: Requires routine use of standard equipment and extended computer use. Employee must be able to sit, use hands and fingers, and occasionally lift, squat, stoop, bend, and reach. Problem-solving, practical learning, and instruction interpretation skills are essential. ScriptPro appreciates the unique qualities of each team member, and as an Equal Opportunity employer, does not discriminate on the basis of race, color, religion, national origin, sex, pregnancy, age, disability, genetic information, veteran status, or any other legally protected status. The company utilizes internal resources for sourcing and filling positions, but when external assistance is needed, we will engage only with pre-approved, contracted agency partners. The company does not offer visa sponsorships, and all applicants must have legal authorization to work in the United States. Please visit to learn more about the mission of our company.
09/07/2026
Full time
Job Description Job Description Who is ScriptPro? Imagine working at a place where innovation meets impact, and every day brings new opportunities to revolutionize the pharmacy industry! At ScriptPro, you'll be part of a dynamic team that's at the cutting edge of technology, creating solutions that make a real difference in people's lives. ScriptPro develops, sells, and supports state of the art robotics and services in thousands of pharmacy settings around the United States and Canada. ScriptPro's Information Assurance department plays a key role in protecting our products, systems, and customer data while supporting the company's security and compliance initiatives. The team helps build a secure technology environment through risk awareness, proactive monitoring, and strong security practices. This is a great opportunity for security-minded professionals who enjoy continuous learning, teamwork, and making a meaningful impact in a highly regulated pharmaceutical technology environment. Job Summary: The Cyber Security Analyst supports ScriptPro's security and compliance initiatives by helping manage projects, documentation, reporting, and audit readiness across multiple cybersecurity frameworks. This individual will partner with internal teams and customers to coordinate security efforts, track progress, and ensure compliance activities are properly documented and completed. Additional responsibilities include supporting risk management, vulnerability scanning, continuous monitoring, and product security initiatives. The Cyber Security Analyst plays an important role in helping identify, communicate, and resolve security and compliance gaps across ScriptPro's products and environments. Reporting Relationship: Manager, Security Operations Shift: General business hours are Monday through Friday, 8:00 AM to 5:00 PM CST. The position requires availability for on-call duties outside regular hours, including nights, weekends, and holidays. This role is primarily performed remotely, though Kansas City Metro employees may have on-campus requirements according to departmental policy and business need. Generally, all positions may be fully performed on-campus in Mission, KS. Regular, punctual, and predictable attendance is an essential function of every job at ScriptPro. Scope of the Role: Manage and track infrastructure, security, and product certification projects, ensuring full lifecycle execution across Risk Management Framework (RMF), Federal Risk and Authorization Management Program (FedRAMP), Payment Card Industry (PCI), Health Information Trust Alliance (HITRUST), International Organization for Standardization (ISO), and National Institute of Standards and Technology (NIST) frameworks Develop, maintain, and deliver project documentation for Customer Service, DevOps, Information Assurance, and Executive leadership teams Prepare and present monthly reports covering system compliance, security KPIs, audit readiness, and project status Serve as a liaison between internal teams and customers, ensuring clear communication and alignment throughout complex security and compliance initiatives Coordinate project schedules, facilitate cross-departmental tasks, and ensure all project phases are properly documented and completed Support security programs aligned to Risk Management Framework (RMF) Step 1-6, Security Technical Implementation Guide (STIG) compliance, Assured Compliance Assessment Solution (ACAS)/Security Content Automation Protocol (SCAP) scanning, and NIST 800-53/171 control implementation Contribute to FedRAMP Moderate/High authorization packages, System Security Plan (SSP) development, Plan of Action and Milestones (POA&M) management, and continuous monitoring activities Assist with multi-framework compliance efforts including PCI DSS v4.0, HITRUST CSF, ISO 27001, Open Worldwide Application Security Project (OWASP) Top 10, and International Electrotechnical Commission (IEC) 62443 Represent Information Assurance in internal and external meetings, proactively resolving conflicts and guiding teams through ambiguity Perform other duties as assigned Required Qualifications: Bachelor's degree in Computer Science, Business, or a related discipline preferred 5+ years of related experience in cybersecurity, auditing, penetration testing, or Microsoft Server OS and SQL database management Proficient with Microsoft Windows technology, Microsoft Office Suite, and Microsoft Teams Proven ability to meet deadlines, manage workload, and maintain productivity under pressure Highly collaborative mindset with a focus on shared goals and team success Strong interpersonal skills with the ability to build relationships and collaborate across cross-functional teams and all organizational levels Strong attention to detail, excellent organizational and time management skills Strong analytical and critical thinking skills with the ability to assess complex problems and identify root causes Highly motivated, adaptable, and able to thrive in a dynamic, fast-paced, and evolving environment Preferred Qualifications: Obtained industry certifications, including Security+, Cybersecurity Analyst+ (CySA+), or equivalent Knowledge of ScriptPro products and processes Knowledge of the software development lifecycle process Government or Department of Defense IT experience or clearance Remote Work Requirements: Must have high-speed reliable internet access with a hard-wired connection Must have a distraction free home office workspace Must be willing to participate in video virtual meetings (camera on) Benefits: At ScriptPro, we believe that our employees are our greatest asset. That's why we are committed to fostering a workplace that prioritizes and enhances your personal health and well-being. Health: Medical, Dental, Vision, Short-Term Disability, Company Paid Life Insurance & Long-Term Disability, 24/7 on campus Gym, and Vitality Wellness Program that helps lower your premium costs Well-being: Paid Time Off (PTO), Parental Leave, nine (9) paid holidays, paid volunteer hours, Employee Assistance Program, company-sponsored events and team-building activities, 401(k) Retirement Plan with company match, financial investment services, employee discounts on products and services. Employment Conditions: It is ScriptPro's policy to run a comprehensive background check post job offer and you must be able to obtain Department of Defense security clearance after date of hire. See Standard Form 85 to preview requirements. This position includes responsibilities for ensuring compliance with cybersecurity and privacy policies to support the safeguarding sensitive data, including personally identifiable information (PII) and Protected Health Information (PHI). Completion of annual cybersecurity and privacy awareness training is required, as the role aligns with the organization's security posture and risk management practices. All duties are defined in accordance with standardizations to ensure consistency and accountability of the policies. Working Conditions: Requires routine use of standard equipment and extended computer use. Employee must be able to sit, use hands and fingers, and occasionally lift, squat, stoop, bend, and reach. Problem-solving, practical learning, and instruction interpretation skills are essential. ScriptPro appreciates the unique qualities of each team member, and as an Equal Opportunity employer, does not discriminate on the basis of race, color, religion, national origin, sex, pregnancy, age, disability, genetic information, veteran status, or any other legally protected status. The company utilizes internal resources for sourcing and filling positions, but when external assistance is needed, we will engage only with pre-approved, contracted agency partners. The company does not offer visa sponsorships, and all applicants must have legal authorization to work in the United States. Please visit to learn more about the mission of our company.
Senior Threat Hunter Analyst
Revolutional, LLC Kansas City, Missouri
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Salary: $125-$150k DOE Clearance: Active Top Secret required Travel: 0-10% Project Description This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program's defensive posture - finding what automated tools miss before it becomes a confirmed incident. The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program's detection and response capabilities over time. Position Description As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat - proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management. What You Will Own Proactive threat hunting across enterprise network environments for undetected adversary activity Malware analysis in support of hunt findings and incident response CND triage and analysis support for active incident response operations Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team IOC report authorship from open-source intelligence portals After-action and lessons-learned documentation for significant hunts and incidents Security event and metric reporting for program management Responsibilities Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program's long-term detection capability Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline Active Top Secret clearance required Technical & Domain Capabilities Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques Experience conducting CND triage and supporting incident response with technical analysis under operational tempo Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape Core Strengths Proactive and analytically driven - you hunt because you assume the adversary is already in, and you don't stop until the evidence tells you otherwise Technically fluent across hunting, malware analysis, and incident response - you shift between disciplines fluidly as the mission demands Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience Collaborative partner to threat intelligence and incident response teams - your findings feed the broader program, not just your own queue Certifications One or more of the following is strongly preferred: GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent Nice to Have (Differentiators) Experience threat hunting in a federal civilian, defense, or intelligence SOC environment Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations Background in advanced malware reverse engineering or exploit analysis Familiarity with cloud-native hunting across commercial or GovCloud environments _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender . click apply for full job details
09/07/2026
Full time
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Threat Hunter Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Salary: $125-$150k DOE Clearance: Active Top Secret required Travel: 0-10% Project Description This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, threat hunting, incident response, and threat intelligence across a complex enterprise network environment. The threat hunting function operates at the leading edge of the program's defensive posture - finding what automated tools miss before it becomes a confirmed incident. The core challenge: proactively hunting adversary activity across a large, high-complexity enterprise network, supporting active incident response, and producing intelligence products that sharpen the program's detection and response capabilities over time. Position Description As a Senior Threat Hunter Analyst at Revolutional, you operate ahead of the threat - proactively hunting for undetected adversary activity across enterprise networks before it surfaces through automated detection. You are a technically deep practitioner who combines hunting tradecraft with malware analysis capability, incident response support, and the discipline to produce IOC reports, after-action reviews, and security metric reporting that make the program measurably better over time. You work in close coordination with the Cyber Threat Intelligence team, maintaining threat indicator feeds that keep your hunts current and your findings actionable. You conduct CND triage, support active incidents with analysis, and author finished intelligence products from open-source portals. Your output reaches both technical peers and program management. What You Will Own Proactive threat hunting across enterprise network environments for undetected adversary activity Malware analysis in support of hunt findings and incident response CND triage and analysis support for active incident response operations Threat indicator feed maintenance in coordination with the Cyber Threat Intelligence team IOC report authorship from open-source intelligence portals After-action and lessons-learned documentation for significant hunts and incidents Security event and metric reporting for program management Responsibilities Proactively hunt for undetected cyber threats across enterprise network environments using network flow, PCAP, log data, endpoint telemetry, and SIEM data; operate ahead of automated detection capabilities Conduct Computer Network Defense (CND) triage: assess alerts and anomalies, determine threat validity, and prioritize findings for response or further investigation Provide analysis support to incident response operations; contribute host and network analysis, malware triage, and attacker TTP reconstruction during active incidents Perform malware analysis on samples collected during hunts and incidents; identify behavioral indicators, persistence mechanisms, and IOCs for operationalization Maintain and update threat indicator feeds in coordination with the Cyber Threat Intelligence team; ensure hunt operations are informed by current intelligence Author IOC reports from open-source intelligence portals; package findings into finished products suitable for both technical teams and program leadership Prepare after-action reports and lessons-learned documentation following significant hunts and incidents; identify detection gaps and recommend improvements Produce security event and metric reports for program management; communicate hunt findings, detection trends, and program health in clear, data-supported terms Develop and maintain reusable hunt tactics, SIEM queries, and detection logic that improve the program's long-term detection capability Stay current on adversary TTPs, malware families, threat actor trends, and emerging attack techniques relevant to the federal enterprise environment What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) 5 or more years of experience in threat hunting, security operations, or a closely related technical discipline Active Top Secret clearance required Technical & Domain Capabilities Demonstrated experience proactively hunting for adversary activity across enterprise networks using hypothesis-driven and intelligence-driven hunt methodologies Hands-on IDS/IPS experience: signature review, alert triage, anomaly identification, and tuning to reduce noise and improve detection fidelity Proficiency with SIEM platforms: search language, query development, correlation rule creation, dashboard operations, and metric reporting Malware analysis experience including behavioral analysis, static review, IOC extraction, and identification of adversary tooling and techniques Experience conducting CND triage and supporting incident response with technical analysis under operational tempo Experience authoring IOC reports and finished intelligence products from open-source intelligence (OSINT) portals Experience preparing after-action reports and lessons-learned documentation that drive concrete defensive improvements Familiarity with MITRE ATT&CK framework applied to hunt hypothesis development and TTP mapping Current knowledge of adversary TTPs, threat actor trends, and the evolving federal cybersecurity threat landscape Core Strengths Proactive and analytically driven - you hunt because you assume the adversary is already in, and you don't stop until the evidence tells you otherwise Technically fluent across hunting, malware analysis, and incident response - you shift between disciplines fluidly as the mission demands Strong written communicator: your IOC reports, after-actions, and metric reports are clear, accurate, and written for the audience Collaborative partner to threat intelligence and incident response teams - your findings feed the broader program, not just your own queue Certifications One or more of the following is strongly preferred: GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCTI (GIAC Cyber Threat Intelligence), GREM (GIAC Reverse Engineering Malware), CySA+, or equivalent Nice to Have (Differentiators) Experience threat hunting in a federal civilian, defense, or intelligence SOC environment Proficiency scripting in Python or equivalent for hunt automation and IOC enrichment workflows Experience with threat intelligence platforms (TIPs) and integrating CTI data into active hunt operations Background in advanced malware reverse engineering or exploit analysis Familiarity with cloud-native hunting across commercial or GovCloud environments _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender . click apply for full job details
Senior Forensic Analyst
Revolutional, LLC Kansas City, Missouri
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Forensic Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Clearance: Active Top Secret required SalaryRange: $130-170k DOE Travel: Yes - travel to government sites as required Project Description This position supports a large-scale federal security operations program responsible for protecting enterprise networks, detecting and responding to intrusions, and conducting forensic investigations of suspected compromises. Forensic evaluations on this program are non-repetitive, fixed-duration engagements - each one is unique, consequential, and conducted under legal chain of custody requirements. The core challenge: conducting rigorous forensic evaluations of federal systems suspected of compromise - independently, under legal and evidentiary standards, with findings that inform both immediate response and broader intelligence community awareness. Position Description As a Senior Forensic Analyst at Revolutional, you conduct forensic evaluations of federal enterprise systems suspected of compromise. You are a senior practitioner operating with a high degree of independence - each engagement is distinct, and you bring the expertise to scope, execute, and deliver findings without a playbook written specifically for the situation in front of you. You maintain strict chain of custody in accordance with applicable federal and state legal requirements, conduct both host and network analysis to determine the full extent of compromise, and interface directly with the intelligence community to share and receive context that sharpens your findings. You may travel to government sites as required to support on-site forensic collection and analysis. What You Will Own End-to-end forensic evaluation of federal systems suspected of compromise Chain of custody integrity across all evidence collected and handled Host and network analysis to determine compromise scope and attacker activity Intelligence community interface and information sharing on active investigations Forensic project support across program-directed engagements On-site forensic collection and analysis at government facilities as required Responsibilities Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction to determine attacker activity and compromise extent Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification to establish the full scope of intrusion activity Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended response actions Interface with the intelligence community to share forensic findings, receive relevant threat context, and ensure investigations are informed by the current intelligence picture Support forensic projects as directed by program leadership, including surge support for high-priority or time-sensitive investigations Travel to government sites as required to conduct on-site evidence collection, system imaging, and forensic analysis Maintain current awareness of adversary TTPs, malware families, and forensic evasion techniques relevant to the federal threat landscape Contribute to development and refinement of forensic procedures, evidence handling standards, and investigation methodologies Coordinate with incident response, threat intelligence, and SOC teams to ensure forensic findings drive timely and effective response actions What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience) 7 or more years of hands-on digital forensics experience, including complex investigations of suspected system compromises in federal or law enforcement environments Demonstrated experience maintaining chain of custody in accordance with federal and state legal requirements Active Top Secret clearance required Ability and willingness to travel to government sites as required Technical & Domain Capabilities Expert-level host forensics: disk and memory acquisition, file system analysis, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments Hands-on network forensics: packet capture analysis, NetFlow, proxy and DNS log review, and identification of lateral movement, exfiltration, and command-and-control activity Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent Experience conducting non-repetitive, fixed-duration forensic evaluations independently with minimal direction Established working relationships or experience interfacing with the intelligence community in the context of cybersecurity investigations Understanding of attacker TTPs, kill-chain methodology, and MITRE ATT&CK framework as applied to forensic investigations Experience producing forensic reports that meet legal and evidentiary standards for federal proceedings Core Strengths Technically expert and analytically independent - you scope and execute complex forensic investigations without needing the situation pre-defined for you Legally disciplined: chain of custody, evidence integrity, and documentation rigor are non-negotiable to you Credible intelligence community partner - you share findings with precision and incorporate external context effectively Composed under operational pressure; fixed-duration engagements with real consequences don't rattle your methodology or your output quality Certifications One or more of the following is strongly preferred: GCFE or GCFA (GIAC Forensics), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), GCIH, or CISSP Nice to Have (Differentiators) GREM (GIAC Reverse Engineering Malware) or equivalent malware analysis credential Experience conducting forensic investigations at the TS/SCI level or within classified network environments Active TS/SCI clearance Prior direct experience working with or embedded in an intelligence community organization Background in mobile device forensics, cloud forensics, or industrial control system (ICS) forensics Experience supporting law enforcement actions or legal proceedings with forensic evidence and expert testimony _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional . click apply for full job details
09/07/2026
Full time
Job Description Job Description Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Senior Forensic Analyst Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred) Terms: Full-time Clearance: Active Top Secret required SalaryRange: $130-170k DOE Travel: Yes - travel to government sites as required Project Description This position supports a large-scale federal security operations program responsible for protecting enterprise networks, detecting and responding to intrusions, and conducting forensic investigations of suspected compromises. Forensic evaluations on this program are non-repetitive, fixed-duration engagements - each one is unique, consequential, and conducted under legal chain of custody requirements. The core challenge: conducting rigorous forensic evaluations of federal systems suspected of compromise - independently, under legal and evidentiary standards, with findings that inform both immediate response and broader intelligence community awareness. Position Description As a Senior Forensic Analyst at Revolutional, you conduct forensic evaluations of federal enterprise systems suspected of compromise. You are a senior practitioner operating with a high degree of independence - each engagement is distinct, and you bring the expertise to scope, execute, and deliver findings without a playbook written specifically for the situation in front of you. You maintain strict chain of custody in accordance with applicable federal and state legal requirements, conduct both host and network analysis to determine the full extent of compromise, and interface directly with the intelligence community to share and receive context that sharpens your findings. You may travel to government sites as required to support on-site forensic collection and analysis. What You Will Own End-to-end forensic evaluation of federal systems suspected of compromise Chain of custody integrity across all evidence collected and handled Host and network analysis to determine compromise scope and attacker activity Intelligence community interface and information sharing on active investigations Forensic project support across program-directed engagements On-site forensic collection and analysis at government facilities as required Responsibilities Conduct forensic evaluations of federal enterprise systems, endpoints, and media suspected of compromise; apply rigorous methodology and maintain chain of custody throughout in accordance with applicable federal and state law Perform host-based forensic analysis: disk imaging, file system examination, artifact recovery, memory analysis, and timeline reconstruction to determine attacker activity and compromise extent Conduct network forensic analysis: packet capture review, NetFlow analysis, log correlation, and lateral movement identification to establish the full scope of intrusion activity Produce thorough, legally defensible forensic reports documenting findings, methodology, evidence handling, and recommended response actions Interface with the intelligence community to share forensic findings, receive relevant threat context, and ensure investigations are informed by the current intelligence picture Support forensic projects as directed by program leadership, including surge support for high-priority or time-sensitive investigations Travel to government sites as required to conduct on-site evidence collection, system imaging, and forensic analysis Maintain current awareness of adversary TTPs, malware families, and forensic evasion techniques relevant to the federal threat landscape Contribute to development and refinement of forensic procedures, evidence handling standards, and investigation methodologies Coordinate with incident response, threat intelligence, and SOC teams to ensure forensic findings drive timely and effective response actions What You Bring (Requirements)Baseline Requirements Bachelor's degree in Computer Science, Digital Forensics, Information Security, or related field (or equivalent experience) 7 or more years of hands-on digital forensics experience, including complex investigations of suspected system compromises in federal or law enforcement environments Demonstrated experience maintaining chain of custody in accordance with federal and state legal requirements Active Top Secret clearance required Ability and willingness to travel to government sites as required Technical & Domain Capabilities Expert-level host forensics: disk and memory acquisition, file system analysis, artifact recovery, malware triage, and attack timeline reconstruction across Windows and Linux environments Hands-on network forensics: packet capture analysis, NetFlow, proxy and DNS log review, and identification of lateral movement, exfiltration, and command-and-control activity Proficiency with industry-standard forensic tools: EnCase, FTK, Autopsy, Volatility, Wireshark, or equivalent Experience conducting non-repetitive, fixed-duration forensic evaluations independently with minimal direction Established working relationships or experience interfacing with the intelligence community in the context of cybersecurity investigations Understanding of attacker TTPs, kill-chain methodology, and MITRE ATT&CK framework as applied to forensic investigations Experience producing forensic reports that meet legal and evidentiary standards for federal proceedings Core Strengths Technically expert and analytically independent - you scope and execute complex forensic investigations without needing the situation pre-defined for you Legally disciplined: chain of custody, evidence integrity, and documentation rigor are non-negotiable to you Credible intelligence community partner - you share findings with precision and incorporate external context effectively Composed under operational pressure; fixed-duration engagements with real consequences don't rattle your methodology or your output quality Certifications One or more of the following is strongly preferred: GCFE or GCFA (GIAC Forensics), EnCE (EnCase Certified Examiner), CFCE (Certified Forensic Computer Examiner), GCIH, or CISSP Nice to Have (Differentiators) GREM (GIAC Reverse Engineering Malware) or equivalent malware analysis credential Experience conducting forensic investigations at the TS/SCI level or within classified network environments Active TS/SCI clearance Prior direct experience working with or embedded in an intelligence community organization Background in mobile device forensics, cloud forensics, or industrial control system (ICS) forensics Experience supporting law enforcement actions or legal proceedings with forensic evidence and expert testimony _ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation and so much more! Check out our Revolutional LinkedIn to find out a little more about who we are and if we are the right next step for your career! Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional . click apply for full job details
Cybersecurity Analyst
Centurum Charleston, South Carolina
Job Description Job Description Centurum is seeking an experienced Endpoint Security Analyst for our team. This role is critical to our US Navy program's mission - supporting the installation, upgrade, testing, and cybersecurity of various tactical systems to ensure compliance with Department of Navy standards. DUTIES AND RESPONSIBILITIES: Assist in the management of an ESS in an enterprise environment. This includes managing policy configurations, managing point product updates, and managing the patching and configuration of the ESS server. Implement DoD-mandated security configurations, as well as industry best practices for ESS. Build, administer, and maintain a centralized ESS server supporting ACAS and ForeScout in an enterprise environment. Manage and administer all assets connected to the centralized ESS infrastructure. Conduct installation, configuration, and troubleshooting Endpoint Security System (ESS). Provide initial and supplemental training on Assured Compliance Assessment Solution (ACAS), system virtualization, Network Security, System Administration, and ESS. Provide remote and on-site cybersecurity and IT expertise to Fleet locations and support all levels of the help desk technical assistance. Deploy Trellix Endpoint Security, McAfee Data Loss Prevention Endpoint, and/or Trellix product policy tuning. Maintain the ePO server (automated tasks, task scheduler, database maintenance tasks, etc.). Maintain system patches, O/S, SQL, and ESS STIG compliance. Provide system administration and maintain operations of ESS 5.10 servers. REQUIRED SKILLS/YEARS OF EXPERIENCE: Expert level knowledge of cybersecurity principles and practices within a DoD environment. DoD 8570.1-M IAT II and/or IAM Level I requirements (Security+) Experience building and administering centralized ESS servers in support of ACAS and ForeScout. Hands-on experience running ACAS scans, analyzing results, and directly remediating plugin findings. Demonstrated experience performing STIG assessments and hardening systems. Experience developing scripts to automate cybersecurity and compliance workflows. Strong working knowledge of RMF processes with specific experience supporting RMF documentation and correcting OPORDs. Excellent analytical, problem solving, and communication skills. This is an on-site position Travel Required: 0% Work Location: Charleston, SC This position is required to have and maintain a Top Secret US DoD security clearance. REMARKS: Compensation: $115K - $125K annual salary. Compensation for positions at Centurum vary depending on a wide range of factors including, but not limited to, location, responsibilities, skill set, and level of experience. Benefits Full-time employees are eligible for the following benefits enrollment from their date of hire: Health Insurance - Centurum provides insurance for employee and dependent in a comprehensive package. Coverage for vision care is included. This option is available on a cost-sharing basis. Dental Insurance - Available in conjunction with Health Insurance for an additional cost. Provides oral maintenance care for employee and dependent. Basic Life Insurance - Company provided benefit for all full-time employees. Supplemental Life Insurance - Optional life insurance coverage to employees at group rates. Dependant Life Insurance - Optional coverage for dependents at a group rate. Long Term Disability Insurance - Optional coverage available to employees at group rates. Vacation and Sick Leave - Leave accrual is determined by length of service. Holidays - The company observes ten paid holidays each year. Retirement 401(k) Plan - Centurum's corporate benefits package includes 401K with a company bi-weekly match and a year-end profit sharing company match for all eligible employees. Investments can be made into selected funds under this plan. Centurum is an Equal Opportunity Employer, providing employment opportunities for all persons without discrimination on the basis of race, color, religion, sex, sexual orientation, national origin, age, disability, marital status, citizenship or any other characteristic protected by U.S. law. Centurum makes reasonable accommodations for persons with disabilities. Powered by JazzHR rr5zj6IsfU
09/07/2026
Full time
Job Description Job Description Centurum is seeking an experienced Endpoint Security Analyst for our team. This role is critical to our US Navy program's mission - supporting the installation, upgrade, testing, and cybersecurity of various tactical systems to ensure compliance with Department of Navy standards. DUTIES AND RESPONSIBILITIES: Assist in the management of an ESS in an enterprise environment. This includes managing policy configurations, managing point product updates, and managing the patching and configuration of the ESS server. Implement DoD-mandated security configurations, as well as industry best practices for ESS. Build, administer, and maintain a centralized ESS server supporting ACAS and ForeScout in an enterprise environment. Manage and administer all assets connected to the centralized ESS infrastructure. Conduct installation, configuration, and troubleshooting Endpoint Security System (ESS). Provide initial and supplemental training on Assured Compliance Assessment Solution (ACAS), system virtualization, Network Security, System Administration, and ESS. Provide remote and on-site cybersecurity and IT expertise to Fleet locations and support all levels of the help desk technical assistance. Deploy Trellix Endpoint Security, McAfee Data Loss Prevention Endpoint, and/or Trellix product policy tuning. Maintain the ePO server (automated tasks, task scheduler, database maintenance tasks, etc.). Maintain system patches, O/S, SQL, and ESS STIG compliance. Provide system administration and maintain operations of ESS 5.10 servers. REQUIRED SKILLS/YEARS OF EXPERIENCE: Expert level knowledge of cybersecurity principles and practices within a DoD environment. DoD 8570.1-M IAT II and/or IAM Level I requirements (Security+) Experience building and administering centralized ESS servers in support of ACAS and ForeScout. Hands-on experience running ACAS scans, analyzing results, and directly remediating plugin findings. Demonstrated experience performing STIG assessments and hardening systems. Experience developing scripts to automate cybersecurity and compliance workflows. Strong working knowledge of RMF processes with specific experience supporting RMF documentation and correcting OPORDs. Excellent analytical, problem solving, and communication skills. This is an on-site position Travel Required: 0% Work Location: Charleston, SC This position is required to have and maintain a Top Secret US DoD security clearance. REMARKS: Compensation: $115K - $125K annual salary. Compensation for positions at Centurum vary depending on a wide range of factors including, but not limited to, location, responsibilities, skill set, and level of experience. Benefits Full-time employees are eligible for the following benefits enrollment from their date of hire: Health Insurance - Centurum provides insurance for employee and dependent in a comprehensive package. Coverage for vision care is included. This option is available on a cost-sharing basis. Dental Insurance - Available in conjunction with Health Insurance for an additional cost. Provides oral maintenance care for employee and dependent. Basic Life Insurance - Company provided benefit for all full-time employees. Supplemental Life Insurance - Optional life insurance coverage to employees at group rates. Dependant Life Insurance - Optional coverage for dependents at a group rate. Long Term Disability Insurance - Optional coverage available to employees at group rates. Vacation and Sick Leave - Leave accrual is determined by length of service. Holidays - The company observes ten paid holidays each year. Retirement 401(k) Plan - Centurum's corporate benefits package includes 401K with a company bi-weekly match and a year-end profit sharing company match for all eligible employees. Investments can be made into selected funds under this plan. Centurum is an Equal Opportunity Employer, providing employment opportunities for all persons without discrimination on the basis of race, color, religion, sex, sexual orientation, national origin, age, disability, marital status, citizenship or any other characteristic protected by U.S. law. Centurum makes reasonable accommodations for persons with disabilities. Powered by JazzHR rr5zj6IsfU

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board