> Markdown version of [/jobs/ext/1449313-cyber-defense-analyst-3-cda3](https://www.wearedevelopers.com/jobs/ext/1449313-cyber-defense-analyst-3-cda3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Analyst 3 (CDA3) - **Company:** RealmOne - **Location:** Columbia, MD, United States - **Experience:** Expert - **Salary:** $197,000.0 - $227,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CentOS, Linux, Event Logging, Intrusion Detection and Prevention, Microsoft Operating Systems, Windows PowerShell, Red Hat Enterprise Linux, Security Information and Event Management, TCP/IP, Tcpdump, Wireshark, Cyber Warfare, Splunk - **Published:** July 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/85425878/1 ## About the Role * Eight (8) years Cyber Defense Analyst experience. * Experience with endpoint detection and response technologies. * Two (2) years TCP/IP fundamentals experience. * Two (2) years Wireshark or tcpdump experience. * Three (3) years SIEM experience. * Three (3) years threat analysis and incident response experience. * Experience investigating host-based intrusions and malware activity. * 8x5 schedule. Certifications Required: * DoD 8570 compliance with CSSP Analyst baseline certification * Information Assurance Technical (IAT) Level I or Level II certification * Computing Environment (CE) certification. The CE certification requirements can be fulfilled with either Microsoft OS, Cent OS/Red Hat OS CE certifications. * Global Information Assurances Certification (GIAC) Certified Incident Handler (GCIH) certificate or Certified Intrusion Analyst (GCIA) certificate. * Splunk software training course "Fundamentals 1" Position requires active Security Clearance with appropriate Polygraph ## Description RealmOne was built on the principle that people matter first and foremost. We believe in providing a strong work/life balance by investing in our employees and encouraging professional and personal growth. We do this by offering exceptional benefits, flexible schedules, and the tools necessary to achieve success through paid training, mentoring, and the opportunity to work alongside top-notch industry professionals. Join us on this journey as we execute this mission-critical contract providing high-end analytics and data science services within the REALM of cybersecurity. Your effort and expertise are crucial to the success and execution of this impactful mission that is critical in ensuring mission success through Security Engineering, Risk Management and Assessment, and Insider Threat Analysis, by improving, protecting, and defending our Nation's Security., The Cyber Defense Analyst III (Endpoint Security) is a senior SOC role responsible for defending enterprise endpoints against advanced threats through monitoring, detection engineering, incident response, and endpoint-focused threat hunting. This position emphasizes deep expertise in endpoint detection and response (EDR), host-based analysis, and adversary behavior on Windows and Linux systems. The Cyber Defense Analyst 3 shall possess the following capabilities: * Monitor and analyze endpoint telemetry for indicators of malicious activity. * Investigate host-based intrusions, malware execution, and persistence mechanisms. * Analyze Windows and Linux endpoint artifacts, processes, registry activity, and event logs. * Utilize EDR platforms to identify, contain, and remediate threats. * Conduct forensic analysis of compromised systems and malicious processes. * Identify PowerShell abuse, credential theft, and endpoint exploitation techniques. * Analyze attacker persistence and lateral movement across enterprise environments. * Correlate endpoint and SIEM data to support threat investigations. * Support cyber incident response and remediation activities. * Perform endpoint-focused threat hunting operations. * Mentor junior analysts and support operational best practices. * Participate in after-action reviews and analytical validation activities. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)