Cyber Network Defense Analyst (CNDA) IV - Cloud Forensics

Argo Cyber Systems
United States
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Amazon Web Services Microsoft Azure Bash Shell Software as a Service Cloud Computing Cyber Security Computer Engineering Digital Forensics Infrastructure as a Service (IaaS) Identity and Access Management Python (Programming Language)
+19 more
Network Security Microsoft Security Essentials Platform as a Service (PAAS) Windows PowerShell Azure Active Directory Google Cloud Office365 Mitre Att&ck Multi-Cloud Cyber Threat Analysis Amazon Virtual Private Cloud (VPC) Cloudformation Kubernetes Information Technology Microsoft Sentinel Terraform Azure Resource Manager Docker Vulnerability Analysis

Job description

Argo Cyber Systems is seeking Cyber Network Defense Analysts (CNDA) with deep Cloud Forensics expertise to support a high-visibility federal mission. The CNDA will lead advanced investigations into sophisticated intrusions across hybrid and multi-cloud environments, identifying attacker tactics, techniques, and procedures (TTPs), correlating artifacts, and driving containment and remediation actions in partnership with government cyber teams., * Conduct end-to-end forensic acquisition and analysis across on-premises, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, Google Cloud Platform, SaaS).

  • Investigate identity-based and credential-abuse incidents targeting cloud control planes and hybrid identity infrastructure.
  • Correlate cloud telemetry (Azure Activity Logs, AWS CloudTrail, Google Cloud Platform Logs, VPC Flow Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs).
  • Develop and deploy automated detection logic, threat-hunting scripts, and analytical playbooks using Microsoft Sentinel, Defender, AWS GuardDuty, and Google Cloud Platform Chronicle.
  • Produce comprehensive technical and executive-level reports, integrating findings across endpoints, networks, and cloud assets to inform threat containment and strategic recommendations.
  • Support continuous improvement of incident response procedures, forensics workflows, and threat-hunting operations.
  • Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen enterprise detection and response posture.

Requirements

  • U.S. Citizenship and active TS/SCI clearance (with ability to obtain DHS EOD Suitability).
  • Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR).
  • Proven expertise in cloud forensics, identity security, and hybrid infrastructure defense.
  • Proficiency in M365/Azure AD, AWS IAM, and SaaS investigative methodologies.
  • Deep understanding of SaaS/PaaS/IaaS architectures, including common attack vectors and defensive measures.
  • Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting.

Desired Qualifications

  • Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript.
  • Familiarity with Terraform, Kubernetes, Docker, CloudFormation, or Azure Resource Manager for automation and orchestration.
  • Understanding of MITRE ATT&CK for Cloud and adversary emulation techniques.
  • Strong communication and collaboration skills for working across multidisciplinary teams.

Education

  • Bachelor’s Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field or

  • High School Diploma and 10+ years of directly relevant DFIR experience.

Preferred Certifications

  • GIAC Cloud Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
  • AWS and Microsoft security/cloud certifications (e.g., Azure Security Engineer, AWS Security Specialty)

About the company

At Argo, you’ll be part of a mission-driven, veteran-founded cybersecurity team protecting America’s most critical systems. We combine hands-on technical excellence with operational precision to outpace the threat. Join us to defend, detect, and innovate at the cyber edge.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all