Cybersecurity Analyst

BrightForge Innovation LLC
Hyattsville, MD, United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$90,985.0 - $94,981.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Systems Engineering Microsoft Azure Bash Shell Cloud Computing Security Communications Protocols CompTIA Security+ Cyber Security Domain Name System (DNS) Multi-Factor Authentication Event Logging
+35 more
Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Network Security Pcap Log Analysis Routing Windows PowerShell Phishing Security Information and Event Management SQL Injection Syslog TCP/IP Tcpdump Traffic Analysis Wireshark Software Vulnerability Management EndPointSecurity Scripting Transport Layer Security Cloud Platform System Mitre Att&ck QRadar Malware Cyber Threat Analysis Firewalls (Computer Science) Cross-Site Scripting (XSS) Falcon Platform Information Technology Nessus Microsoft Sentinel Splunk SentinelOne Expertise Qualys Vulnerability Analysis

Job description

We are looking for an experienced Cybersecurity Analyst to monitor, detect, and respond to security threats across our IT infrastructure, networks, and cloud environments. In this role, you will analyze security telemetry, investigate security incidents, perform vulnerability management, and implement defensive controls to protect our systems from unauthorized access, malware, and data breaches., As a Cybersecurity Analyst, you will serve as a frontline defender of our technical environment. You will work within our Security Operations Center (SOC) framework to monitor security event logs, evaluate threat intelligence, conduct root-cause analysis on security alerts, and execute incident response procedures., * Threat Monitoring & Analysis: Monitor security logs, alerts, and event streams across network firewalls, endpoint protection systems, IAM platforms, and cloud environments using SIEM tools (e.g., Splunk, Microsoft Sentinel).

  • Incident Response & Triage: Investigate security incidents, perform initial containment, isolate compromised endpoints, and execute containment/remediation protocols following incident response playbooks.
  • Vulnerability Assessment: Conduct regular vulnerability scans across infrastructure and applications using tools like Nessus or Qualys; prioritize and track patching efforts with IT engineering teams.
  • Threat Intelligence Integration: Evaluate actionable threat intelligence feeds, Indicator of Compromise (IoC) data, and emerging CVEs to update security rules and detection signatures.
  • Security Controls & Hardening: Collaborate with system administrators and network engineers to enforce baseline security configurations, principle of least privilege access, and multi-factor authentication (MFA).
  • Documentation & Compliance: Document security incidents, root-cause analyses, and post-incident reviews; support compliance audits aligned with standards such as NIST CSF, ISO 27001, or SOC 2.

Requirements

This position requires hands-on experience with SIEM platforms, network protocol analysis, endpoint detection tools, and security remediation workflows in accordance with established framework standards., * Experience: Minimum 2-4 years of technical experience as a Cybersecurity Analyst, SOC Analyst, or Information Security Specialist.

  • SIEM & Log Analysis: Hands-on experience operating SIEM systems (e.g., Splunk, Sentinel, QRadar) to write detection queries, analyze Syslog/Windows Event logs, and identify suspicious activity.
  • Networking & Security Fundamentals: Deep understanding of TCP/IP stack, DNS, routing/switching concepts, firewalls, VPNs, TLS/SSL, and common attack vectors (e.g., Phishing, Ransomware, SQLi, XSS).
  • Endpoint Protection: Direct experience with Endpoint Detection and Response (EDR/XDR) platforms (e.g., CrowdStrike, Defender for Endpoint, SentinelOne).
  • Packet & Traffic Analysis: Proficiency using tools like Wireshark or tcpdump to inspect PCAP files and trace malicious network behavior.
  • Communication & Incident Management: Ability to produce clear incident triage reports and communicate mitigation steps effectively during active incident response scenarios.

Technical Competencies (Preferred)

  • Active industry certifications such as CompTIA Security+, CySA+, GIAC (GSEC/GCIH), or Certified Ethical Hacker (CEH).
  • Scripting experience in Python, PowerShell, or Bash for automating log parsing and security tasks.
  • Knowledge of cloud security architecture and threat monitoring in AWS, Azure, or GCP environments.
  • Practical familiarity with the MITRE ATT&CK framework to map adversary tactics and techniques.

Benefits & conditions

  • 401(k)
  • Dental insurance
  • Health insurance
  • Life insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

2:30 min

Discovering and instrumenting services using systemd process enumeration

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all