Cyber Security Engineer III

System One
Springfield, VA, United States
5 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Digital Forensics Forensics Tools (Digital Forensics Software) Reverse Engineering Scripting Malware Information Technology Cybercrime Cyber Warfare

Job description

System One IT is seeking a Cyber Security Engineer to support a mission critical cyber operations program in Springfield, VA.

This role is focused on cyber incident response, investigation, containment, documentation, and coordination across Government and contractor teams. The Cyber Security Engineer will support the full lifecycle of security incidents, including triage, analysis, response actions, reporting, and recommendations to improve future defensive cyber operations.

The ideal candidate will have hands on experience in incident response, CSOC or SOC operations, digital forensics, malware analysis, indicator development, and cyber incident reporting within a DoD, Intelligence Community, or federal cyber environment.

Responsibilities

  • Coordinate and support cyber incident response activities across Government and contractor teams

  • Perform analysis and documentation of response actions, including containment, remediation, and recovery activities

  • Support containment efforts such as IP blocks, domain blocks, account disablement, and other approved defensive measures

  • Analyze host, server, network, memory, and system artifact data to support incident investigations

  • Develop and identify indicators of compromise and share findings with appropriate cybersecurity stakeholders

  • Support malware analysis, signature development, and adversary attribution efforts

  • Build incident timelines, briefings, reports, and other documentation for stakeholders

  • Document all actions and analysis in approved ticketing and reporting systems with sufficient detail for reconstruction of events

  • Coordinate with CSOC Tier 1 and Tier 2 teams to remediate discrepancies and recommend actions to prevent recurrence

  • Support Government directed Cyber Incident Response Team activities as required

  • Develop and coordinate courses of action with Government and contractor stakeholders

  • Conduct quality control reviews of closed CSOC tickets to ensure accurate analysis, categorization, documentation, and notification

  • Provide input for daily and weekly CSOC reporting, including significant activity reports, operations updates, and status reports, System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan., System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Requirements

Clearance Requirement: Active TS/SCI with ability to obtain a polygraph, * Active TS/SCI clearance

  • Ability to obtain a polygraph

  • Bachelor’s degree or 6 plus years of cybersecurity experience

  • Experience supporting cyber incident response, CIRT, CSOC, SOC, DFIR, threat hunting, or defensive cyber operations

  • Experience performing incident triage, investigation, containment, remediation, and reporting

  • Familiarity with host, server, network, memory, or system artifact analysis

  • Experience developing or identifying indicators of compromise

  • Experience documenting incident timelines, analysis, actions taken, and recommendations

  • Understanding of DoD cyber operations, incident handling, and reporting processes

  • DoD 8570 / 8140 IAT Level II certification

  • Ability to meet CSSP Incident Responder requirements

Preferred Qualifications

  • Master’s degree

  • IAT Level III certification

  • Experience supporting NGA, DoD, Intelligence Community, or federal cybersecurity programs

  • Experience with malware analysis or reverse engineering

  • Experience with digital forensics tools and processes

  • Experience with JIMS, ICMS, or similar Government incident reporting systems

  • Experience developing scripts, tools, or automation to collect and analyze cyber incident data

  • Certifications such as CySA+, GCIH, GCIA, GCFA, GCFE, CEH, CISSP, or similar

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all