Security Engineer III, Exploitation Analyst / Incident Responder (TS Clearance)

Deloitte T.T.L.
Arlington, VA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Apple Mac Systems Software System Penetration Testing Bash Shell CompTIA Security+ Computer Networks Linux Digital Forensics Intrusion Detection Systems Python (Programming Language) Log Analysis Network Forensics
+11 more
Network Protocols Windows PowerShell Red Team (Cyber Security) Reverse Engineering Security Information and Event Management Scripting Malware IDA Pro Cybercrime Cyber Warfare Vulnerability Analysis

Job description

Experteer Overview In this role you will help clients defend against evolving cyber threats by analyzing threat activity, investigating incidents, and strengthening security postures across enterprise environments. You work with cross-functional teams to translate technical findings into actionable recommendations, contributing to the Cyber Defense & Resilience capability. You will engage in threat intelligence, exploitation analysis, and incident response to drive timely, risk-based security improvements. This is a hands-on, impact-focused position with a clear connection to client outcomes and incident readiness. Compensation / Benefits * Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity * Investigate security incidents, collect and analyze logs, memory artifacts, network traffic, and support containment, eradication, and recovery activities * Identify and assess vulnerabilities in systems, networks, and applications and recommend remediation actions based on risk and exploitability * Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments * Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders Tasks * Bachelor’s degree in a related technical field * Active Top-Secret Clearance * 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response * Experience analyzing APTs, malware, exploitation techniques, and using reverse engineering tools (IDA Pro or Ghidra) * Experience with vulnerability assessments, penetration testing, or red team activities * Experience with network traffic analysis, log analysis, digital forensics across Windows, Linux, macOS, and common network protocols * Scripting experience (Python, PowerShell, Bash) and security monitoring tools (SIEM, IDS/IPS, EDR) * Willingness to travel up to 20% and work onsite up to 5 days a week * Industry certifications such as GIAC, CISSP, or CompTIA Security+ * Legal authorization to work in the United States without sponsorship Key requirements *

Requirements

Willingness and recommend remediation actions based on risk and exploitability * Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments * Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders Tasks * Bachelor’s degree in a related technical field * Active Top-Secret Clearance * 2+ years of experience in cyber exploitation analysis, threat intelligence, or incident response * Experience analyzing APTs, malware, exploitation techniques, and using reverse engineering tools (IDA Pro or Ghidra) * Experience with vulnerability assessments, penetration testing, or red team activities * Experience with network traffic analysis, log analysis, digital forensics across Windows, Linux, macOS, and common network protocols * Scripting experience (Python, PowerShell, Bash) and security monitoring tools (SIEM, IDS/IPS, EDR) * a risk-based to travel up to 20% and work onsite up to 5 days a week * Industry certifications such as GIAC, CISSP, or CompTIA Security+ * Legal authorization to work in the United States without sponsorship Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all