Cyber Security Analyst: Data Sanitization & Spill Cleanup Specialist

Savannah River National Laboratory
Aiken, SC, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Computer Networks Digital Forensics Image Management Security Information and Event Management Enterprise Search Forensic Toolkit Data Processing Imager Information Technology Encase Splunk

Job description

We are seeking a highly methodical, detail-oriented Cyber Security Analyst specializing in Data Sanitization and Spill Cleanup. In this critical role, you will be responsible for managing, executing, and documenting the remediation of classified or sensitive data spills (unauthorized disclosures/data contamination) across various network enclaves. This position demands an exceptional level of precision, a strict adherence to federal and organizational handling procedures, and outstanding communication skills to coordinate containment and recovery efforts with technical teams, affected end-users, and management., * Spill Containment & Isolation: Immediately respond to reports of data spills or classified contamination; locate, isolate, and restrict access to affected systems, mailboxes, and network shares to prevent further exposure.

  • Data Sanitization & Remediation: Execute rigorous sanitization, purging, and overwriting procedures on storage media, endpoints, and server environments in strict compliance with NIST SP 800-88 guidelines and site-specific policies.

  • Incident Investigation & Tracking: Perform detailed forensic tracking to determine the origin, scope, and pathway of the spilled data, compiling meticulous incident timelines and post-cleanup reports.

  • Interdepartmental Communication: Work directly with the Security Incident Program Manager during an active spill event to serve as a clear-voiced liaison, translating complex technical containment instructions to non-technical users and providing concise situational updates to leadership.

  • Tooling & Log Auditing: Use enterprise search, SIEM tools, and endpoint management consoles to verify that all instances of spilled data have been identified and successfully purged from the environment.

  • Policy & Procedure Maintenance: Develop, update, and test standard operating procedures (SOPs) and incident response playbooks for data spill remediation.

Requirements

  • BS/BA Cybersecurity, Information Assurance, Computer Science, or equivalent practical experience.
  • 4-6 yrs of experience in cybersecurity, system administration, or digital forensics, with a demonstrated focus on media sanitization or security incident remediation.
  • Maintain appropriate level government security clearance.
  • The candidate must be able to remain calm under pressure, draft highly professional incident reports, and direct staff politely and assertively during high-stress cleanup operations.
  • Ability to obtain and maintain an active DOE security clearance
  • US Citizenship required
  • Complies with all policies and standards., * In-depth knowledge of NIST SP 800-88 (Guidelines for Media Sanitization), data handling standards, and classified spill containment frameworks.
  • Digital Forensics & Imaging: Experience with site-funded investigative and forensic imaging tools such as EnCase Forensic / Endpoint Security, FTK (Forensic Toolkit), Magnet Axiom, and FTK Imager to audit, recover, and validate the complete remediation of spilled media.
  • Enterprise Search & SIEM: Practical experience utilizing Splunk or other log aggregation platforms to query network, file, and system logs to track file movement.
  • Endpoint & File Security: Experience with Microsoft Defender (XDR and Purview/GCC High) or similar endpoint management platforms to locate files, execute remote isolations, and run targeted deletion commands.
  • Email & Collaboration Security: Experience navigating email administration consoles (e.g., Exchange Online/M365 Security & Compliance Center, Microsoft Purview, or Proofpoint) to search for, quarantine, and permanently purge unauthorized email content.

Benefits & conditions

Savannah River National Laboratory (SRNL) is a multi-program laboratory applying state of the art science and practical, high-value, cost-effective solutions to complex technical problems to protect the nation. Located at the U.S. Department of Energy’s (DOE) Savannah River Site (SRS) in Aiken SC, the laboratory develops and deploys innovative technologies to address some of the nation’s environmental, energy, and national security challenges.

Battelle Savannah River Alliance (BSRA) is constantly assessing trends to provide the best possible benefits to our workforce. We also negotiate cost effective premiums that will meet the needs of our evolving workforce.

Some of the *Benefits offered to employees include:

*Benefits vary based upon employment status

  • Highly competitive Medical, Dental, and Vision options including HSA options with company provided seed
  • Short- & Long-Term Disability (company paid)
  • Life Insurance Non-Contributary 1X salary (company paid)
  • AD&D Non-contributary 1x salary (company paid)
  • Savings & Investment plan: *

  • Qualified Non-Elective Company Contribution of 5% each pay period with immediate vesting
  • Company match 50 cents/dollar up to 8% (5 yrs. vesting in company match)
  • Contributory Life Insurance up to 5x Salary with $1M Cap
  • Contributory AD&D (employee, spouse and children)
  • Paid Time Off
  • Employee Assistance Plan
  • SRNL offers a competitive relocation package to ease the transition process. Domestic and international relocation assistance is available for certain positions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:01 min

Live text-to-image generation and image editing implementation

Joerg Krall Joerg Krall · WWC Europe 2026

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:52 min

Directing image generation using contrastive language image pre-training

Ekaterina Sirazitdinova · LIVE

Videos

See all

Related articles

See all