Host Based Systems Analyst III

Solutions³ LLC
Arlington, VA, United States
5 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Bash Shell Microsoft Online Services Software as a Service Cloud Computing Cloud Database Cloud Engineering Cyber Security Computer Engineering
+22 more
Computer Forensics Digital Forensics Infrastructure as a Service (IaaS) Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Network Security Platform as a Service (PAAS) Windows PowerShell Azure Active Directory Workflow Management Systems Scripting Google Cloud Cloud Platform System Office365 Amazon Virtual Private Cloud (VPC) Cloudformation Kubernetes Information Technology Terraform Azure Resource Manager Docker

Job description

Solutions³ LLC is supporting our prime contractor and their U.S. Government customer on a large mission-critical provide remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based, and cloud-based cybersecurity analysis capabilities. Personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. Solutions³ LLC is seeking Cyber Network Defense Analysts (CNDA) with Cloud Forensics experience to support this critical customer mission., * Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.

  • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
  • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
  • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
  • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
  • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
  • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.

Requirements

  • Must be a US Citizen
  • Must have an active TS/SCI clearance
  • Must be able to obtain DHS Suitability prior to starting employment
  • 5+ years of direct relevant experience in cyber forensic investigations using leading tools and techniques, * Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.
  • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
  • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
  • Knowledge of AWS, IAM, and best practices for cloud identity security.

Desired Skills:

  • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
  • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
  • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).

Desired Certifications: One or more of the following certifications: GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS or Microsoft Cloud/Security certifications Required Education: BS in Computer Science, Cybersecurity, Computer Engineering or related degree; or HS Diploma and 7+ years of relevant experience Powered by JazzHR

Solutions3

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

7:32 min

Troubleshooting syntax roadblocks and achieving early cloud certification

Megha Kadur · LIVE

Videos

See all

Related articles

See all