Secret-cleared Tier 3 DCO Senior Analyst / Threat Hunter (Malware)

Valiant Solutions, LLC
Charleston, SC, United States
13 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Cyber Security Digital Forensics Intrusion Detection Systems Malware Information Technology 3-tier Architectures Purple Team (Cyber Security)

Job description

Tier 3 DCO Senior Analyst / Threat Hunter (Malware) is responsible for leading complex incident response, conducting proactive threat hunting, and enhancing detection capabilities within a Cybersecurity Service Provider (CSSP) environment. The analyst oversees incident analysis, coordinates with internal and external stakeholders, leads purple team exercises, and drives improvements to detection and response capabilities. This position requires advanced expertise, operational leadership, and strict compliance with CJCSM 6510.01B standards., * Lead incident response efforts, including analysis, mitigation, and reporting of significant incidents per CJCSM 6510.01B.

  • Manage incident response campaigns by developing strategies, coordinating multi-team efforts, and ensuring comprehensive resolution and reporting.
  • Conduct proactive threat hunting to identify advanced threats and network vulnerabilities.
  • Lead purple team exercises in collaboration with red and blue teams to evaluate and enhance detection and response capabilities.
  • Evaluate and refine detection mechanisms, including IDS/IPS signatures and log correlation rules, to improve accuracy and reduce false positives.
  • Perform advanced network and host-based digital forensics on Windows and other operating systems to support investigations.
  • Coordinate with reporting agencies and subscriber sites for comprehensive incident analysis and reporting.
  • Develop and maintain internal SOP documentation, ensuring alignment with CJCSM 6510.01B and applicable directives.
  • Work with a team to provide 24/7 support for incident response, including non-core hours, and mentor junior analysts.
  • Participate in program reviews, product evaluations, and onsite certification assessments.
  • Work four 10-hour shifts (Sunday-Wednesday or Wednesday Saturday); shift placement at management’s discretion.
  • Surge support may be required to support incident response actions.
  • Up to 10% travel may be required, to include OCONUS locations.

Requirements

Clearance Required: Active Secret

Education Requirement: Bachelor’s Degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, OR Mathematics with a concentration in computer science or equivalent

Certification Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification

Required Experience:

  • 5 years experience supporting CSSP or similar SOC technical role.
  • Comprehensive knowledge of CJCSM 6510.01B and incident response procedures.
  • In depth expertise with IDS/IPS solutions, including signature development and optimization.
  • Extensive experience performing digital forensics across multiple operating systems., Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:24 min

Installing premium packages using the Store CLI

Noraa Junker Noraa Junker · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all