> Markdown version of [/jobs/ext/2243373-advanced-cyber-security-analytics-engineer](https://www.wearedevelopers.com/jobs/ext/2243373-advanced-cyber-security-analytics-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Advanced Cyber Security Analytics Engineer - **Company:** D2 Technical Services - **Location:** St. Louis, MO, United States - **Experience:** Expert - **Salary:** $90,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Cloud Computing, Cyber Security, Data Mining, Issue Tracking Systems, Python (Programming Language), Network Protocols, Performance Tuning, Windows PowerShell, Regular Expressions, Security Information and Event Management, Data Lakes, Data Analytics, Purple Team (Cyber Security), Cyber Warfare - **Published:** August 26, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9118892/advanced-cyber-security-analytics-engineer ## About the Role * Must be a US Citizen with an Active TS/SCI. * 8+ years of related advanced cyber security analytics work experience. * Must have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst. * Experience with data mining or building queries in a SIEM. * Strong understanding of signature development and tuning. * Strong understanding of network protocols and analysis with protocol analyzers. * Knowledge of static file signatures, i.e. "magic numbers" and how it applies to developing countermeasures for files in transit and that reside locally on a host. * Good working knowledge of regular expressions. Preferred Skills: * Comfortable in a hex editor. * Ability to write python/bash/powershell scripts. * Ability to analyze each use case, as it pertains to detection logic, and identify the corresponding capability. * Good understanding of Purple Team Tactics. * Familiarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining. ## Description Reporting to the Lead of Focused Operations, under the Branch Chief of Defensive Cyber Operations, you will be tasked with developing and maintaining defensive countermeasures for the enterprise. Working within a Fusion model, will collaborate with other teams within Focused Operations with the distinct task of proactively preventing a successful compromise and eradicating persistent adversaries already in the enterprise. This will be done through various means such as reviewing future and past intelligence reports, reviewing incident reports, through regular Purple Teaming exercises, and continuously validating Defensive Countermeasures already deployed. More about your role: * Analyzes trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents and develop or tune rules/signatures/scripts as needed. * Coordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts. * Coordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems and develop or tune rules/signatures/scripts as needed. * Correlates and analyzes precursors to incidents and develop or tune rules/signatures/scripts as needed. * Will collaborate with the Cyber Data Analytics team to achieve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed * Work with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage. * Documents all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis; * Provide input to reoccurring meetings and briefings as required. ## Related Videos - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Empowering Retail Through Applied Machine Learning](https://www.wearedevelopers.com/videos/976-empowering-retail-through-applied-machine-learning) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Data Mining Accessibility](https://www.wearedevelopers.com/videos/802-data-mining-accessibility) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)