> Markdown version of [/jobs/ext/2985137-remote-cyber-security](https://www.wearedevelopers.com/jobs/ext/2985137-remote-cyber-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Remote Cyber Security - **Company:** Insight Global - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Bash Shell, Cyber Security, Computer Telephony Integration, Linux, Digital Forensics, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Network Forensics, Network Protocols, Windows PowerShell, Cloud Services, Phishing, Security Information and Event Management, TCP/IP, Scripting, Cloud Platform System, Mitre Att&ck, Malware, HybridCloud, Amazon Virtual Private Cloud (VPC), Information Technology, Cybercrime, Tenable Nessus, CIS Benchmarks, Purple Team (Cyber Security), Splunk, Servicenow, Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3394172561&tx=FP10198LFU&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Perform advanced EDR analysis, including alert triage, threat detection, behavioral rule tuning, IOC investigation, and endpoint telemetry enrichment., * AWS proficiency in analyzing security events within AWS environments, including CloudTrail, VPC Flow Logs, GuardDuty, and IAM policies * AWS Familiarity with compliance and audit frameworks: NIST CSF, 800-53, OMB M-21-31, CIS Benchmarks, STIGs * Knowledge of vulnerability scanning tools (e.g., Tenable Nessus) and CVE exposure analysis * Experience collaborating with cyber threat intelligence and/or red teams * Experience in digital forensics, malware analysis, or purple team operations * Experience with Case Management System (e.g., ServiceNow) * Experience with SIEM (e.g., Splunk) * Experience using SOAR platforms for alert triage and response automation * Solid understanding of Windows and Linux operating system internals and log analysis * Strong grasp of network protocols, TCP/IP, and common attack vectors * Familiarity with scripting (e.g., PowerShell, Python, Bash) and automation workflows * Experience with threat hunting, IOC analysis, or MITRE ATT&CK-based detection * Understanding of identity and access management (IAM) risks in cloud environments * Experience improving SOC processes, detection logic, architecture, or playbooks * Ability to communicate findings clearly-verbally and in writing-to technical and non-technical audiences - Played a key role in managing a major security incident, including rapid triage, root cause analysis, coordinated containment actions, and cross-team communication. * Demonstrated the ability to operate effectively under pressure, making sound technical decisions while balancing business impact and urgency. * Skilled in reconstructing attack paths using log analysis, network forensics, endpoint telemetry, and cloud service investigations. * Collaborated closely with engineering, IT, and leadership to ensure timely remediation and clear documentation throughout the incident lifecycle. * Contributed to post-incident reporting, lessons learned, and improvements to detection rules, playbooks, and security controls based on incident findings. * Proven capability to interpret complex threat behaviors and apply frameworks like MITRE ATT&CK to understand adversary techniques encountered during the incident. * Strengthened SOC readiness by helping refine escalation procedures, communication channels, and response strategies following the major event., * Degree educated or equivalent, preferably in a computer science related subject * AWS Certified * GIAC Certified (e.g., GCIH, GCIA, GCFA, GNFA, GDAT) * OffSec Certified * 8-10 years experience ## Description We are seeking three highly motivated and experienced Cyber Security Specialist to support day, swing, and night shift operations within our 100% remote 24/7/365 Security Operations Center (SOC). You will monitor, analyze, investigate, and respond to threats across hybrid cloud and on-prem environments. This role is ideal for analysts with a strong investigative mindset, technical depth, and a passion for continuous learning., * Support EDR platform administration by managing agent health and deployment, maintaining integration with SIEM and other telemetry pipelines, coordinating policy updates, and partnering with SysAdmins to troubleshoot endpoint and infrastructure-level issues affecting EDR visibility. * Conduct digital forensics during incident response by acquiring, preserving, and analyzing endpoint artifacts (e.g., memory, disk, registry, logs); assist with root cause analysis and ensure forensic evidence in accordance with legal and procedural requirements. * Provide engineering-focused support on SOC architecture improvements to increase visibility, data fidelity, and detection capabilities across hybrid environments. * Perform threat detection, log analysis, and anomaly identification across on-premises and cloud workloads (AWS required). * Conduct initial incident response and assist with investigations into malware, phishing, lateral movement, privilege misuse, and data exfiltration. * Apply threat intelligence to enrich alerts and uncover TTPs using the MITRE ATT&CK framework. * Participate in threat hunting missions based on hypotheses, intel feeds, and environmental knowledge. * Collaborate with engineering, system administrators, and cyber stakeholders to contain and remediate threats. * Support compliance efforts by ensuring audit trails, access logs, and investigative artifacts are collected and preserved. * Maintain situational awareness through active monitoring of CTI sources, advisories, and vulnerability disclosures. * Provide summary reports and handoff briefings at the end of each shift. * Document investigative activities, incident details, troubleshooting steps, and evidence in the case management system; create, update, and escalate tickets in accordance with established procedures and escalation guidelines. * Provide after-hours operational support by monitoring incident intake channels, performing initial triage of operational and security events, coordinating with on-call resources, and ensuring timely escalation and handoff of incidents. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture)