Cyber Defense Analyst 3 (CDA3)

RealmOne
Maryland, United States
21 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows CentOS Linux Event Logging Intrusion Detection and Prevention Microsoft Operating Systems Windows PowerShell Red Hat Enterprise Linux Security Information and Event Management TCP/IP Tcpdump Wireshark
+2 more
Cyber Warfare Splunk

Job description

RealmOne was built on the principle that people matter first and foremost. We believe in providing a strong work/life balance by investing in our employees and encouraging professional and personal growth. We do this by offering exceptional benefits, flexible schedules, and the tools necessary to achieve success through paid training, mentoring, and the opportunity to work alongside top-notch industry professionals. Join us on this journey as we execute this mission-critical contract providing high-end analytics and data science services within the REALM of cybersecurity. Your effort and expertise are crucial to the success and execution of this impactful mission that is critical in ensuring mission success through Security Engineering, Risk Management and Assessment, and Insider Threat Analysis, by improving, protecting, and defending our Nation’s Security., The Cyber Defense Analyst III (Endpoint Security) is a senior SOC role responsible for defending enterprise endpoints against advanced threats through monitoring, detection engineering, incident response, and endpoint-focused threat hunting. This position emphasizes deep expertise in endpoint detection and response (EDR), host-based analysis, and adversary behavior on Windows and Linux systems. The Cyber Defense Analyst 3 shall possess the following capabilities:

  • Monitor and analyze endpoint telemetry for indicators of malicious activity.
  • Investigate host-based intrusions, malware execution, and persistence mechanisms.
  • Analyze Windows and Linux endpoint artifacts, processes, registry activity, and event logs.
  • Utilize EDR platforms to identify, contain, and remediate threats.
  • Conduct forensic analysis of compromised systems and malicious processes.
  • Identify PowerShell abuse, credential theft, and endpoint exploitation techniques.
  • Analyze attacker persistence and lateral movement across enterprise environments.
  • Correlate endpoint and SIEM data to support threat investigations.
  • Support cyber incident response and remediation activities.
  • Perform endpoint-focused threat hunting operations.
  • Mentor junior analysts and support operational best practices.
  • Participate in after-action reviews and analytical validation activities.

Requirements

  • Eight (8) years Cyber Defense Analyst experience.
  • Experience with endpoint detection and response technologies.
  • Two (2) years TCP/IP fundamentals experience.
  • Two (2) years Wireshark or tcpdump experience.
  • Three (3) years SIEM experience.
  • Three (3) years threat analysis and incident response experience.
  • Experience investigating host-based intrusions and malware activity.
  • 8x5 schedule.

Certifications Required:

  • DoD 8570 compliance with CSSP Analyst baseline certification
  • Information Assurance Technical (IAT) Level I or Level II certification
  • Computing Environment (CE) certification. The CE certification requirements can be fulfilled with either Microsoft OS, Cent OS/Red Hat OS CE certifications.

  • Global Information Assurances Certification (GIAC) Certified Incident Handler (GCIH) certificate or Certified Intrusion Analyst (GCIA) certificate.
  • Splunk software training course “Fundamentals 1”

Position requires active Security Clearance with appropriate Polygraph

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:59 min

Designing HTTP and HTML for familiar document sharing

Tim Berners-Lee · World Congress 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all