Cloud Threat Analyst

ASRC Federal

Hanover (MD)

Hybrid

USD 115,000 - 135,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k)
Education assistance
Paid time off

Job summary

ASRC Federal is seeking a Cloud Threat Analyst in Hanover, MD to safeguard national security systems through proactive threat hunting and advanced detection techniques. You will monitor threat intel, analyze large datasets, and map activities to MITRE ATT&CK while collaborating with CSOC and stakeholders.

The role supports remote flexibility with onsite presence up to one day weekly. The position requires a DoD IAM II/IAT Level II capable professional and a Bachelor’s in Information Security or

Qualifications

  • 2+ years in system-level cybersecurity or threat hunting.
  • Knowledge of NIST CSF and ISO 27001 incident response procedures.
  • Ability to map adversary activity to MITRE ATT&CK.

Responsibilities

  • Perform proactive threat hunting to detect advanced threats.
  • Monitor threat intelligence to identify emerging threats and attack vectors.
  • Analyze datasets to identify patterns and anomalies in networks, endpoints, and cloud.
  • Develop and implement new threat detection techniques and strategies.
  • Conduct forensic analysis and document findings for leadership.

Skills

Threat hunting
Log analysis
MITRE ATT&CK mapping
NIST/ISO incident response
Technical communication
Cloud security

Education

Bachelor's degree in Information Security or related field

Tools

SIEM platforms
Security analytics tools
Forensic analysis tools

Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are atop veteran employer and Certified Great Place to Work™

ASRC Federal is hiring a Cloud Threat Analyst in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD.

Team members may be required to report to Fort Meade daily if required, however Remote flexibility available! Telework offered with a requirement to be onsite up to one (1) day a week in Hanover MD. (5 days in the office has not been required to date)

Position Description:

As the Cloud Threat Analyst, your primary duty is to safeguard our national security systems through proactive threat hunting and advanced threat detection activities. You will continuously monitor and analyze threat intelligence sources to stay informed about emerging threats, searching for signs of malicious activity across our network infrastructure, endpoints, and systems that evade traditional security solutions. A key part of your role involves developing and implementing new and innovative threat detection techniques and strategies, analyzing large datasets to identify patterns and anomalies indicative of malicious activities, and mapping adversary tactics to the MITRE ATT&CK framework. You will collaborate with other CSOC team members and stakeholders to respond to and investigate security incidents, perform in-depth forensic analysis to understand the nature and impact of threats, and provide detailed reports and briefings on threat hunting activities and findings to senior management.

  • 2+ years of system-level cybersecurity experience in one of the following areas:
  • Cyber Security Analyst, Incident Response and Threat Hunting as part of a mid to large enterprise red team or threat hunt team.
  • Enterprise vulnerability management, endpoint security, or web security within a mid to large enterprise.
  • Bachelor's degree in Information Security or related field, or equivalent combination of experience.
  • Must meet DoD 8140/8570.01-M IAM II or IAT Level II requirements (e.g., CCNA Security, CySA+, GICSP, Security+ CE, CND, SSCP, CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, HCISPP, CEH, Pentest+, OSCP, CSSP-IR). At least one certification is required.
Required Skills:
  • Able to read, decipher and understand system, network, or cloud logs
  • Knowledge of basic Enterprise and Network operations.
  • Knowledge of NIST Cybersecurity Framework and/or ISO 27001 (specifically focused on incident response procedures, including containment, eradication, and recovery.)
  • Basic understanding of Mitter Attack framework
  • Communication & Collaboration: Excellent written and verbal communication skills to effectively articulate technical findings and collaborate with diverse teams.
Recommended skills:
  • Conduct proactive threat hunting activities to detect advanced threats that evade traditional security solutions
  • Continuously monitor and analyze threat intelligence sources to stay informed about emerging threats, vulnerabilities, and attack vectors
  • Search for signs of malicious activity across network infrastructure, endpoints, cloud environments, and systems
  • Develop and implement new and innovative threat detection techniques and strategies
  • Analyze large datasets using SIEM platforms and security analytics tools to identify patterns and anomalies indicative of malicious activities
  • Tune detection logic and alerting to reduce false positives and improve threat detection fidelity
  • Leverage threat intelligence sources to identify emerging threats targeting federal environments and national security systems
  • Map adversary activity to MITRE ATT&CK framework and develop threat models
  • Analyze advanced persistent threats (APTs) and understand adversary tactics, techniques, and procedures (TTPs)
  • Recommend defensive improvements based on observed threat actor behaviors and attack patterns
  • Correlate threat intelligence with internal security events to identify potential compromises
  • Collaborate with other CSOC team members and stakeholders to respond to and investigate security incidents
  • Perform in-depth forensic analysis to understand the nature, scope, and impact of threats
  • Conduct root cause analysis and impact assessments for security incidents
  • Support containment, eradication, and recovery efforts during security incidents
  • Coordinate response actions with SOC analysts, engineering teams, system owners, and government stakeholders
  • Document incidents, response actions, and remediation recommendations in accordance with government reporting requirements
Reporting & Documentation:
  • Provide detailed reports and briefings on threat hunting activities and findings to senior management
  • Develop and maintain threat hunting playbooks, processes, and procedures
  • Document lessons learned and contributed to the continuous improvement of security operations
  • Create and maintain technical documentation for detection rules, hunting queries, and analytical methodologies
  • Clearly document findings, response actions, and technical recommendations
  • Participate in the development and refinement of security monitoring and incident response tools and processes
  • Assist with security documentation, evidence collection, and audit response
  • Validate security configurations against established baselines and policies
  • Stay current with the latest cybersecurity trends, threat actor TTPs, and defensive technologies

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of $115,000.00 - $134,745.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Cloud Incident Responder
Cyber Defense Cloud Incident Responder

ASRC Federal • Fort Meade (MD)

On-site
USD 106,000 - 160,000
Senior Cyber Tools Architect/Engineer
Senior Cyber Tools Architect/Engineer

ASRC Federal • Quantico (VA)

Hybrid
USD 140,000 - 210,000
Health care
Dental
Vision
+4
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Virginia (MN)

On-site
USD 110,000 - 150,000
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Quantico (VA)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+5
Cyber Defense Incident Responder - Swing Shift
Cyber Defense Incident Responder - Swing Shift

ASRC Federal • Quantico (VA)

On-site
USD 90,000 - 120,000
Health care
401(k)
Education assistance
+1
Penetration Tester
Penetration Tester

ASRC Federal • Washington

Hybrid
USD 120,000 - 180,000
Health insurance
401(k) plan
Education assistance
+1
Continuous Vetting Analyst
Continuous Vetting Analyst

ASRC Federal • Boyers (PA)

Hybrid
USD 60,000 - 85,000
Cybersecurity Program Manager
Cybersecurity Program Manager

ASRC Federal • Reston (VA)

Hybrid
USD 120,000 - 160,000
Health insurance
401(k)
Education assistance
+1
Elastic SIEM Engineer
Elastic SIEM Engineer

ASRC Federal • Hanover (MD)

Hybrid
USD 150,000 - 166,000
Health care
Dental insurance
Vision insurance
+4
Remote Cloud Threat Hunter
Remote Cloud Threat Hunter

ASRC Federal • Hanover (MD)

Hybrid
USD 115,000 - 135,000
Health benefits
401(k)
Education assistance
+1