Cyber Network Defense Analyst (CNDA) – Cloud Forensics

ARGO Cyber Systems

Arlington (VA)

Hybrid

USD 130,000 - 160,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Argo Cyber Systems seeks a Cyber Network Defense Analyst (CNDA) with deep cloud forensics expertise for a high-visibility federal mission. You will lead investigations across hybrid and multi‑cloud environments, identifying attacker TTPs, correlating artifacts, and driving containment with government cyber teams.

Responsibilities include end‑to‑end forensics, cloud telemetry correlation, and automated detection logic development using Microsoft Sentinel and AWS GuardDuty.

Qualifications

  • U.S. Citizenship with active TS/SCI clearance and DHS EOD eligibility.
  • Minimum 8 years in digital forensics and incident response (DFIR).
  • Proven cloud forensics, identity security, and hybrid infrastructure defense.
  • Proficient in M365/Azure AD, AWS IAM, and SaaS investigative methods.
  • Deep understanding of SaaS/PaaS/IaaS architectures and typical attack vectors.
  • Strong evidence acquisition, volatile data capture, artifact analysis, and reporting.

Responsibilities

  • Perform end-to-end forensic acquisition and analysis across on‑prem, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, SaaS).
  • Investigate identity-based and credential abuse incidents targeting cloud control planes and hybrid identity infra.
  • Correlate cloud telemetry and network data to reconstruct attacker timelines and IOC validation.
  • Develop automated detection logic, threat-hunting scripts, and playbooks using Sentinel, Defender, GuardDuty, Chronicle.
  • Produce technical and executive reports integrating findings across endpoints, networks, and cloud assets.
  • Support continuous improvement of IR procedures, forensics workflows, and threat-hunting operations.
  • Collaborate with Argo and government stakeholders to triage alerts and strengthen detection and response.

Skills

Cloud forensics
DFIR
Hybrid cloud
M365/Azure AD
SaaS/PaaS/IaaS

Education

Bachelor's Degree in CS/Cybersecurity
High School + 10+ years DFIR

Tools

Terraform
Kubernetes
Docker
CloudFormation
Azure RM

Job description

Cyber Network Defense Analyst (CNDA) - Cloud Forensics
Location

Remote / Onsite (as required)

Clearance

Active TS/SCI (DHS EOD eligibility required)

Company

Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small Business (SDVOSB)

About Argo Cyber Systems

Argo Cyber Systems delivers advanced cybersecurity and threat-hunting capabilities to safeguard federal and critical infrastructure environments. Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission experience with innovation-empowering our customers to detect, disrupt, and defeat adversaries in real time.

Position Overview

Argo Cyber Systems is seeking Cyber Network Defense Analysts (CNDA) with deep Cloud Forensics expertise to support a high-visibility federal mission. The CNDA will lead advanced investigations into sophisticated intrusions across hybrid and multi-cloud environments, identifying attacker tactics, techniques, and procedures (TTPs), correlating artifacts, and driving containment and remediation actions in partnership with government cyber teams.

Key Responsibilities
  • Conduct end-to-end forensic acquisition and analysis across on-premises, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, SaaS).
  • Investigate identity-based and credential-abuse incidents targeting cloud control planes and hybrid identity infrastructure.
  • Correlate cloud telemetry (Azure Activity Logs, AWS CloudTrail, GCP Logs, VPC Flow Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs).
  • Develop and deploy automated detection logic, threat-hunting scripts, and analytical playbooks using Microsoft Sentinel, Defender, AWS GuardDuty, and GCP Chronicle.
  • Produce comprehensive technical and executive-level reports, integrating findings across endpoints, networks, and cloud assets to inform threat containment and strategic recommendations.
  • Support continuous improvement of incident response procedures, forensics workflows, and threat-hunting operations.
  • Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen enterprise detection and response posture.
Required Qualifications
  • U.S. Citizenship and active TS/SCI clearance (with ability to obtain DHS EOD Suitability).
  • Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR).
  • Proven expertise in cloud forensics, identity security, and hybrid infrastructure defense.
  • Proficiency in M365/Azure AD, AWS IAM, and SaaS investigative methodologies.
  • Deep understanding of SaaS/PaaS/IaaS architectures, including common attack vectors and defensive measures.
  • Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting.
Desired Qualifications
  • Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript.
  • Familiarity with Terraform, Kubernetes, Docker, CloudFormation, or Azure Resource Manager for automation and orchestration.
  • Understanding of MITRE ATT&CK for Cloud and adversary emulation techniques.
  • Strong communication and collaboration skills for working across multidisciplinary teams.
Education
  • Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field or
  • High School Diploma and 10+ years of directly relevant DFIR experience.
Preferred Certifications
  • GIAC Cloud Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
  • AWS and Microsoft security/cloud certifications (e.g., Azure Security Engineer, AWS Security Specialty)
Why Argo Cyber Systems

At Argo, you'll be part of a mission-driven, veteran-founded cybersecurity team protecting America's most critical systems. We combine hands‑on technical excellence with operational precision to outpace the threat. Join us to defend, detect, and innovate at the cyber edge.

Salary

Salary: $130000 - $160000 per year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Network Defense Analyst (CNDA) III – Cloud Forensics
Cyber Network Defense Analyst (CNDA) III – Cloud Forensics

argocyber • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Remote Cloud Forensics & Network Defense Analyst
Remote Cloud Forensics & Network Defense Analyst

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 130,000 - 160,000
Computer Network Defense Incident Manager III
Computer Network Defense Incident Manager III

argocyber • Arlington (VA)

On-site
USD 140,000 - 190,000
Remote Cloud Forensics Cyber Defense Analyst
Remote Cloud Forensics Cyber Defense Analyst

argocyber • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Host Based Systems Analyst II
Host Based Systems Analyst II

ARSIEM Corporation • Arlington (VA)

On-site
USD 110,000 - 160,000
Computer Network Defense Analyst (CNDA) III
Computer Network Defense Analyst (CNDA) III

NewGen Technologies • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Host Based Systems Analyst II
Host Based Systems Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 140,000
Incident Response Expert III
Incident Response Expert III

ARGO Cyber Systems • Arlington (VA)

On-site
USD 100,000 - 125,000
Host Based Systems Analyst II
Host Based Systems Analyst II

ARSIEM • Arlington (VA)

On-site
USD 80,000 - 120,000
Cyber Network Defense Analyst III
Cyber Network Defense Analyst III

NewGen Technologies • Arlington (VA)

On-site
USD 120,000 - 160,000