Trinity Cyber is a leading developer and provider of advanced cybersecurity technologies and services. Our breakthrough core technology - Full Content Inspection (FCI)™ - can deeply, quickly, and precisely find threats within files and internet sessions and automatically remove them. As a secure edge, our platform identifies and neutralizes traffic at line-speed, with accuracy and precision beyond the capability of anything on the market. Our team operate the FCI capability on behalf of our customers and are the experts behind the platform and services, ensuring that customers are protected against advanced and emerging threats regardless of where they originate from on the internet.
Role Description:
As a Resident Threat Operations Analyst, you will be Trinity Cyber’s embedded technical authority for a major government customer, working on-site in a classified environment as the resident expert on FCI. You will advise customer cyber operations teams on maximizing FCI’s effectiveness against advanced threats, surface new detection opportunities, operationalize customer threat intelligence, and translate mission requirements into capabilities delivered by Trinity Cyber teams. The work combines threat intelligence research, deep protocol analysis, and an in-depth command of FCI technology. This position supports a major U.S. Government customer, is based on-site in the Washington, DC metro area, and requires an active Top Secret/SCI clearance.
Duties:
- Drive Countermeasure Operations: Translate customer-unique cyber threat intelligence into FCI countermeasure and Course of Action (COA) recommendations. Work with the customer to decouple internet-observed adversary tactics, techniques, and procedures (TTPs) from classified reporting. Identify countermeasure gaps and opportunities as threats emerge. Translate new FCI detection/countermeasure requirements to Trinity Cyber’s engineering teams.
- Research Adversary Tradecraft: Study adversary TTPs, analyze network traffic and PCAPs at the protocol level, and identify how adversaries abuse, or hide within legitimate traffic, then turn those findings into opportunities to counter the adversary at scale. Maintain expertise on emerging threats, malware, and FCI methodologies.
- Advise the Customer: Evaluate customer network architectures, traffic flows, and enclave boundaries to advise on optimal FCI placement, coverage, and blind spots. Help analysts integrate FCI into detection, investigation, and incident response workflows, and assist cyber investigations where FCI can improve detection fidelity and operational outcomes.
- Close the Loop: Communicate technical findings and recommendations to both government and Trinity Cyber engineering teams, and capture customer operational requirements as product feedback that shapes future FCI capabilities.
Experience Requirements:
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
- Local to the Washington, DC metro area, with the ability to work on-site at the customer location.
- Prior experience as a Security Operations Center (SOC) analyst, threat hunter, incident responder, or in a similar cyber operations role, with a strong understanding of adversary tradecraft, analyst workflows, event triage, investigations, and incident response.
- Prior hands-on experience developing, tuning, validating, or operationalizing network detection technology in production environments, with depth sufficient to scope, evaluate, and guide detection engineering performed by others.
- Experience supporting cybersecurity operations within classified government environments.
- Demonstrated ability to rapidly learn complex cybersecurity technologies and become the trusted technical authority for those capabilities.
Technical Qualifications:
- Network traffic analysis, including expert-level packet analysis (PCAP) and deep, layer-by-layer understanding of protocols such as TCP/IP, DNS, TLS, HTTP/HTTPS, SMB, SMTP, and QUIC, including how adversaries abuse them.
- Experience with detection technologies such as YARA, Suricata, Snort, Sigma, or comparable frameworks.
- Experience with malware triage, payload decoding, deobfuscation, and behavioral analysis.
- Familiarity with the MITRE ATT&CK framework as applied to detection development.
- Experience with enterprise SIEM platforms (Splunk preferred) and log analysis.
- Experience conducting operationally secure open-source intelligence (OSINT) research is a plus.
- Excellent written and verbal communication skills, with the ability to explain complex technical concepts to analysts, engineers, and government leadership.