Cyber Security Analyst

Trinity Cyber

Washington (District of Columbia)

On-site

USD 120,000 - 160,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Trinity Cyber is seeking a Resident Threat Operations Analyst to be the embedded technical authority for a major government customer. You will be on-site in the Washington, DC metro area, advising threat operations teams and translating mission requirements into FCI capabilities.

The role requires an active TS/SCI clearance, deep knowledge of threat intelligence, protocol analysis, and network detection, and the ability to drive detection engineering and customer engagements in a classified

Qualifications

  • Active TS/SCI clearance.
  • Local to the Washington, DC metro area, on-site at the customer location.
  • Experience as a SOC analyst, threat hunter, or incident responder with strong adversary-tradecraft knowledge.
  • Hands-on experience developing or operationalizing network detection technology in production environments.
  • Experience in classified government environments.
  • Ability to rapidly learn complex cybersecurity technologies and become a trusted technical authority.

Responsibilities

  • Translate customer threat intel into FCI countermeasures and COA recommendations.
  • Study adversary TTPs and analyze traffic at the protocol level to counter threats at scale.
  • Advise on FCI placement, coverage, and blind spots within customer networks and workflows.
  • Communicate technical findings to government and Trinity Cyber teams and capture requirements for future FCI capabilities.

Skills

Threat intelligence research
Protocol analysis
Threat hunting
Incident response
Detection engineering
Technical authority
Communication skills
OSINT research
Rapid learning

Tools

YARA
Suricata
Snort
Sigma
Wireshark
Splunk

Job description

Trinity Cyber is a leading developer and provider of advanced cybersecurity technologies and services. Our breakthrough core technology - Full Content Inspection (FCI) - can deeply, quickly, and precisely find threats within files and internet sessions and automatically remove them. As a secure edge, our platform identifies and neutralizes traffic at line-speed, with accuracy and precision beyond the capability of anything on the market. Our team operate the FCI capability on behalf of our customers and are the experts behind the platform and services, ensuring that customers are protected against advanced and emerging threats regardless of where they originate from on the internet.

Role Description

As a Resident Threat Operations Analyst, you will be Trinity Cyber’s embedded technical authority for a major government customer, working on-site in a classified environment as the resident expert on FCI. You will advise customer cyber operations teams on maximizing FCI’s effectiveness against advanced threats, surface new detection opportunities, operationalize customer threat intelligence, and translate mission requirements into capabilities delivered by Trinity Cyber teams. The work combines threat intelligence research, deep protocol analysis, and an in-depth command of FCI technology. This position supports a major U.S. Government customer, is based on-site in the Washington, DC metro area, and requires an active Top Secret/SCI clearance.

Duties
  • Drive Countermeasure Operations: Translate customer-unique cyber threat intelligence into FCI countermeasure and Course of Action (COA) recommendations. Work with the customer to decouple internet-observed adversary tactics, techniques, and procedures (TTPs) from classified reporting. Identify countermeasure gaps and opportunities as threats emerge. Translate new FCI detection/countermeasure requirements to Trinity Cyber’s engineering teams.
  • Research Adversary Tradecraft: Study adversary TTPs, analyze network traffic and PCAPs at the protocol level, and identify how adversaries abuse, or hide within legitimate traffic, then turn those findings into opportunities to counter the adversary at scale. Maintain expertise on emerging threats, malware, and FCI methodologies.
  • Advise the Customer: Evaluate customer network architectures, traffic flows, and enclave boundaries to advise on optimal FCI placement, coverage, and blind spots. Help analysts integrate FCI into detection, investigation, and incident response workflows, and assist cyber investigations where FCI can improve detection fidelity and operational outcomes.
  • Close the Loop: Communicate technical findings and recommendations to both government and Trinity Cyber engineering teams, and capture customer operational requirements as product feedback that shapes future FCI capabilities.
Experience Requirements
  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Local to the Washington, DC metro area, with the ability to work on-site at the customer location.
  • Prior experience as a Security Operations Center (SOC) analyst, threat hunter, incident responder, or in a similar cyber operations role, with a strong understanding of adversary tradecraft, analyst workflows, event triage, investigations, and incident response.
  • Prior hands-on experience developing, tuning, validating, or operationalizing network detection technology in production environments, with depth sufficient to scope, evaluate, and guide detection engineering performed by others.
  • Experience supporting cybersecurity operations within classified government environments.
  • Demonstrated ability to rapidly learn complex cybersecurity technologies and become the trusted technical authority for those capabilities.
Technical Qualifications
  • Network traffic analysis, including expert-level packet analysis (PCAP) and deep, layer-by-layer understanding of protocols such as TCP/IP, DNS, TLS, HTTP/HTTPS, SMB, SMTP, and QUIC, including how adversaries abuse them.
  • Experience with detection technologies such as YARA, Suricata, Snort, Sigma, Wireshark, or comparable frameworks.
  • Experience with malware triage, payload decoding, deobfuscation, and behavioral analysis.
  • Familiarity with the MITRE ATT&CK framework as applied to detection development.
  • Experience with enterprise SIEM platforms (Splunk preferred) and log analysis.
  • Experience conducting operationally secure open-source intelligence (OSINT) research is a plus.
  • Excellent written and verbal communication skills, with the ability to explain complex technical concepts to analysts, engineers, and government leadership.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

On-Site Threat Operations Analyst (TS/SCI)
On-Site Threat Operations Analyst (TS/SCI)

Trinity Cyber • Washington

On-site
USD 120,000 - 160,000
Cyber Threat Analyst
Cyber Threat Analyst

Peraton • Linthicum (MD)

On-site
USD 90,000 - 150,000
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph

General Dynamics - IT • Reston (VA)

On-site
USD 140,000 - 170,000
Mid Cyber Threat Intelligence (CTI) Analyst
Mid Cyber Threat Intelligence (CTI) Analyst

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 160,000
Cyber Triage Analyst
Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Cyber Threat Analyst II
Cyber Threat Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 120,000
Sr. Cyber Triage Analyst
Sr. Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 140,000 - 190,000
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph
Cyber Threat Intelligence (Fusion) Analyst - TS/SCI with Polygraph

General Dynamics Information Technology • Washington

On-site
USD 120,000 - 150,000
Senior Cybersecurity Defense Analyst III
Senior Cybersecurity Defense Analyst III

Invictus International • Alexandria (VA)

On-site
USD 130,000 - 190,000
ME00600-Cyber Threat Analyst (Multiple Positions)
ME00600-Cyber Threat Analyst (Multiple Positions)

Momentum Engineering, Inc. • Maryland

On-site
USD 80,000 - 130,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2