Cyber Triage Analyst Level III

argocyber

Arlington (VA)

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Argo Cyber Systems, LLC is seeking an experienced JCDC Cyber Triage Analyst to support the Joint Cyber Defense Collaborative (JCDC). You will perform initial triage of threat reports, IOC submissions, and cybersecurity notifications, serving as frontline defender.

This is a non-entry level role requiring 2–4+ years of cybersecurity experience, TS/SCI clearance, and strong written/verbal communication to coordinate with government and industry partners.

Qualifications

  • 2–4+ years of progressive cybersecurity experience.
  • Experience in SOC, CTI, incident response, or network monitoring.
  • Ability to independently triage and analyze cybersecurity incidents and incidents.

Responsibilities

  • Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
  • Analyze indicators and artifacts including IPs, domains, URLs, file hashes, and malware artifacts.
  • Correlate indicators with known threat actors, campaigns, and TTPs.
  • Develop concise, defensible cyber triage reports with actionable recommendations.
  • Coordinate with interagency partners and escalate when needed.

Skills

SOC Operations
Cyber Threat Intelligence
Incident response
Network security monitoring
Threat hunting
Cybersecurity operations

Education

Bachelor's degree
High School Diploma or equivalent plus 4+ years of experience

Tools

SIEM
Threat Intelligence Platforms (TIPs)
Case management systems
Cybersecurity ticketing platforms

Job description

JCDC Cyber Triage Analyst – TS/SCI

Company: Argo Cyber Systems, LLC
Program: Engagement Support Services (ESS) – JCDC Cyber Operations
Clearance Required: Active TS/SCI
Citizenship: U.S. Citizenship Required
Suitability: Must be able to obtain and maintain DHS Suitability
Employment Type: Full-Time
Experience Level: Mid-Level | 5-7 + Years Cybersecurity Experience

About Argo Cyber Systems

Argo Cyber Systems, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing advanced cybersecurity services to U.S. Government and commercial customers.

Our cybersecurity capabilities include Security Operations Center operations, cyber incident response, threat hunting, cyber threat intelligence, vulnerability management, cloud security, Zero Trust, digital forensics and incident response, penetration testing, and cybersecurity risk and compliance services.

Argo Cyber Systems provides opportunities for experienced cybersecurity professionals to work directly on mission-focused programs protecting federal agencies and critical infrastructure from sophisticated cyber threats.

About the Mission

Argo Cyber Systems is supporting a U.S. Government customer in the rapid deployment and management of secure, cloud-based capabilities supporting cyber incident response, threat hunting, and national-level cybersecurity operations.

Under the Engagement Support Services (ESS) program, our team helps ensure cybersecurity analysts have rapid access to the secure tools, infrastructure, and operational environments required to investigate cyber threats affecting federal agencies, state and local governments, and U.S. critical infrastructure.

Working on this program means directly supporting the nation's cybersecurity defenders. Our mission is to provide reliable, scalable, and secure capabilities when they are needed most-during active cyber incidents and emerging threat campaigns affecting America's digital infrastructure.

Position Overview

Argo Cyber Systems is seeking an experienced JCDC Cyber Triage Analyst to serve as a frontline cyber defender supporting the Joint Cyber Defense Collaborative (JCDC).

The Cyber Triage Analyst performs initial analysis and triage of cyber threat reports, indicators of compromise (IOCs), incident notifications, and other cybersecurity information submitted to the JCDC.

This is not an entry-level or developmental analyst position.

The successful candidate will operate in a role comparable to a Tier 1/Tier 2 SOC Analyst with enhanced Cyber Threat Intelligence (CTI) responsibilities. Analysts are expected to independently research cyber activity, rapidly evaluate technical information, develop defensible analytical conclusions, identify intelligence and information gaps, and recommend appropriate follow-on actions.

This position requires strong technical analysis skills combined with the ability to communicate and coordinate effectively with government organizations, private‑sector partners, critical infrastructure stakeholders, and other cybersecurity professionals.

Key Responsibilities

The JCDC Cyber Triage Analyst will:

  • Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
  • Analyze technical indicators and artifacts including IP addresses, domain names, URLs, file hashes, network traffic patterns, malware artifacts, and related telemetry.
  • Assess the credibility, severity, scope, and potential operational impact of reported cyber activity.
  • Evaluate potential impacts to federal networks and U.S. critical infrastructure sectors.
  • Enrich IOCs using Threat Intelligence Platforms (TIPs), OSINT resources, commercial intelligence sources, and authorized government‑exclusive resources.
  • Correlate indicators with known threat actors, campaigns, malware families, vulnerabilities, tactics, techniques, and procedures (TTPs).
  • Develop concise, defensible cyber triage reports containing analytical findings and actionable recommendations.
  • Determine when incidents or threat activity require escalation or additional technical analysis.
  • Route tickets and analytical findings to appropriate JCDC teams, CISA organizations, or interagency partners.
  • Coordinate with sector‑specific analysts, incident responders, threat hunters, intelligence analysts, and interagency liaisons to obtain additional technical and operational context.
  • Maintain complete and accurate documentation within ticketing, case management, and knowledge management systems.
  • Participate in operational shift handoffs and daily cybersecurity briefings.
  • Monitor emerging cyber threat campaigns, adversary activity, vulnerabilities, and trends.
  • Support development and continuous improvement of cyber triage playbooks, workflows, and Standard Operating Procedures (SOPs).
  • Provide appropriate feedback to submitters and partner organizations regarding ticket status, findings, and disposition.
  • Support collaboration across geographically distributed government and contractor teams.
Required Qualifications

Candidates must meet the following requirements:

  • U.S. Citizenship.
  • Active TS/SCI security clearance.
  • Ability to obtain and maintain DHS Suitability.
  • 2–4+ years of progressive cybersecurity experience supporting one or more of the following:
    • Security Operations Center (SOC) operations
    • Cyber Threat Intelligence (CTI)
    • Cyber incident response
    • Network security monitoring
    • Threat hunting
    • Cybersecurity operations
  • Demonstrated ability to independently triage and analyze cybersecurity incidents, alerts, threat reports, or intelligence.
  • Experience analyzing technical indicators such as IP addresses, domains, URLs, file hashes, network traffic, and malware‑related artifacts.
  • Experience researching and enriching IOCs using threat intelligence and OSINT resources.
  • Ability to assess the severity, credibility, and potential impact of cyber threats.
  • Ability to document analytical findings and develop concise, actionable recommendations.
  • Strong technical research and analytical reasoning skills.
  • Strong written and verbal communication skills.
  • Ability to work effectively with government personnel, technical analysts, incident responders, intelligence professionals, and partner organizations.
  • Ability to work collaboratively across geographically distributed teams and physical locations.
Desired Qualifications

Highly qualified candidates may possess experience in several of the following areas:

  • Previous cybersecurity experience supporting CISA, FBI, NSA, DoD, DHS, or another federal cybersecurity or intelligence organization.
  • Understanding of the National Cyber Incident Scoring System (NCISS) and its application to incident prioritization and triage.
  • Knowledge of common cyberattack lifecycle stages, including:
    • Reconnaissance and footprinting
    • Scanning and enumeration
    • Initial access
    • Privilege escalation
    • Persistence
    • Network exploitation and lateral movement
    • Command and control
    • Defense evasion and covering tracks
  • Demonstrated ability to recognize and categorize cybersecurity vulnerabilities and associated attack techniques.
  • Knowledge of Computer Network Defense (CND) policies, procedures, processes, and regulations.
  • Understanding of different operational threat environments, ranging from opportunistic attackers and cybercriminal organizations to sophisticated nation‑state actors.
  • Knowledge of system and application security threats and vulnerabilities, including:
    • Buffer overflows
    • Cross‑site scripting (XSS)
    • SQL/PL‑SQL and other injection attacks
    • Malicious or mobile code
    • Race conditions
    • Covert channels
    • Replay attacks
    • Return‑oriented programming/attacks
    • Other common application and network exploitation techniques
  • Experience working with SIEM platforms, Threat Intelligence Platforms (TIPs), case management systems, and cybersecurity ticketing platforms.
  • Familiarity with cyber threat intelligence concepts, adversary TTPs, and IOC lifecycle management.
  • Knowledge of U.S. critical infrastructure sectors and associated cyber risks.
  • Familiarity with DHS/CISA cybersecurity products, services, alerts, advisories, and operational processes.
  • Experience working in an operational SOC, watch floor, incident response center, or cyber fusion environment.
Education

Candidates must possess one of the following:

Bachelor's degree from an accredited college or university in:

  • Cybersecurity
  • Computer Science
  • Computer Engineering
  • Information Technology
  • Information Systems
  • Network Engineering
  • Another related technical discipline

OR

High School Diploma or equivalent plus at least four additional years of directly relevant technical cybersecurity experience.

Desired Certifications

One or more of the following certifications is preferred:

  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Other comparable cybersecurity, incident response, SOC, or threat intelligence certifications
What We're Looking For

This role is well suited for a cybersecurity professional who can move beyond simply reviewing alerts.

We are looking for analysts who can receive incomplete or ambiguous cyber threat information, independently research the available evidence, determine what is technically significant, identify what information is missing, and develop a defensible recommendation for what should happen next.

Successful candidates should be comfortable operating in a fast‑paced cyber operations environment where accurate analysis, concise communication, sound judgment, and timely escalation directly contribute to the protection of federal systems and U.S. critical infrastructure.

Argo Cyber Systems, LLC is an Equal Opportunity Employer. Employment decisions are made based on qualifications, merit, and business requirements consistent with applicable federal, state, and local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

JCDC Cyber Triage Analyst
JCDC Cyber Triage Analyst

Base One Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Senior Cyber Triage Analyst – TS/SCI
Senior Cyber Triage Analyst – TS/SCI

argocyber • Arlington (VA)

On-site
USD 120,000 - 160,000
JCDC Cyber Triage Analyst - 3-5 years of experience
JCDC Cyber Triage Analyst - 3-5 years of experience

Business Computers Management Consulting Group Llc • Arlington (VA)

On-site
USD 95,000 - 140,000
Competitive salary
Employer-paid health/dental/vision
401k with company match
+1
JCDC Cyber Triage Analyst - 3-5 years of experience
JCDC Cyber Triage Analyst - 3-5 years of experience

bcmcllc • Arlington (VA)

On-site
USD 110,000 - 150,000
Competitive salary
Employer-paid health/dental/vision
Employer-paid life & disability
+3
Cyber Triage Analyst
Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Incident Manager II
Incident Manager II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 56,000 - 66,000
Incident Manager III
Incident Manager III

Solutions3 LLC • Arlington (VA)

On-site
USD 94,000 - 112,000
JCDC Cyber Triage Analyst - 3-5 years of experience
JCDC Cyber Triage Analyst - 3-5 years of experience

BCMC • Arlington (VA)

On-site
USD 90,000 - 130,000
Competitive salary
Employer-paid health benefits
401(k) with company match
+2
Sr. Cyber Triage Analyst
Sr. Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 140,000 - 190,000
Senior JCDC Cyber Triage Analyst
Senior JCDC Cyber Triage Analyst

Business Computers Management Consulting Group Llc • Arlington (VA)

On-site
USD 130,000 - 170,000
Competitive salary
Employer-paid health/dental/vision
401k with company match
+2