Cybersecurity Defense Analyst II

Invictus International

Colorado Springs (CO)

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Invictus International is seeking a Cyber Defense Analyst to monitor and respond to security incidents within DoD/IC environments. You will analyze telemetry from enterprise systems, correlate events, and coordinate containment and remediation actions in partnership with government stakeholders.

The role requires a current TS/SCI clearance with CI polygraph and DoD 8570 IAM II/IAT II certification, plus hands-on experience with SIEM and network security technologies.

Qualifications

  • Bachelor's degree in a technical discipline; 4 years may substitute for degree
  • Minimum four years of relevant experience
  • Knowledge of TCP/IP, DNS, HTTP/S, and enterprise networking
  • Experience with SIEM and security technologies
  • DoD 8570 IAT II or IAM II certification
  • DoD/IC environment experience
  • Current TS/SCI clearance with CI polygraph

Responsibilities

  • Monitor, triage, and investigate routine and moderately complex security alerts.
  • Perform cyber defense monitoring using telemetry from enterprise systems and sensors.
  • Analyze logs and network activity to identify malicious behavior and document findings.
  • Triage cyber defense incidents including scope, urgency, and escalation.
  • Support incident handling across detection, investigation, remediation, and reporting.
  • Correlate security data across sources to identify affected systems and adversary activity.
  • Collect and preserve intrusion artifacts and evidence per procedures.
  • Communicate incident status, findings, and recommendations to SOC and stakeholders.
  • Develop investigative hypotheses by correlating network, host, identity, and threat data.
  • Expand investigative scope when related activity is identified.
  • Execute incident response and coordinate containment/remediation actions.
  • Identify recurring telemetry issues and recommend improvements to analysts

Skills

Incident handling
Analytical thinking
Evidence-based reasoning
Communication

Education

Bachelor's degree in a technical discipline

Tools

SIEM
Threat intel tools
IDS/IPS

Job description

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
  • Independently monitor, triage, and investigate routine and moderately complex security alerts and suspected incidents.
  • Perform cyber defense monitoring and analysis using security information from enterprise systems, networks, security sensors, firewalls, intrusion detection/prevention technologies, endpoint sources, and other available telemetry.
  • Analyze log files and network activity to identify anomalous or malicious behavior, determine potential security impact, and document investigative findings in the authorized case or ticketing system
  • Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
  • Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
  • Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
  • Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
  • Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
  • Develop and test investigative hypotheses by correlating network, host, identity, firewall, vulnerability, and threat data
  • Identify related activity beyond the initially alerted system and appropriately expand investigative scope
  • Execute established incident response and escalation procedures and coordinate with technical teams when containment or remediation action is required
  • Identify recurring alert-quality, telemetry, or process issues and recommend improvements to senior analysts
Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Working knowledge of TCP/IP, DNS, HTTP/S, authentication, enterprise networking, Windows/Linux security events, and common adversary techniques
  • Hands-on experience using SIEM and one or more network, endpoint, firewall, IDS/IPS, or security-analysis technologies
  • Ability to independently investigate security activity, distinguish facts from assumptions, and communicate evidence-based conclusions
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Helping all candidates find great careers is our goal. The information you provide here is secure and confidential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Defense Analyst II
Cybersecurity Defense Analyst II

Invictus International • Alexandria (VA)

On-site
USD 90,000 - 140,000
Cybersecurity Defense Analyst
Cybersecurity Defense Analyst

Invictus International • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
Cybersecurity Defense Analyst
Cybersecurity Defense Analyst

Invictus International • Alexandria (VA)

On-site
USD 110,000 - 140,000
Cybersecurity Threat Analyst
Cybersecurity Threat Analyst

Invictus International • Alexandria (VA)

On-site
USD 110,000 - 170,000
Cybersecurity Threat Analyst
Cybersecurity Threat Analyst

Invictus International • Colorado Springs (CO)

On-site
USD 90,000 - 140,000
Senior Cybersecurity Defense Analyst III
Senior Cybersecurity Defense Analyst III

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 130,000 - 170,000
Senior Cybersecurity Defense Analyst III
Senior Cybersecurity Defense Analyst III

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 140,000 - 180,000
Senior Cybersecurity Defense Analyst III
Senior Cybersecurity Defense Analyst III

Invictus International • Alexandria (VA)

On-site
USD 130,000 - 190,000
Cybersecurity Risk & Exposure Analyst II
Cybersecurity Risk & Exposure Analyst II

Invictus International • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
Equal Opportunity Employer/Veteran/Dis
Cybersecurity Risk & Exposure Analyst II
Cybersecurity Risk & Exposure Analyst II

Invictus International • Alexandria (VA)

On-site
USD 90,000 - 120,000