Host Based Cyber Systems Analyst IV

ARGO Cyber Systems

Arlington (VA)

Hybrid

USD 130,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Argo Cyber Systems is seeking a Cyber Network Defense Analyst with Cloud Forensics experience to support critical missions. You will conduct forensic analysis across on-premises and cloud platforms, investigate incidents, and develop automated detection using Defender/Sentinel and cloud tools. Role requires strong scripting, cloud expertise, and a TS/SCI access approach with U.S.

citizenship. The team collaborates with government and internal stakeholders to validate alerts and drive containment

Qualifications

  • 8+ years of experience in cyber forensic investigations.
  • U.S. Citizenship required; TS/SCI clearance preferred.
  • Experience with cloud environments (SaaS/PaaS/IaaS) and hybrid identity security.

Responsibilities

  • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS).
  • Investigate and respond to incidents targeting cloud and hybrid identity.
  • Correlate cloud control-plane events and network telemetry to reconstruct attacker timelines.
  • Develop and operationalize detection logic and automation using cloud-native tools and scripting.
  • Produce incident reports and containment recommendations; support IR playbooks for cloud/hybrid environments.
  • Coordinate with internal teams and external stakeholders.

Skills

Cloud forensics
Incident response
Threat hunting
Forensic investigations
PowerShell/Python scripting

Tools

Microsoft Defender
Sentinel
AWS GuardDuty
GCP Chronicle

Job description

Argo Cyber Systems provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for malicious cyber activity. We are seeking Cyber Network Defense Analysts (CNDA) with Cloud Forensics experience to support this critical customer mission.


Responsibilities


  • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.

  • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.

  • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.

  • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.

  • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.

  • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.

  • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.


Required Skills


  • U.S. Citizenship

  • Active TS/SCI clearance

  • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability

  • 8+ years of experience in cyber forensic investigations with leading tools and techniques.

  • Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.

  • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.

  • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.

  • Knowledge of AWS, IAM, and best practices for cloud identity security.


Desired Skills


  • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.

  • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.

  • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).


This position requires a minimum of a USG Top Secret Security Clearance!

Argo Cyber is an Equal Opportunity Employer.


Salary: $130000 - $160000 per year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Network Defense Analyst (CNDA) III – Cloud Forensics
Cyber Network Defense Analyst (CNDA) III – Cloud Forensics

argocyber • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Remote Cloud Forensics Cyber Defense Analyst
Remote Cloud Forensics Cyber Defense Analyst

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 130,000 - 160,000
Remote/Onsite as required
Remote Cloud Forensics Cyber Defense Analyst
Remote Cloud Forensics Cyber Defense Analyst

argocyber • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Senior Cloud Forensics & IR Analyst
Senior Cloud Forensics & IR Analyst

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 130,000 - 160,000
Host Based Cyber Systems Analyst III
Host Based Cyber Systems Analyst III

ARGO Cyber Systems • Arlington (VA)

Hybrid
USD 120,000 - 140,000
Computer Network Defense Incident Manager III
Computer Network Defense Incident Manager III

argocyber • Arlington (VA)

On-site
USD 140,000 - 190,000
Incident Response Expert III
Incident Response Expert III

ARGO Cyber Systems • Arlington (VA)

On-site
USD 100,000 - 125,000
Senior Cloud Architect
Senior Cloud Architect

argocyber • Arlington (VA)

On-site
USD 140,000 - 190,000
Network Based Systems Analyst - II
Network Based Systems Analyst - II

Beyond SOF • Arlington (VA)

Hybrid
USD 110,000 - 160,000
Cyber Threat intelligence Analyst II
Cyber Threat intelligence Analyst II

ARGO Cyber Systems • Arlington (VA)

On-site
USD 70,000 - 85,000