Malware Analyst

Indigo IT, LLC

Fort Bragg (NC)

On-site

USD 75,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision coverage
401(k) with company match
Paid time off
Education assistance
In-house training
Bonuses and recognition

Job summary

Indigo IT, LLC, Fort Bragg, NC, seeks two Senior Integrated Assessment / Malware Analysts to support the DCOMSS program. You will perform malware and artifact analysis in an isolated lab, manage tooling lifecycle, and provide first-line watch relief for 24/7 operations.

Requirements include a Bachelor's degree with 5 years of experience, DoD 8140 qualifications, DoD SECRET clearance (with interim), US Citizenship, and CAC eligibility. Onsite work required with core hours and occasional travel.

Qualifications

  • Bachelor’s degree and 5 years of experience
  • DoD 8140 qualification for DCWF roles required
  • US Citizenship required
  • Current DoD SECRET clearance required and CAC eligibility

Responsibilities

  • Plan and execute Network Assistance Visits and Network Damage Assessments with ROE
  • Execute annual web assessments using named tools; validate remediation through re-tests
  • Perform malware and artifact analysis in isolated lab; own tooling lifecycle
  • Provide watch relief on 24/7 rotation and support exercises and hunts

Skills

Malware analysis
Forensics
Incident response
Network monitoring
Communication

Education

Bachelor’s degree
DoD 8140.03 qualifications
US Citizenship
DoD SECRET clearance

Tools

ACAS
Nessus
Nessus Web App
Metasploit
Cobalt Strike
Burp Suite Pro
OWASP ZAP
BloodHound
Impacket
Wireshark
Kali Linux

Job description

Malware Analyst

Location: Ft. Bragg, NC

Job Id: 557

# of Openings: 1

SUMMARY:

Founded in 2001, Indigo IT is an award-winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers’ technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation’s Veterans. Recognized on the Inc. 5000 list of America’s fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today!

The USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) program establishes a dedicated, 24/7/365 cyber defense capability for the U.S. Army Reserve Command CIO/G-6, operating as a Cyber Security Service Provider - Executor (CSSP-E). The team performs continuous network security monitoring, detection, analysis, and incident response across NIPRNet and SIPRNet; integrated assessments under the Computer Defense Assistance Program (Network Assistance Visits, Network Damage Assessments, and web assessments); and Cyber Threat Intelligence collection, correlation, signature development, and finished intelligence production in support of approximately 205,000 Army Reserve personnel.

We are seeking two Senior Integrated Assessment / Malware Analysts to form the standing assessment cell for Computer Defense Assistance Program missions, share the annual web-assessment portfolio, perform malware and artifact analysis in the isolated lab, own tooling lifecycle and configuration management, and provide first-line planned watch relief. Both positions are configured as broad, senior cross-domain practitioners with mutual backup rather than a primary specialist and a junior alternate.

ESSENTIAL FUNCTIONS/RESPONSIBILITIES:
Network Assistance Visits and Network Damage Assessments
  • Plan and execute Network Assistance Visits (average one per month) under Government-approved Rules of Engagement: pre-coordination and in-brief; network survey, technical assistance, and organizational repairs; executive summary, out-brief, and final report on encrypted media within 30 calendar days
  • Deploy within four hours of notification for Network Damage Assessments; validate compromise, determine depth of intrusion, gather host logs and forensic artifacts, conduct on-site anomaly-detection scans and incident handling, provide leadership updates every two hours, and deliver the formal NDA report within five business days
  • Manage the engagement lifecycle: signed scope authorization, ROE, kickoff, daily situational reports, written scope-change requests, immediate notification of active adversary or data-spill findings, 24-hour hot wash, and draft report within seven business days
Web Assessments and Remediation Validation
  • Execute annual web assessments of all registered public-facing websites in the AOR (approximately 920 per year) using approved tools (OWASP ZAP, Burp Suite Pro, Nessus Web App); cover at minimum XSS, SQL injection, embedded credentials, and common port vulnerabilities; rule out false positives before delivery; assist site owners with remediation
  • Validate remediation through 30/60/90-day re-tests by severity; provide closure certification to the ISSO for eMASS POA&M entry; elevate failed re-tests within five business days; produce quarterly finding-closure trend reports
Malware Analysis and Tooling Lifecycle
  • Perform malware and artifact analysis in the isolated DCO test lab and package findings for incident, CTI, and signature use
  • Serve as primary or backup owner of tooling lifecycle and configuration management: CNF/ERVB tool authorization, Tool Authorization Register, STIG/SRG baselines, ACAS/Tenable scanning and IAVM remediation, upgrade test and rollback, lab isolation and egress control, and the semiannual Technology Refresh Plan
Watch Relief and Mission Support
  • Provide planned watch relief on the 24/7/365 rotation to cover training, leave, and surge without consuming Key Personnel capacity
  • Support exercises, hunts, and signature testing as scheduled by the Blue Team Lead
EDUCATION, EXPERIENCE, & CERTIFICATIONS:
  • Bachelor’s degree and 5 years of experience
  • Army Penetration Testing Course (APTC) completion, or Government-accepted equivalent, required before conducting any production assessment activity
  • DoDM 8140.03 qualification for the DCWF Vulnerability Assessment Analyst work role at Intermediate proficiency and DCWF 511 Cyber Defense Analyst at Intermediate proficiency (watch relief)
  • DoDM 8140.03 qualification for DCWF 521 Cyber Defense Infrastructure Support Specialist at Intermediate proficiency for tool/lab ownership duties; DCWF 531 Cyber Defense Incident Responder at Intermediate where assigned NDA incident-response duties
  • Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access
  • US Citizenship required
  • Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
  • Ability to obtain and maintain a DoD Common Access Card and USARC installation access
  • Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
SPECIFIC KNOWLEDGE, SKILLS, & ABILITIES:
  • Demonstrated experience executing authorized network and web application assessments in a DoD environment under formal Rules of Engagement
  • Hands-on proficiency with:
    • ACAS, Nessus, and Nessus Web App
    • Metasploit Framework and Cobalt Strike or approved adversary-emulation equivalent
    • Burp Suite Pro and OWASP ZAP
    • BloodHound, Impacket, Wireshark, and Kali Linux
  • Experience collecting and preserving forensic artifacts and maintaining chain of custody
  • Proficiency with CVSSv3 scoring and with translating technical findings into prioritized, actionable remediation guidance
  • Hands‑on static and dynamic malware‑analysis skills, including disassembler/debugger use, Windows internals and Win32 API knowledge, assembly-code interpretation, and documentation of malware behavior, indicators, and mitigation recommendations
  • Hands‑on experience configuring, patching, troubleshooting, and validating security tools and isolated Windows/Linux lab environments, including STIG/SRG baselines, IAVM remediation, controlled connectivity, and tested rollback procedures
  • Ability to stand watch on an enterprise SIEM when assigned relief
  • Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
  • Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
  • The ability to communicate complex technical findings clearly to non-technical audiences
  • A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
  • A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies
Work Environment
  • Onsite presence at USARC Headquarters, Fort Bragg, NC required
  • Core hours with on-call rotation and planned watch relief, including occasional nights and weekends
  • CONUS/OCONUS travel with four-hour deployment readiness for Network Damage Assessments

At Indigo IT, we offer an expansive benefits package for our employees, which includes: Medical, Dental, and Vision coverage options. In addition, we offer 401(k) with company match, Group life and disability, Flex Spending Accounts (FSA), Paid Time Off (PTO), Paid holidays, and Education assistance. We also have in house training programs for employees, we reward thought leadership with bonuses and recognition for publishing, speaking, and innovative thought leadership in our industry.

Indigo IT is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. This employer uses E-Verify.

Pay Range: $75,000 - $130,000 per year

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst, Tier II
SOC Analyst, Tier II

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 80,000 - 110,000
Medical, Dental, Vision coverage
401(k) with company match
Life and disability insurance
+1
SOC Analyst, Tier I
SOC Analyst, Tier I

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 60,000 - 87,000
Medical/Dental/Vision
401(k) with company match
PTO & Holidays
+1
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 95,000 - 150,000
Medical benefits
Dental benefits
Vision benefits
+9
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 90,000 - 110,000
Medical coverage
401(k) with company match
Paid holidays
+2
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 125,000 - 150,000
Medical, Dental, and Vision coverage
401(k) with company match
Group life and disability
+4
DCOMSS - Blue Team Lead / Senior Cyber Defense Analyst
DCOMSS - Blue Team Lead / Senior Cyber Defense Analyst

Technology,-Automation,-and-Management,-Inc. • Fort Bragg (NC)

On-site
USD 120,000 - 180,000
Relocation Assistance
Sign-on Bonus
Travel Required
Computer Network Defense Analyst Multiple locations- MD,HI,GA
Computer Network Defense Analyst Multiple locations- MD,HI,GA

WarCollar Industries, LLC • Fort Meade (MD)

On-site
USD 120,000 - 170,000
Medical insurance
PTO
401k matching
+2
Media Malware Analyst, Journeyman
Media Malware Analyst, Journeyman

Leidos Inc • Odenton (MD)

On-site
USD 90,000 - 120,000
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents 7/2/2026 Fort Meade, MD
Cybersecurity - Cyber Defense Analyst - Malware, Vulnerability, Incidents 7/2/2026 Fort Meade, MD

Erias Ventures, LLC • Fort Meade (MD)

On-site
USD 210,000 - 232,000
100% Company Paid Vision and Dental Coverage
Flexible Work Schedules
Professional Development Bonuses
Senior Malware & Threat Analysis Specialist
Senior Malware & Threat Analysis Specialist

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 75,000 - 130,000
Medical, Dental, Vision coverage
401(k) with company match
Paid time off
+3