Senior Integrated Assessment / Malware Analyst

Sentar

Fort Bragg (NC)

On-site

USD 120,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision coverage
Life insurance
Group 401(k) match
Paid Time Off

Job summary

Sentar seeks a Senior Integrated Assessment / Malware Analyst to join the Fort Bragg, NC team. The role focuses on DoD network and web assessments, malware analysis in an isolated lab, and tooling lifecycle management. You will support watch relief and contribute to mission readiness.

Candidates should have DoD clearance eligibility, strong malware analysis skills, and hands-on experience with ACAS, Nessus, Metasploit, and Burp Suite Pro. Onsite in Fort Bragg is required.

Qualifications

  • Bachelor's degree and 5 years of experience, or AA with 7+ years.
  • DoD environment experience and ability to obtain DoD clearance.
  • Experience executing authorized network and web assessments under Rules of Engagement.
  • Hands-on malware analysis and artifact handling; documentation of findings.

Responsibilities

  • Plan and perform DoD network and web assessments with ROE compliance.
  • Analyze malware and artifacts in isolated labs and prepare reports.
  • Lead or backup tooling lifecycle management, including baselines and lab access.
  • Provide watch relief and support exercises, hunts, and testing.

Skills

ACAS
Nessus
Nessus Web App
Metasploit
Cobalt Strike
Adversary emulation
Burp Suite Pro
OWASP ZAP
BloodHound
Impacket
Wireshark
Kali Linux

Education

Bachelor's degree
Associate's degree

Tools

Kali Linux
Burp Suite Pro
OWASP ZAP
Metasploit
Cobalt Strike
Nessus
ACAS
BloodHound
Wireshark

Job description

Current job opportunities are posted here as they become available.

Senior Integrated Assessment / Malware Analyst

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a Senior Integrated Assessment / Malware Analyst in Ft. Bragg, NC to form the standing assessment cell for Computer Defense Assistance Program missions, share the annual web-assessment portfolio, perform malware and artifact analysis in the isolated lab, own tooling lifecycle and configuration management, and provide first-line planned watch relief. Both positions are configured as broad, senior cross-domain practitioners with mutual backup rather than a primary specialist and a junior alternate.

Role Description
Network Assistance Visits and Network Damage Assessments
  • Plan and execute Network Assistance Visits (average one per month) under Government-approved Rules of Engagement: pre-coordination and in-brief; network survey, technical assistance, and organizational repairs; executive summary, out-brief, and final report on encrypted media within 30 calendar days
  • Deploy within four hours of notification for Network Damage Assessments; validate compromise, determine depth of intrusion, gather host logs and forensic artifacts, conduct on-site anomaly-detection scans and incident handling, provide leadership updates every two hours, and deliver the formal NDA report within five business days
  • Manage the engagement lifecycle: signed scope authorization, ROE, kickoff, daily situational reports, written scope-change requests, immediate notification of active adversary or data-spill findings, 24-hour hot wash, and draft report within seven business days
Web Assessments and Remediation Validation
  • Execute annual web assessments of all registered public-facing websites in the AOR (approximately 920 per year) using approved tools (OWASP ZAP, Burp Suite Pro, Nessus Web App); cover at minimum XSS, SQL injection, embedded credentials, and common port vulnerabilities; rule out false positives before delivery; assist site owners with remediation
  • Validate remediation through 30/60/90-day re-tests by severity; provide closure certification to the ISSO for eMASS POA&M entry; elevate failed re-tests within five business days; produce quarterly finding-closure trend reports
Malware Analysis and Tooling Lifecycle
  • Perform malware and artifact analysis in the isolated DCO test lab and package findings for incident, CTI, and signature use
  • Serve as primary or backup owner of tooling lifecycle and configuration management: CNF/ERVB tool authorization, Tool Authorization Register, STIG/SRG baselines, ACAS/Tenable scanning and IAVM remediation, upgrade test and rollback, lab isolation and egress control, and the semiannual Technology Refresh Plan
Watch Relief and Mission Support
  • Provide planned watch relief on the 24/7/365 rotation to cover training, leave, and surge without consuming Key Personnel capacity
  • Support exercises, hunts, and signature testing as scheduled by the Blue Team Lead
Work Environment
  • Onsite presence at USARC Headquarters, Fort Bragg, NC required
  • Core hours with on-call rotation and planned watch relief, including occasional nights and weekends
  • CONUS/OCONUS travel with four-hour deployment readiness for Network Damage Assessments
Qualifications
  • Bachelor's degree and 5 years of experience, or AA with 7+ years
  • Army Penetration Testing Course (APTC) completion, or Government-accepted equivalent, required before conducting any production assessment activity
  • DoDM 8140.03 qualification for the DCWF Vulnerability Assessment Analyst work role at Intermediate proficiency (PWS cites 512; current catalog indicates 541; verify at hire) and DCWF 511 Cyber Defense Analyst at Intermediate proficiency (watch relief)
  • DoDM 8140.03 qualification for DCWF 521 Cyber Defense Infrastructure Support Specialist at Intermediate proficiency for tool/lab ownership duties; DCWF 531 Cyber Defense Incident Responder at Intermediate where assigned NDA incident-response duties
  • Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access
  • US Citizenship required
  • Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
  • Ability to obtain and maintain a DoD Common Access Card and USARC installation access
  • Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
SPECIFIC KNOWLEDGE, SKILLS, & ABILITIES
  • Demonstrated experience executing authorized network and web application assessments in a DoD environment under formal Rules of Engagement
  • Hands-on proficiency with: ACAS, Nessus, and Nessus Web App, Metasploit Framework and Cobalt Strike or approved adversary-emulation equivalent, Burp Suite Pro and OWASP ZAP, BloodHound, Impacket, Wireshark, and Kali Linux
  • Experience collecting and preserving forensic artifacts and maintaining chain of custody
  • Proficiency with CVSSv3 scoring and with translating technical findings into prioritized, actionable remediation guidance
  • Hands-on static and dynamic malware-analysis skills, including disassembler/debugger use, Windows internals and Win32 API knowledge, assembly-code interpretation, and documentation of malware behavior, indicators, and mitigation recommendations
  • Hands-on experience configuring, patching, troubleshooting, and validating security tools and isolated Windows/Linux lab environments, including STIG/SRG baselines, IAVM remediation, controlled connectivity, and tested rollback procedures
  • Ability to stand watch on an enterprise SIEM when assigned relief
  • Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
  • Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
  • The ability to communicate complex technical findings clearly to non-technical audiences
  • A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
  • A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies

Clearance Level: Secret

Education: Bachelor's degree and 5 years of experience or Associate's degree and 7 years experience

Certifications: APTC or Government-accepted equivalent before any production assessment work; DoDM 8140.03 qualified for Vulnerability Assessment Analyst (Intermediate), 511 (Intermediate) for watch relief, and 521 (Intermediate) for tool and lab ownership

Benefits at Sentar:

  • Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty

Sentar is an affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities

We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at recruiting@sentar.com . Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.

Build, Innovate, Secure Your Career at Sentar.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Integrated Assessment / Malware Analyst
Senior Integrated Assessment / Malware Analyst

Sentar • United States

On-site
USD 120,000 - 170,000
Voluntary MedicalDentalVision options
Generous 401k match
Competitive PTO
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
Medical/Dental/Vision
Life & Disability Insurance
Group Term Life
+3
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Sentar Inc. • Fort Bragg (NC)

On-site
USD 95,000 - 130,000
Voluntary Medical, Dental, Vision
401(k) match
Paid time off
+3
SOC Tier 2 Watch Analyst
SOC Tier 2 Watch Analyst

Sentar • Fort Bragg (NC)

On-site
USD 95,000 - 135,000
401(k) match
Generous PTO
Medical/Dental/Vision
Exploitation Analyst (EA): Level 1-4
Exploitation Analyst (EA): Level 1-4

Sentar Inc. • Fort Meade (MD)

On-site
USD 80,000 - 100,000
Cigna Health Insurance
Guardian Vision and Dental Insurance
Time-off plan
+2
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar Inc. • Fort Bragg (NC)

On-site
USD 120,000 - 160,000
Voluntary medical, dental, vision
401(k) match
Paid time off
+4
Cyber Network Defense Analyst (CNDA)
Cyber Network Defense Analyst (CNDA)

Sentar Inc. • Fort Meade (MD)

On-site
USD 90,000 - 130,000
Health insurance options
Generous 401(k) match
Tuition reimbursement
+2
Computer Network Defense Analyst (CNDA) Level 1-4
Computer Network Defense Analyst (CNDA) Level 1-4

Sentar • Annapolis (MD)

On-site
USD 80,000 - 120,000
Medical, Dental, Vision insurance options
Generous 401(k) match
Competitive PTO plan
+2
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar • Northern (KY)

On-site
USD 120,000 - 180,000
Voluntary Medical, Dental, Vision
Flexible Spending Plan options
Group Term Life, Disability
+3
Red Team Adversary Emulation Tech Lead
Red Team Adversary Emulation Tech Lead

Sentar Inc. • Quantico (VA)

On-site
USD 140,000 - 230,000
Medical coverage
Dental coverage
Vision coverage
+4