Threat Management Specialist - Tier2 (shift work) - no C2C candidates please)

Tier One Technologies, LLC

United States

Hybrid

USD 90,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading technology firm is seeking a Threat Management Specialist to work with a US Government client. The specialist will analyze network traffic, recommend detection mechanisms, and leverage AI for incident response. Required qualifications include a Bachelor's or Master's degree in Computer Science, 8 years of IT Security experience, and familiarity with AI/ML. The position offers competitive compensation and a hybrid work schedule.

Qualifications

  • 8+ years of IT Security experience required.
  • 2+ years of network traffic analysis experience required.
  • Familiarity with AI/ML projects is essential.

Responsibilities

  • Identify cybersecurity threats and gaps that require mitigating controls.
  • Analyze network traffic to detect exploit attempts, intrusions, and anomalous behavior.
  • Recommend and implement detection mechanisms for exploit- and intrusion-related activity.

Skills

Network traffic analysis
Cybersecurity automation
AI/ML familiarity
Incident response
Data analysis

Education

Bachelor's or Master's Degree in Computer Science

Tools

Splunk
Cisco Firepower
Proofpoint
SentinelOne

Job description

Threat Management Specialist - Tier2 (shift work) - no C2C candidates please)

Please note that all applicants must be US Citizens and no C2C candidates will be accepted.

Summary:

  • Tier One Technologies is looking for a Tier2 Threat Management Specialist to work with our direct US Government client.
  • This hybrid contract-to-hire position can be located in Raleigh, NC or Falls Church, VA or Eagan, MN.
  • Available shifts: 3:30 PM to 11:30 PM EST with Tuesday & Wednesday days off or 11:30 PM to 7:30 AM EST with Saturday & Sunday days off.
  • SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT.
Responsibilities
  • Identify cybersecurity threats and gaps that require mitigating controls.
  • Analyze network traffic to detect exploit attempts, intrusions, and anomalous behavior.
  • Recommend and implement detection mechanisms for exploit- and intrusion-related activity.
  • Provide subject matter expertise in network-based attacks, traffic analysis, and intrusion methodologies.
  • Escalate incidents requiring deeper investigation to senior members of the Threat Management team.
  • Execute operational processes in support of security incident response efforts.
  • Leverage AI/ML-based tools to detect anomalies, automate incident triage, and enhance threat intelligence.
  • Perform and analyze threat intelligence to assess risk and adapt defenses using ML-enhanced tools.
  • Manage email security using Proofpoint; monitor threats and respond rapidly to attacks.
  • Configure and maintain Splunk for log analysis, alert creation, and security incident investigation.
  • Configure Cisco Firepower for network monitoring, analyze traffic patterns, and enforce security controls.
  • Deploy and manage SentinelOne agents, monitor alerts, and conduct comprehensive security assessments.
  • Monitor, review, and respond to security alerts and incidents across multiple platforms, including MS Defender for Cloud Apps, Defender for Endpoint, Defender XDR, Defender for Office 365, Azure Entra ID, and Google Cloud Security Command Center (SCC).
  • Conduct threat detection and analysis, investigate suspicious activity, coordinate incident response, and implement remediation actions.
  • Tune security policies, maintain visibility across cloud and endpoint environments, and support continuous security posture improvement.
  • Stay current with emerging cybersecurity threats, threat actors, and AI/ML research.
  • Identify and support security automation use cases, including AI/ML-driven SOC enhancements.
  • Collaborate across Operations to deliver SOC capability improvements through automation and AI.
Qualifications
  • Bachelor's or Master's Degree in Computer Science, Information Systems, or other related fields.
  • 8+ years of IT Security experience.
  • 2+ years of network traffic analysis experience.
  • Familiarity with AI/ML projects.
  • Certifications (One or more required): GIAC Certified Enterprise Defender (GCED) or GIAC Certified Security Essentials (GSEC) or CISSP, or SSCP.
  • Strong working knowledge of Boolean Logic, TCP/IP Fundamentals, Network Level Exploits and Threat Management.
  • Strong understanding of IDS/IPS technologies, trends, vendors, processes and methodologies.
  • Strong understanding of common IDS/IPS architectures and implementations.
  • Strong understanding of IDS/IPS signatures, content creation and signature characteristics including both signature and anomaly-based analysis and detection.
  • Prior experience with cloud security (AWS, Azure, GCP).
  • Hands‑on experience with cybersecurity automation (e.g., SOAR platforms).
  • Proficiency in using machine learning frameworks to develop, train, and deploy models for anomaly detection, threat intelligence, and behavioral analysis in cybersecurity contexts.
  • Skills in data analysis and feature engineering, with the ability to preprocess and transform large datasets from various sources (e.g., logs, network traffic) to extract relevant features for machine learning models aimed at identifying security incidents and vulnerabilities.
  • Familiarity with the application of AI/ML techniques in cybersecurity, including but not limited to automated threat detection, incident response automation, and predictive analytics. Experience in evaluating the effectiveness of AI/ML solutions in a SOC environment is a plus.
  • Understanding and experience identifying and implementing automation use cases.
  • Knowledge of Control Frameworks and Risk Management techniques.
  • Excellent oral and written communication skills.
  • Must be able to obtain a Position of Public Trust Clearance.
  • All candidates must be a US Citizen or have permanent residence status (Green Card).
  • Candidate must have lived in the United States for the past 5 years.
  • Cannot have more than 6 months travel outside the United States within the last 5 years. Military Service excluded.
Employment Details

Seniority level: Mid‑Senior level. Employment type: Contract.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Management Specialist (Tier 2)
Threat Management Specialist (Tier 2)

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 150,000
Cyber Threat Analyst II
Cyber Threat Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 120,000
Incident Manager II
Incident Manager II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 56,000 - 66,000
Tier 2 Shift Lead- Secret Clearance
Tier 2 Shift Lead- Secret Clearance

Koitecc Solutions • Beltsville (MD), Northern (KY)

On-site
USD 100,000 - 124,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Tier 2 Shift Lead- Secret Clearance
Tier 2 Shift Lead- Secret Clearance

Veterans Enterprise Technology Solutions Inc • Beltsville (MD)

On-site
USD 100,000 - 124,000
ON-SITE WORK ONLY
Cybersecurity Incident Manager (2nd Shift/OnSite)
Cybersecurity Incident Manager (2nd Shift/OnSite)

Triangle Cyber, LLC • Arlington (VA)

On-site
USD 120,000 - 150,000
Network Based Systems Analyst II
Network Based Systems Analyst II

Solutions³ LLC • Arlington (VA)

On-site
USD 95,000 - 130,000
Tier 2 Cybersecurity Engineer
Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC • Houston (TX)

On-site
USD 110,000 - 170,000
Health insurance
Retirement plan
Disability insurance
+3