Cyber Threat Analyst (Tier 2)

Posted 3 Days Ago
Be an Early Applicant
Homeland, VA, USA
In-Office
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Lead complex cybersecurity investigations in a multi-tenant MSSP Security Operations Center. Perform forensic triage, incident response, threat hunting, root cause analysis, and customer reporting across endpoint, cloud, identity, email, network, and SaaS environments. Escalate and mentor Tier 1 analysts, coordinate with customers and technical stakeholders, correlate SIEM and security telemetry, improve detections aligned with MITRE ATT&CK, and collaborate with detection engineering and SOAR teams to improve alert fidelity and operational efficiency.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Cyber Threat Analyst (Tier 2) to work remotely

 

ECS is seeking a Cyber Threat Analyst (Tier 2) to support a multi-tenant Managed Security Services Provider (MSSP) environment protecting commercial customers and internal systems. Please Note: This position is contingent upon contract award.

This position serves as a senior investigator within the Security Operations Center, leading complex investigations, supporting incident response activities, improving detection capabilities, and mentoring junior analysts. The ideal candidate possesses strong investigative and incident response experience, is capable of independently managing complex security events, and can operate effectively in a fast-paced MSSP environment supporting multiple customers simultaneously.

Responsibilities
  • Lead investigations involving malware, ransomware, business email compromise (BEC), account compromise, insider threats, cloud attacks, and advanced persistent threats.
  • Perform incident response activities including forensic triage, scope determination, evidence collection, containment recommendations, root cause analysis, and post-incident reporting.
  • Serve as the primary escalation point for Tier 1 analysts during complex investigations and security events.
  • Manage multiple concurrent customer investigations while meeting service-level objectives and communication requirements.
  • Coordinate response efforts with customers, IT teams, system administrators, and executive stakeholders.
  • Develop detailed technical incident reports, executive summaries, and customer-facing communications.
  • Conduct forensic triage across endpoints, servers, cloud platforms, email environments, and identity providers.
  • Analyze and correlate telemetry from SIEM, EDR, SOAR, NDR, cloud monitoring platforms, identity providers, email security tools, and threat intelligence sources.
  • Recommend, validate, test, and optimize detection content aligned with MITRE ATT&CK techniques and observed adversary behavior.
  • Conduct targeted threat hunts based on intelligence requirements, active investigations, or emerging threats, and contribute findings to detection improvement efforts.
  • Investigate security events across on-premises, cloud, SaaS, endpoint, network, and identity environments.
  • Analyze attacker behavior and map observed activity to MITRE ATT&CK techniques to support reporting, threat tracking, and investigation activities.
  • Utilize commercial and open-source threat intelligence to enrich investigations and identify emerging threats.
  • Collaborate with Detection Engineering and SOAR teams to improve alert fidelity, reduce false positives, and increase operational efficiency.

 

Preferred Qualifications
  • US. Citizenship with the ability to obtain and maintain a Secret Security Clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. Relevant experience may be substituted for education.
  • Minimum of 5 years of cybersecurity experience.
  • Minimum of 3 years supporting Security Operations Center (SOC), MSSP, MDR, Incident Response, Threat Detection, or Cyber Defense operations.
  • Strong understanding of modern attacker methodologies, threat actor tactics, techniques, and procedures (TTPs), and attack lifecycles.
  • Experience investigating cybersecurity incidents from initial detection through containment, eradication, and recovery.
  • Experience operating enterprise SIEM platforms including Microsoft Sentinel, Elastic, Splunk, QRadar, or equivalent technologies.
  • Experience with EDR technologies including Microsoft Defender for Endpoint, CrowdStrike Falcon, Trellix, SentinelOne, or equivalent platforms.
  • Experience with SOAR platforms, case management systems, and security automation technologies.
  • Experience investigating Microsoft 365, Entra ID, Azure, AWS, or hybrid-cloud environments.
  • Experience investigating identity-focused attacks including account compromise, privilege escalation, token abuse, suspicious authentication activity, and MFA-related attacks.
  • Strong understanding of Windows, Linux, networking, DNS, email security, web technologies, and cloud architectures.
  • Experience analyzing firewall, proxy, VPN, DNS, endpoint, NDR, identity, cloud, and authentication logs.
  • Experience creating custom detections using KQL, Sigma, SPL, Elastic Query Language, or equivalent detection technologies.
  • Ability to correlate events from multiple data sources and construct detailed attack timelines.
  • Ability to perform ad hoc scripting and automation using Python, PowerShell, or similar languages.
  • Strong written and verbal communication skills.
  • Ability to independently manage multiple concurrent investigations while meeting customer and operational requirements.

Skills Required

  • US citizenship with the ability to obtain and maintain a Secret Security Clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field; relevant experience may substitute
  • Minimum of 5 years of cybersecurity experience
  • Minimum of 3 years supporting SOC, MSSP, MDR, incident response, threat detection, or cyber defense operations
  • Strong understanding of attacker methodologies, threat actor TTPs, and attack lifecycles
  • Experience investigating cybersecurity incidents through detection, containment, eradication, and recovery
  • Experience operating enterprise SIEM platforms such as Microsoft Sentinel, Elastic, Splunk, QRadar, or equivalent
  • Experience with EDR technologies such as Microsoft Defender for Endpoint, CrowdStrike Falcon, Trellix, SentinelOne, or equivalent
  • Experience with SOAR platforms, case management systems, and security automation technologies
  • Experience investigating Microsoft 365, Entra ID, Azure, AWS, or hybrid-cloud environments
  • Experience investigating identity-focused attacks, including account compromise, privilege escalation, token abuse, suspicious authentication, and MFA attacks
  • Strong understanding of Windows, Linux, networking, DNS, email security, web technologies, and cloud architectures
  • Experience analyzing firewall, proxy, VPN, DNS, endpoint, NDR, identity, cloud, and authentication logs
  • Experience creating custom detections using KQL, Sigma, SPL, Elastic Query Language, or equivalent technologies
  • Ability to correlate events from multiple data sources and construct detailed attack timelines
  • Ability to perform ad hoc scripting and automation using Python, PowerShell, or similar languages
  • Strong written and verbal communication skills
  • Ability to independently manage multiple concurrent investigations while meeting customer and operational requirements

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elkhorn, NE
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

QBE LLC Logo QBE LLC

Systems Analyst

Information Technology • Professional Services • Consulting • Defense
In-Office
Haymarket, VA, USA
66 Employees
100K-115K Annually

Samsara Logo Samsara

Analytics Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
119K-180K Annually

Capital One Logo Capital One

Principal Risk Specialist, Compliance Governance Analyst

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
2 Locations
55000 Employees
110K-138K Annually

Capital One Logo Capital One

Compliance Tester II

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
3 Locations
55000 Employees
88K-110K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account