Senior Cybersecurity Analyst

Posted 5 Days Ago
Be an Early Applicant
Washington, DC, USA
Hybrid
Senior level
Security
The Role
Conduct advanced cybersecurity monitoring, incident detection, investigation, response, threat analysis, and security validation across on-premises and cloud environments. Perform authorized vulnerability validation, penetration-test finding reproduction, remediation verification, and application security testing. Develop incident-response procedures, testing methodologies, documentation, and playbooks while supporting offensive security, adversary emulation, and purple-team capabilities. Mentor junior analysts and collaborate with technical teams and government stakeholders.
Summary Generated by Built In

SAIC is looking for a Senior Cybersecurity Analyst supports Security Operations functions while helping establish and mature the organization's offensive security capability in support of a critical U.S. Government agency.

This position is responsible for advanced incident detection, investigation, response, threat analysis, and security monitoring across on-premises and cloud environments. In addition to traditional SOC responsibilities, the analyst performs authorized offensive security activities, including manual vulnerability validation, reproduction of penetration test findings, remediation verification, and security control validation to identify and validate security weaknesses requiring manual analysis beyond automated vulnerability scanning.

The position supports the development of repeatable security validation processes and the agency's evolving offensive security capability, which may expand over time to include application security assessments, adversary emulation, and purple team activities.

ONSITE 3 Days / Remote 2 days – Washington DC

Key Responsibilities:

  • Monitor, analyze, investigate, and respond to cybersecurity alerts and incidents using SIEM, endpoint detection and response (EDR), network monitoring, email security, identity security, and other enterprise security technologies.
  • Perform advanced incident triage to determine scope, impact, attack vectors, and recommend appropriate containment, eradication, recovery, and mitigation activities.
  • Analyze network traffic, endpoint telemetry, authentication events, application logs, system logs, and threat intelligence to identify malicious activity and indicators of compromise.
  • Lead or support investigations involving phishing, malware, unauthorized access, insider threats, data exposure, and other cybersecurity events.
  • Develop, maintain, and improve incident response procedures, investigative workflows, technical documentation, and response playbooks.
  • Review, assign, document, and track cybersecurity incidents and operational activities using approved ticketing and documentation systems.
  • Support investigations involving DHS, CISA, US-CERT, vendor advisories, and other cybersecurity notifications affecting agency systems.
  • Provide technical leadership, mentorship, and knowledge sharing to junior cybersecurity analysts.
  • Conduct authorized offensive security activities, including manual vulnerability validation, reproduction of penetration test findings, remediation verification, and security control validation.
  • Perform recurring validation testing of known vulnerabilities and security deficiencies to verify exploitability, assess technical impact, and confirm remediation effectiveness.
  • Perform manual testing of applications, APIs, identity services, wireless technologies, and other designated systems using approved security assessment tools and methodologies.
  • Distinguish confirmed vulnerabilities from false positives, configuration issues, environmental conditions, and non-exploitable findings, and document technical evidence, remediation recommendations, and validation results.
  • Develop repeatable testing procedures, validation methodologies, assessment documentation, and technical guidance to support recurring security validation activities.
  • Collaborate with Security Operations, Patch and Vulnerability Management, application teams, infrastructure teams, system owners, and external assessors to improve the agency's overall security posture.
  • Identify opportunities to improve security monitoring, detection logic, logging, defensive controls, and incident response based on manual security assessment results.
  • Research emerging threats, vulnerabilities, and offensive security techniques to support continuous improvement of organizational cybersecurity capabilities.
  • Support the continued development of internal offensive security, application security, adversary emulation, and purple team capabilities while performing all activities within approved authorization, scope, rules of engagement, and operational safeguards.
Qualifications

Qualifications & Experience:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Additional relevant experience may be substituted in lieu of a degree.
  • Five or more years of experience in cybersecurity operations, Security Operations Center (SOC) activities, incident response, vulnerability management, security engineering, or related cybersecurity disciplines.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. 
  • Demonstrated experience investigating, analyzing, and responding to cybersecurity incidents.
  • Strong understanding of cybersecurity principles, attack methodologies, common threat vectors, and NIST incident response guidance.
  • Experience analyzing network traffic, endpoint telemetry, authentication activity, application logs, system logs, and threat indicators.
  • Experience with enterprise cybersecurity technologies, including SIEM, EDR, email security, identity security, privileged access management, and threat intelligence platforms.
  • Working knowledge of TCP/IP, DNS, HTTP/HTTPS, authentication protocols, Windows, Linux, cloud environments, enterprise networking, and common application architectures.
  • Understanding of web applications, APIs, authentication, authorization, session management, and common application security vulnerabilities.
  • Ability to learn, adapt to, and effectively utilize agency-approved offensive security methodologies, manual security assessment techniques, and supporting technologies.
  • Ability to reproduce technical findings, validate vulnerabilities, document repeatable testing procedures, and communicate technical results.
  • Strong analytical, troubleshooting, organizational, technical writing, and communication skills.
  • Ability to work independently while collaborating effectively across technical teams, application owners, and government stakeholders.

Preferred Qualifications:

  • Experience conducting manual vulnerability validation, application security testing, remediation verification, or penetration testing activities.
  • Experience reproducing and validating findings identified through penetration testing, vulnerability assessments, or independent security assessments.
  • Familiarity with OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and common offensive security methodologies.
  • Experience evaluating authentication, authorization, business logic, API security, identity security, wireless security, or other application security controls.
  • Experience supporting federal cybersecurity operations, FISMA compliance, or DHS/CISA cybersecurity activities.
  • Experience developing scripts or automating security tasks using Python, PowerShell, SQL, or similar technologies.
  • Relevant cybersecurity certifications such as CISSP, Security+, CySA+, PenTest+, GPEN, GWAPT, GWEB, PNPT, OSCP, or equivalent.
About UsSAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field; additional relevant experience may substitute.
  • Five or more years of experience in cybersecurity operations, SOC activities, incident response, vulnerability management, security engineering, or related disciplines.
  • Ability to obtain and maintain a Public Trust clearance; requires U.S. Citizenship or Green Card.
  • Experience investigating, analyzing, and responding to cybersecurity incidents.
  • Strong understanding of cybersecurity principles, attack methodologies, threat vectors, and NIST incident response guidance.
  • Experience analyzing network traffic, endpoint telemetry, authentication activity, application logs, system logs, and threat indicators.
  • Experience with SIEM, EDR, email security, identity security, privileged access management, and threat intelligence platforms.
  • Working knowledge of TCP/IP, DNS, HTTP/HTTPS, authentication protocols, Windows, Linux, cloud environments, enterprise networking, and application architectures.
  • Understanding of web applications, APIs, authentication, authorization, session management, and common application security vulnerabilities.
  • Ability to use approved offensive security methodologies, manual security assessment techniques, and supporting technologies.
  • Ability to reproduce technical findings, validate vulnerabilities, document repeatable testing procedures, and communicate technical results.
  • Strong analytical, troubleshooting, organizational, technical writing, and communication skills.
  • Ability to work independently and collaborate across technical teams, application owners, and government stakeholders.
  • Experience with manual vulnerability validation, application security testing, remediation verification, or penetration testing.
  • Familiarity with OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and offensive security methodologies.
  • Experience evaluating authentication, authorization, business logic, API security, identity security, or wireless security controls.
  • Experience supporting federal cybersecurity operations, FISMA compliance, or DHS/CISA cybersecurity activities.
  • Experience developing scripts or automating security tasks using Python, PowerShell, SQL, or similar technologies.
  • Relevant cybersecurity certifications such as CISSP, Security+, CySA+, PenTest+, GPEN, GWAPT, GWEB, PNPT, or OSCP.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stamford, CT
34,000 Employees

What We Do

Spectrum San Diego is a high tech security innovator, specializing in ultra-low-dose X-ray screening systems.

Similar Jobs

Cherokee Federal Logo Cherokee Federal

Operations Analyst

Information Technology • Professional Services • Defense • Manufacturing
In-Office or Remote
Washington, DC, USA
5000 Employees
145K-165K Annually
In-Office
20376, Washington Navy Yard, DC, USA
88 Employees
127K-138K Annually

Apollo.io Logo Apollo.io

Senior Manager, Solution Consulting

Artificial Intelligence • Enterprise Web • Information Technology • Productivity • Sales • Software • Database
Easy Apply
In-Office or Remote
3 Locations
850 Employees
230K-280K Annually

CrowdStrike Logo CrowdStrike

Business Systems Analyst

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
100K-155K Annually

Similar Companies Hiring

Closinglock Thumbnail
Fintech • Real Estate • Security • Software • Financial Services • Cybersecurity • PropTech
Austin, TX
110 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account