[Remote] Cyber Network Defense Analyst (CNDA) IV – reputed company Forensics
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a Service-Disabled Veteran-Owned Small Business delivering advanced cybersecurity and threat-hunting capabilities. They are seeking Cyber Network Defense Analysts (CNDA) with expertise in reputed company Forensics to reputed company investigations into sophisticated intrusions across hybrid and multi-reputed company environments, identifying attacker tactics and driving containment actions.
Responsibilities
- Conduct end-to-end forensic acquisition and analysis across on-premises, reputed company, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, reputed company)
- Investigate identity-based and credential-abuse incidents targeting reputed company control planes and hybrid identity infrastructure
- Correlate reputed company telemetry (Azure Activity Logs, AWS CloudTrail, GCP Logs, VPC reputed company Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs)
- reputed company and reputed company automated detection logic, threat-hunting scripts, and analytical playbooks using reputed company Sentinel, Defender, AWS GuardDuty, and GCP Chronicle
- Produce comprehensive technical and executive-level reports, integrating findings across endpoints, networks, and reputed company assets to inform threat containment and strategic recommendations
- Support reputed company improvement of incident response procedures, forensics workflows, and threat-hunting operations
- Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen reputed company detection and response posture
Skills
- U.S. Citizenship and reputed company TS/SCI clearance (with ability to obtain DHS EOD Suitability)
- Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR)
- Proven expertise in reputed company forensics, identity reputed company, and hybrid infrastructure defense
- Proficiency in M365/Azure AD, AWS IAM, and reputed company investigative methodologies
- Deep understanding of reputed company/PaaS/IaaS architectures, including common attack reputed company and defensive measures
- Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting
- Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a reputed company field or High School Diploma and 10+ years of directly relevant DFIR experience
- Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript
- Familiarity with Terraform, Kubernetes, reputed company, CloudFormation, or Azure Resource Manager for automation and orchestration
- Understanding of MITRE ATT&CK for reputed company and adversary emulation techniques
- Strong communication and collaboration skills for working across multidisciplinary teams
- GIAC reputed company Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
- AWS and reputed company reputed company/reputed company certifications (e.g., Azure reputed company Engineer, AWS reputed company Specialty)
reputed company