Cyber Analyst
Location: Hill Air Force Base, UT. Clearance Required: Secret; Top Secret preferred. Employment Type: Full-Time.
About the Role
The JAAW Group LLC, a Service-Disabled Veteran-Owned Small Business (SDVOSB), is seeking a Cyber Analyst to support secure, mission-critical Department of Defense systems at Hill Air Force Base. This role focuses on continuous security monitoring, threat detection, incident response, and threat hunting across classified government environments.
The Cyber Analyst will monitor security telemetry, investigate suspicious activity, triage security alerts, and support incident response while working closely with Security Engineers, ISSOs, and other technical teams to identify threats, coordinate remediation, and strengthen the overall cybersecurity posture of mission systems.
Responsibilities
- Monitor SIEM platforms, including Splunk, for security events, alerts, and anomalous activity across mission systems.
- Triage and investigate cybersecurity alerts and escalate confirmed incidents in accordance with established procedures.
- Perform proactive threat hunting to identify indicators of compromise and suspicious activity.
- Participate in cybersecurity incident handling and response activities, including documenting findings and recovery actions.
- Support root-cause investigations for confirmed security incidents.
- Coordinate with ISSOs, Security Engineers, and other cybersecurity personnel on incident reporting, remediation, and recovery activities.
- Support vulnerability scanning and assessment activities using tools such as Nessus and ACAS.
- Assist with STIG compliance verification using SCAP Compliance Checker, Evaluate-STIG, or similar DoD cybersecurity tools.
- Contribute findings to Plan of Action and Milestones (POA&M) tracking and remediation efforts.
- Document detection logic, investigation procedures, playbooks, and other cybersecurity processes.
- Partner with Security Engineers to improve security telemetry, detection capabilities, and alert tuning.
- Participate in Agile delivery activities, including sprints, standups, retrospectives, and continuous process improvement.
Required Qualifications
- Active Secret security clearance required prior to onboarding; Top Secret preferred.
- U.S. citizenship required.
- Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related field; relevant certifications may be considered in lieu of a degree.
- 2–5 years of experience in security monitoring, SOC/NOC operations, cyber defense, or a related cybersecurity role.
- Hands-on experience with SIEM platforms, with Splunk preferred.
- Working knowledge of vulnerability management tools such as Nessus and ACAS.
- Familiarity with STIG compliance tools such as SCAP Compliance Checker and Evaluate-STIG.
- Working knowledge of TCP/IP networking and network security fundamentals.
- Familiarity with cybersecurity incident response processes and documentation standards.
- Strong troubleshooting, analytical, communication, and problem-solving skills.
- Ability to work effectively in an Agile, fast-paced, mission-focused environment.
- Willingness to support shift-based or on-call coverage as required.
Preferred Qualifications
- Active Top Secret security clearance with SCI eligibility.
- DoD 8570 CSSP Analyst certification or equivalent, such as GCIA or CySA+.
- CompTIA Security+ or equivalent security certification.
- Experience with threat hunting methodologies and frameworks, including MITRE ATT&CK.
- Experience with cloud security monitoring in AWS or Microsoft Azure environments.
- Familiarity with container security technologies, including Docker, Kubernetes, ECS, EKS, or AKS.
- Experience supporting Department of Defense or other classified government environments.
Learn more about this Employer on their Career Site
