Haystack
← Back to Jobs
Employee
Technology
II

Senior Cyber Defense Analyst III with Security Clearance

InvictusColorado Springs, CO🇺🇸United StatesPosted Oct 5, 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to lead advanced cyber defense investigations and mentor junior analysts within a highly reputable organization, leveraging your TS/SCI clearance. You'll thrive here if you're a proactive problem-solver eager to refine incident response strategies and contribute to critical national security efforts. Apply now to elevate your career in a dynamic and impactful environment.

Quick Overview

Seniority
Mid Senior
Employment type
Employee
Work mode
Hybrid
Location
Colorado Springs, CO, United States
Posted
2 days ago
LESS

Job Description

Title: Senior Cyber Defense Analyst III Location: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Description: Invictus, a Red River company, delivers technology and services supporting government and national security missions. We combine cleared mission expertise with enterprise engineering, technology partnerships and large-program execution in support of advanced modernization, cybersecurity, intelligence and systems integration. Our teams support complex operational environments across the U.S. and around the world, helping customers strengthen resilience, accelerate mission outcomes and deploy capabilities that meet demanding mission requirements. Learn more at www. InvictusIC.com.

Job Details

  • Perform and lead advanced investigation of complex security events and incidents across network, endpoint, identity, firewall, vulnerability, and other available telemetry
  • Perform cyber defense incident triage, including validation, enrichment, determination of scope, urgency, potential impact, and appropriate escalation
  • Support incident handling across detection, investigation, analysis, containment/remediation coordination, recovery, and reporting in accordance with established authorities and procedures
  • Correlate incident and security data across multiple sources to identify affected systems, users, vulnerabilities, adversary activity, and related events
  • Collect and preserve relevant intrusion artifacts and investigative evidence in accordance with established procedures
  • Communicate incident status, findings, risk, and recommended actions to SOC personnel, technical teams, management, and government stakeholders as appropriate
  • Serve as a senior technical escalation point to less expereinced team members and provide hands-on guidance during complex investigations
  • Lead portions of incident response activities, including scoping, evidence analysis, containment recommendations, technical coordination, and post-incident review
  • Conduct proactive analysis and threat hunting when warranted to identify related or previously undetected activity
  • Develop, maintain, and improve analyst runbooks, investigative procedures, escalation criteria, incident playbooks, and shift-turnover practices
  • Partner with threat analysts and engineering personnel to identify telemetry gaps, detection gaps, false positives, and opportunities for improved enrichment or automation
  • Mentor junior analysts, support analyst qualification and exercises, and perform quality review of investigations and case documentation
  • Translate incident lessons learned into improved detections, procedures, training, and defensive recommendations Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum six (6) years of relevant experience in addition to education level
  • Significant hands-on experience conducting cybersecurity investigations and incident response in enterprise environments.
  • Strong knowledge of network and host-based investigation, common adversary tactics, techniques, and procedures, and the MITRE ATT&CK framework
  • Experience developing or improving SOC procedures, incident playbooks, runbooks, or analyst training materials
  • Experience serving as an escalation point, technical lead, or mentor for cyber defense analysts
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Similar jobs