Haystack
← Back to Jobs
Employee
Administrative

Cyber Defence Analyst/Threat Hunter with Security Clearance

ICS Nett, Inc.Quantico, VA🇺🇸United StatesPosted 26 Jul 2026

Why This Role Stands Out

This on-site role offers a critical opportunity to defend vital mission systems and develop advanced threat hunting skills using cutting-edge security tools. You'll thrive here if you possess a strong background in cyber defense concepts and a proactive approach to safeguarding enterprise infrastructure, contributing to a secure environment for important Department of War missions.

Quick Overview

Work Type
On Site
Schedule
Employee
Level
Mid Senior

Job Description

Cyber Defense Analyst
DCSA Cyber Program ICS Nett, Inc. is seeking a highly skilled and experienced Cyber Defense Analyst/Threat Hunter to join our dynamic team on the swing shift (2.30 PM to 11.00 PM), to provide support coverage that includes weekend and holiday rotations. This is an on-site position at Quantico, VA The selected candidate will perform complete network security monitoring and proactively identify potential threats across our enterprise infrastructure. This role is critical for defending mission systems, conducting in-depth traffic and vulnerability analysis, and maintaining a strong security posture in support of Department of War (DOW) missions.
Position Description: The Cyber Defense Analyst /Threat Hunter is an important role responsible for performing comprehensive network security monitoring and proactive threat hunting during swing-shift, weekend, and holiday coverage windows. This position focuses on safeguarding the network through continuous traffic analysis, vulnerability and wireless scanning, and leveraging enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Analyst will collaborate with cross-functional IT and security teams to:
• Implement Information Assurance Vulnerability Management (IAVM) programs
• Manage Network Access Control
• Provide insider threat support
• Monitor data at rest
• Review web content filtering
• Maintain and upkeep various cybersecurity applications and tools on servers and workstations to ensure high operational readiness during all covered hours
Minimum Requirements: • At least five (5) Years – Hands-on technical cybersecurity experience and knowledge of Computer Network Defense concepts, DISA Security Technical Information Implementation Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
• Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
• Batchelor’s degree in information technology, Information Systems Management, Cyber Security, or equivalent experience.
• Must meet 8570 certification requirements at the time of hire. IAT Level II (e.g., CCNA Security, CySA +, GICSP, GSEC, Security+, SSSP or a CSSP Auditor Certification CEH, CISA, GSNA is preferred).
• Willingness and availability to work the swing shift (1430 – 2300), including weekend and holiday rotations, fully on-site at Quantico, VA.
Required Skills:
• Log Analysis & Threat Identification: Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to identify possible security threats (e.g., determine rogue systems, infected systems, unauthorized system changes, and unauthorized hardware connections).
• Policy Enforcement: Ability to identify violations of internet access by reviewing web content filtering logs in accordance with DoD policy, and Standard Operating Procedures (SOPs).
• Task Management: Experience in processing and handling JFHQ DODIN Cyber related tasks to completion.
• Proactive Threat Hunting: Performance of threat hunting activities using DoD approved cyber tools through data hunting, manipulation, and presentation, including generating queries and reports for management and the end-customer.
• Incident Assessment: Validation and confirmation of critical security events and assessing the impact of the event, by incorporating data from multiple tool sources.
• Investigation & Forensics: Identifying evidence of illegal activity involving cybercrime offenses and examining computers that may have been involved in other types of crime or malware infection.
• Malware Analysis: Use of forensic tools and investigative methods to find specific electronic data, namely associated with performing complex malware analysis.
• Process Documentation: Experience developing and maintaining SOPs for security monitoring.
• Reporting: Provide daily/weekly/monthly reports to senior leadership on key indicators of network security.
Work Environment – On Site. • This is a fully on-site position at DCSA facilities, Quantico, VA. • Must be flexible to work swing shift (2.30 PM to 11.00 PM) and support weekend and holiday coverage as scheduled.
Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form

Similar jobs