Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Fairfax, VA, United States
Posted
Yesterday
AWSMFASplunkAzureCase ManagementDNSKubernetesPowerShellPythonRoot Cause AnalysisTriage
Job Description
Job Description
Everforth ECS is seeking a Cyber Threat Analyst (Tier 2) to work remotely .
ECS is seeking a Cyber Threat Analyst (Tier 2) to support a multi-tenant Managed Security Services Provider (MSSP) environment protecting commercial customers and internal systems. Please Note: This position is contingent upon contract award.
This position serves as a senior investigator within the Security Operations Center, leading complex investigations, supporting incident response activities, improving detection capabilities, and mentoring junior analysts. The ideal candidate possesses strong investigative and incident response experience, is capable of independently managing complex security events, and can operate effectively in a fast-paced MSSP environment supporting multiple customers simultaneously.
Responsibilities
Required Skills
Desired Skills
ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:
Meet the challenge. Make a difference with Everforth ECS!
Everforth ECS is seeking a Cyber Threat Analyst (Tier 2) to work remotely .
ECS is seeking a Cyber Threat Analyst (Tier 2) to support a multi-tenant Managed Security Services Provider (MSSP) environment protecting commercial customers and internal systems. Please Note: This position is contingent upon contract award.
This position serves as a senior investigator within the Security Operations Center, leading complex investigations, supporting incident response activities, improving detection capabilities, and mentoring junior analysts. The ideal candidate possesses strong investigative and incident response experience, is capable of independently managing complex security events, and can operate effectively in a fast-paced MSSP environment supporting multiple customers simultaneously.
Responsibilities
- Lead investigations involving malware, ransomware, business email compromise (BEC), account compromise, insider threats, cloud attacks, and advanced persistent threats.
- Perform incident response activities including forensic triage, scope determination, evidence collection, containment recommendations, root cause analysis, and post-incident reporting.
- Serve as the primary escalation point for Tier 1 analysts during complex investigations and security events.
- Manage multiple concurrent customer investigations while meeting service-level objectives and communication requirements.
- Coordinate response efforts with customers, IT teams, system administrators, and executive stakeholders.
- Develop detailed technical incident reports, executive summaries, and customer-facing communications.
- Conduct forensic triage across endpoints, servers, cloud platforms, email environments, and identity providers.
- Analyze and correlate telemetry from SIEM, EDR, SOAR, NDR, cloud monitoring platforms, identity providers, email security tools, and threat intelligence sources.
- Recommend, validate, test, and optimize detection content aligned with MITRE ATT&CK techniques and observed adversary behavior.
- Conduct targeted threat hunts based on intelligence requirements, active investigations, or emerging threats, and contribute findings to detection improvement efforts.
- Investigate security events across on-premises, cloud, SaaS, endpoint, network, and identity environments.
- Analyze attacker behavior and map observed activity to MITRE ATT&CK techniques to support reporting, threat tracking, and investigation activities.
- Utilize commercial and open-source threat intelligence to enrich investigations and identify emerging threats.
- Collaborate with Detection Engineering and SOAR teams to improve alert fidelity, reduce false positives, and increase operational efficiency.
Required Skills
- US. Citizenship with the ability to obtain and maintain a Secret Security Clearance.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. Relevant experience may be substituted for education.
- Minimum of 5 years of cybersecurity experience .
- Minimum of 3 years supporting Security Operations Center (SOC), MSSP, MDR, Incident Response, Threat Detection, or Cyber Defense operations.
- Strong understanding of modern attacker methodologies, threat actor tactics, techniques, and procedures (TTPs), and attack lifecycles.
- Experience investigating cybersecurity incidents from initial detection through containment, eradication, and recovery.
- Experience operating enterprise SIEM platforms including Microsoft Sentinel, Elastic, Splunk, QRadar, or equivalent technologies.
- Experience with EDR technologies including Microsoft Defender for Endpoint, CrowdStrike Falcon, Trellix, SentinelOne, or equivalent platforms.
- Experience with SOAR platforms, case management systems, and security automation technologies.
- Experience investigating Microsoft 365, Entra ID, Azure, AWS, or hybrid-cloud environments.
- Experience investigating identity-focused attacks including account compromise, privilege escalation, token abuse, suspicious authentication activity, and MFA-related attacks.
- Strong understanding of Windows, Linux, networking, DNS, email security, web technologies, and cloud architectures.
- Experience analyzing firewall, proxy, VPN, DNS, endpoint, NDR, identity, cloud, and authentication logs.
- Experience creating custom detections using KQL, Sigma, SPL, Elastic Query Language, or equivalent detection technologies.
- Ability to correlate events from multiple data sources and construct detailed attack timelines.
- Ability to perform ad hoc scripting and automation using Python, PowerShell, or similar languages.
- Strong written and verbal communication skills.
- Ability to independently manage multiple concurrent investigations while meeting customer and operational requirements.
Desired Skills
- Experience leading cybersecurity investigations during active incidents.
- Experience conducting proactive threat hunting activities across large datasets.
- Experience with endpoint and cloud forensic artifact analysis.
- Experience creating or improving incident response procedures, playbooks, and investigation workflows.
- Experience developing automated workflows using SOAR technologies.
- Experience supporting multi-tenant MSSP, MDR, consulting, or managed security environments.
- Experience validating detections through adversary emulation, purple team activities, or threat simulation exercises.
- Familiarity with malware analysis and modern threat intelligence platforms.
- Experience supporting cloud-native, containerized, or Kubernetes environments.
- Understanding of NIST 800-61, MITRE ATT&CK, Cyber Kill Chain, and modern incident response frameworks.
ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:
- Attracting and developing top talent and high-performing teams
- Fostering a culture that is engaging, accountable, and mission-driven
Meet the challenge. Make a difference with Everforth ECS!
Similar jobs
- AS
Cybersecurity Assessment and Authorization Validator with Security Clearance
NewAmerican Systems Corporation
Middletown, RI🇺🇸$83k - $125k/yrHybrid2 days agoTechnology - QS
Information System Security Engineer (ISSE)-Senior with Security Clearance
Quantech Services, Inc.
Fort Meade, MD🇺🇸Hybrid6 weeks agoCSSPKITechnology - LM
Cyber Systems Security Engineering with Security Clearance
NewLockheed Martin
Huntsville, AL🇺🇸HybridYesterdayAWSAzureGoogle Cloud+1Technology - MI
Lead Cyber Threat Intelligence Analyst with Security Clearance
NewMITRE Corporation
Bedford, MA🇺🇸$158.8k - $198.5k/yrOn-siteYesterdayTechnology - MI
Lead Cyber Threat Intelligence Analyst with Security Clearance
NewMITRE Corporation
Colorado Springs, CO🇺🇸$158.8k - $198.5k/yrOn-siteYesterdayTechnology - MA
Acquisition Security Analyst with Security Clearance
MANTECH
Los Angeles, CA🇺🇸On-site3 weeks agoTechnology