Haystack
← Back to Jobs
Temporary/Casual
Technology
BO

Host Based Systems Analyst - IV – SME with Security Clearance

Base One TechnologiesArlington, VA🇺🇸United StatesPosted Jul 13, 2026

Why This Role Stands Out

Advance your cybersecurity career with a hybrid role that offers significant growth potential in cutting-edge cloud and identity forensics. You'll thrive if you possess a strong background in incident response and a passion for developing advanced detection strategies, especially with your active TS/SCI clearance. Apply now to join a reputable organization and make a real impact in a dynamic field.

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
Arlington, VA, United States
Posted
2 months ago
DockerGCPAWSAzureBashCloudFormationJavaScriptKubernetesPowerShellPythonTerraform

Job Description

Responsibilities

  • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
  • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
  • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
  • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
  • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
  • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
  • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.

Required Skills

  • U.S. Citizenship
  • Active TS/SCI clearance
  • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
  • 5+ years of experience in cyber forensic investigations with leading tools and techniques.
  • Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.
  • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
  • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
  • Knowledge of AWS, IAM, and best practices for cloud identity security.

Desired Skills

  • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
  • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
  • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).

Required Education

BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 7+ years relevant experience.

Desired Certifications

GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS or Microsoft Cloud/Security certifications

Similar jobs