Cyber Threat Detection - Active Defense Analyst
$128.1k - $239.6kErnst & Young Oman
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. EY Technology: Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have 250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything from the laptops we use, to the ability to work remotely on our mobile devices and connecting our people and our clients, to enabling hundreds of internal tools and external solutions delivered to our clients. Technology solutions are integrated in the client services we deliver and is key to us being more innovative as an organization. EY Technology supports our technology needs through three business units: Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster, and pursue those opportunities more rapidly. Enterprise Workplace Technology (EWT) – EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience. Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems. The opportunity The Active Defense team is responsible for four core areas: Network Reconnaissance, Proactive Penetration Testing (Purple Team), Anomaly Analysis, and Trapping and Coercion. This function allows the Cyber Defense Team to fortify and mature the firm’s enterprise security. In an Active Defense Analyst, we are looking for someone who has experience in Information Security and wants to take the next step in the adventure. In its purple team capacity, candidates will be expected to emulate attacker behaviors and devise strategies to disrupt the actions of an attacker, thus enhancing the abilities of defensive teams. In the threat hunting capacity, the analyst will identify security vulnerabilities through analysis of event data from SIEM and other relevant tools. You will report findings to technical and non-technical audiences, and collaborate with other teams identify and remediate vulnerabilities. The position requires attention to detail and the ability to work, both as part of a team and independently. Skills and attributes for success Essential Functions of the job: Perform research and analysis of attacker techniques and methodologies, and emulate those attacks in a collaborative and controlled environment Identify security breaches through ‘Hunting’ operations within a SIEM, full packet capture, EDR, and other tools and treat intelligence Identify patterns consistent with sophisticated attacker methodologies, and report on security concerns as they are escalated or identified. Analyze artifacts collected during a security test or passive investigation. Communicate with server owners, system custodians, and IT contacts to pursue security testing activities, including: obtaining access to systems, digital artifact collection, and containment and/or remediation actions Create presentations in MS Word, PowerPoint, and/or Excel that support findings Maintain, manage, improve and update security testing process and protocol documentation Assist in analyzing findings, and develop fact based reports Identify means to disrupt attacker actions, and enhance defender response capabilities. To qualify for the role, you must have: 6+ years of relevant experience in one or more of the following areas: threat intelligence, intrusion analysis, incident response, malware analysis, security and network operations, penetration tester, or similar roles. Demonstrated understanding of the threat intelligence life cycle, network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs). Knowledgeable in security incident response process, procedures, and life-cycle, including performing security audits as part of red team Good understanding of both Windows and Unix/Linux based operating systems Understanding of IP networking concepts, to include addressing, routing, common protocol usage, use of proxies, load balancers, firewalls, routers, and switches in network architecture. Global mind-set for working with different cultures and backgrounds Demonstrated integrity and judgment within a professional environment Ability to appropriately balance work/personal priorities Teaming skills as well as ability to work independently on taskings Good social, communication, and writing skills Qualifications, Certifications and Education requirements: Associates Degree and/or any of the following certifications: GPEN, CISSP, Security+, GCIH, OSCP, GCFE, CFCE, other relevant GIAC certs. Familiarity with EDR, SIEM, Scripting, Malware Analysis. Preferred: Some hands-on experience as an administrator configuring one or more of SIEM, Endpoint Protection, Vulnerability Scanners, or Data Loss Prevention Proficient with one or more scripting languages such as Perl, Python, PowerShell etc. in a threat intelligence or incident response environment Supervising Responsibilities: However, the role requires mentoring, collaboration, and training of more junior associates. On rare occasions, may be required to work nights or weekends in support of incident response or penetration audits. What we offer you The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more . We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $128,100 to $239,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $153,800 to $272,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being. Are you ready to shape your future with confidence? Apply today. EY accepts applications for this position on an on-going basis. For those living in California, please click here for additional information. EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io . #J-18808-Ljbffr
$128.1k - $239.6k
...Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and... ...The opportunity The Active Defense team is responsible for four... ...In an Active Defense Analyst, we are looking for someone... ...defensive teams. In the threat hunting capacity, the analyst...CyberSummer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work- ...leading global consulting firm in Washington is seeking an Active Defense Analyst to enhance its cybersecurity efforts. This role involves identifying... ...in information security, demonstrating expertise in threat intelligence and incident response. Candidates should possess...SuggestedFlexible hours
- ...Garrett Group is looking for an Insider Threat HUB Analyst to enhance capabilities in addressing... ...analyzing and developing strategies for detection, deterrence, and mitigation of insider... ...the Navy. Key responsibilities include cyber threat analysis, incident response, and...Cyber
- cFocus Software Incorporated is seeking a Mid-level Threat Hunt Analyst in Washington, DC. This role involves advanced cyber threat hunting and proactive adversary detection as part of the SBA Enterprise Cybersecurity Services program. The ideal candidate will have a Bachelor...Cyber
$94.1k - $150k
Position Overview The Cyber Threat Hunter proactively protects... ...to identify malicious activity that may evade... ...data-flow baselines, detects anomalies, develops threat... ...procedures to strengthen cyber defense and incident response... ...closely with SOC analysts and detection...CyberContract workWork at office$82.55k - $149.23k
...has an opening for a Hunt Analyst supporting the HEITS... ...Security (DHS) Insider Threat Program (ITP) supporting... ...behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative... ..., Homeland Security, Cyber Security, or related...CyberContract workLocal areaImmediate startMonday to FridayWeekend work- Threat Hunt Analyst - Mid Position Title: Threat Hunt Analyst Program... ...performing advanced cyber threat hunting, proactive adversary detection, cybersecurity... ...and incident support activities. The Threat Hunt Analyst... ...coverage, and cybersecurity defensive measures. Coordinate...Cyber
$110k - $160k
CHAOS Industries is seeking a SOC Analyst II to enhance its growing Security Operations... ...responsibilities such as monitoring and investigating cyber threats across various systems. The ideal... ...contribute to a critical mission in modern defense! #J-18808-Ljbffr CHAOS IndustriesCyber- ...Information Assurance Analyst / Security and Insider Threat Systems Engineer / Hub Washington... ...to advance the detection, deterrence and mitigation of insider threat activity in the Department of the Navy... ...more of the following areas: cyber threat analysis, incident response...CyberCivilian Contractor
$107.9k - $195.05k
...current job opportunity for an Insider Threat/UAM (User Activity Monitoring) Analyst at the Mark Center in Alexandria,... ...1 year of UAM or insider threat detection experience * Demonstrated... ...experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE...CyberFor contractors- ...U.S. citizenship required. Active Top Secret security clearance... ...environments. Exposure to anomaly detection, trend analysis, statistical... ...seeking an experienced Data Analyst – Cyber Analytics professional to... ...trends, identify emerging threats, and deliver insights that...Cyber
- A prominent defense contractor in McLean, VA is seeking an experienced Cyber Threat Hunt Analyst to enhance national security. The ideal candidate will have a strong background... ...operations team, and developing innovative detection techniques. A High School Diploma with...CyberFor contractors
- A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National Capital Region. The role... ...with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work independently....CyberFor contractors
$120k - $132k
...SkyePoint Decisions is seeking a Threat Analyst to support the Diplomatic Security Cyber Mission (DSCM) program providing... ...persistent threat actor activity. Perform pattern, trend, and behavior... ...infrastructure. Familiarity with threat detection tools. Knowledge of cloud...CyberContract workRemote work$104k - $166k
...Cyber Threat Analyst - GTA / Active TS Job Locations US-VA-Arlington Requisition ID... ...including malware analysis, network defense, and incident response. Demonstrated... ...threat intelligence platforms, intrusion detection systems, and SIEM tools. Knowledge...CyberFull timeContract workOverseasShift work$83.85k - $107.95k
...Threat Analyst Chicago, IL, USKansas City, MO, USHouston, TX, USAtlanta... ...playbooks to streamline detection and response and maintain comprehensive... ...of threat hunting activities. The analyst collaborates with... ...adapts to the evolving cyber threat landscape. Responsibilities...CyberTemporary workLocal area- ...Permanente is expanding our Cyber Risk Defense program and seeking a... ...environment supporting cyber threat missions. As the position requires... ...and engineering, including activities such as Use Case planning/... ...the deployment of threat detection capabilities and/or...Cyber
$135.4k - $208.1k
...What Cybersecurity Defense contributes to Cardinal Health Cybersecurity... ...Defense focuses heavily on threat detection, incident response, and... ...Health. The Director, Cyber Detection & Response is responsible... .... Lead threat modeling activities to identify attack vectors,...CyberTemporary workLocal areaImmediate startRemote workFlexible hours- ...advanced full-spectrum cyber, data operations,... ...operations, cyber defense and resiliency,... ...cybersecurity concepts to the detection and defense of... ...Network Defense threat condition and determine... ...to specialized analysts Required Skills: - Must have an active TS/SCI clearance -...CyberContract workImmediate startShift work
- ...A technology company supporting government clients is seeking a Cyber Network Defense Analyst to monitor and analyze network activity for signs of suspicious behavior. The position involves characterizing network traffic, coordinating with cyber defense teams, and documenting...Cyber
- ...advanced full-spectrum cyber, data operations,... ...operations, cyber defense and resiliency,... ...concepts to detect and defend against... ...Computer Network Defense threat conditions and... ...escalating to specialized analysts when necessary (... ....S. Citizenship. Active TS/SCI clearance....CyberContract workImmediate startShift workNight shiftWeekend work
$116.35k - $210.33k
...accomplished All-Source Analyst (Production/Janus/Hard... ...operations and defense intelligence mission requirements... ...and the evolving cyber threat landscape. Join a... .... Security Clearance: Active DoD TS/SCI with Polygraph... ...knowledge sharing, and detection of environmental...CyberContract workWork experience placementShift work$75k - $160k
...many major corporations, GEICO is actively addressing industry-wide challenges... ...a chance to improve prevention, detection, assessment, and mitigation of threats from malicious insiders, ultimately... ...understanding of risk mitigation within the cyber security realm. This role is both...CyberHourly payWork experience placementLocal areaFlexible hours- ...searching for an Incident Detection Analyst to support our customer in... ...actions to evaluate and contain threats as necessary in accordance... ...Special Tactics and Active Response (JSTAR) team and provide... ...Framework for the role of Cyber Defense Incident Responder. Qualifications...CyberContract workFor contractorsWork experience placementWork at officeLocal areaImmediate startMonday to FridayShift work
- ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure... ...from a variety of cyber defense tools (e.g., IDS alerts, firewalls... ...purposes of mitigating threats. Interprets, analyzes... ...Clearance: ~ Active TS/SCI and the willingness...CyberShift work
$116.9k - $243.1k
...ingenuity for clients across defense, national security,... ...are seeking an elite Cyber Threat Hunt Lead to build and... ...advanced malicious activity that evades traditional... ...the SOC to create new detections, signatures, and... ...IAM Level I, or CSSP Analyst/Incident Responder)....CyberLive inWork at officeLocal area- cFocus Software seeks a Insider Threat Analyst Lead to join our program... ...clearance. Qualifications Active Public Trust clearance B.S.... ...Response, Threat Hunting, and Cyber Threat Intelligence teams to... ...integration into the existing SIEM and detection engineering framework....CyberWork at office
$112k - $179k
Cyber Network Security Analyst job at Peraton. Arlington, VA. Program Overview... ..., space, cyber, defense, civilian, health,... ...a focus on network activity and data; this includes... ...on related threats & vulnerabilities, diagnose... ...systems. Recommend detection and prevention/mitigation...CyberInternshipLocal area$160k - $250k
...your in-depth knowledge of the Threat Detection market to help guide the... ...proactively deliver cutting-edge defenses. Partner with Marketing... ...information on competitive activities. Work within a team of... ...passionate about staying ahead of cyber threats and have a proven...CyberWork experience placementWork at officeLocal areaRemote workWorldwide3 days per week1 day per week$68k - $119.83k
...to computer network defense, incident response, insider threat, and computer... ...mitigate, and report cyber security threats. Provides timely detection, alerting, and response... ...malicious network activity originating from external... ...of skilled analysts that Lockheed Martin...CyberFull timeTemporary workFor contractorsWork experience placementWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Detection - Active Defense Analyst. Be the first to apply!
- analyst asset management Washington DC
- origination analyst Washington DC
- design analyst Washington DC
- category analyst Washington DC
- junior analyst Washington DC
- crime analyst Washington DC
- law enforcement response team analyst Washington DC
- meditech analyst Washington DC
- facility analyst Washington DC
- proposal analyst Washington DC

