Cyber Defense Analyst 3 (CDA3)
$7.5kRealmOne
Cyber Defense Analyst 3 (CDA3)
Location: Central Maryland
Security Clearance Required: Security Clearance with appropriate Polygraph
Job Brief
TCP/IP fundamentals, network traffic analysis tools, security information and event management suites.
Job Description
RealmOne was built on the principle that people matter first and foremost. We believe in providing a strong work/life balance by investing in our employees and encouraging professional and personal growth. We do this by offering exceptional benefits, flexible schedules, and the tools necessary to achieve success through paid training, mentoring, and the opportunity to work alongside top-notch industry professionals.
Join us on this journey as we execute this mission-critical contract providing high-end analytics and data science services within the REALM of cybersecurity.
Your effort and expertise are crucial to the success and execution of this impactful mission that is critical in ensuring mission success through Security Engineering, Risk Management and Assessment, and Insider Threat Analysis, by improving, protecting, and defending our Nation's Security.
Job Description:
Uses information collected from a variety of sources to monitor network activity and analyze it for evidence of anomalous behavior. Identifies, triages, and reports events that occur in order to protect data, information systems, and infrastructure. Finds trends, patterns, or anomaly correlations utilizing security-relevant data. Recommends proactive security measures. Conducts analysis to isolate indicators of compromise. Notify designated managers, cyber incident responders, and cybersecurity service provider team member of suspected cyber incidents and articulate the event's history, status, and potential impact for further action in accordance with the organization's cyber incident response plan.
The Cyber Defense Analyst 3 shall possess the following capabilities:
- Use cyber defense tools to monitor, detect, analyze, categorize, and perform initial triage of anomalous activity.
- Generate cybersecurity cases (including event's history, status, and potential impact for further action) and route as appropriate.
- Leverage knowledge of commonly used network protocols and detection methods to defend against related abuses.
- Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Perform advanced manual analysis to hunt previously unidentified threats.
- Conduct PCAP analysis.
- Identify cyber-attack phases based on knowledge of common attack vectors and network layers, models and protocols.
- Apply techniques for detecting host- and network-based intrusions.
- Working knowledge of enterprise-level network intrusion detection/prevention systems and firewall capabilities.
- Understand the foundations of a hardened windows network and what native services and protocols are subject to abuse (such as RDP, Kerberos, NTLM, WMI, and SMB).
- Familiarity with fragmentation of network traffic and how to detect and evaluate fragmentation related attacks in raw packet captures.
- Conduct network – traffic, protocol and packet-level – and netflow analysis for anomalous values that may be security-relevant using appropriate tools (such as Wireshark, tshark, tcpdump).
- Understand snort filters and how they are crafted and tuned to feed IDS alerting.
- Understand system and application security threats and vulnerabilities to include buffer overflow, SQL injection, race conditions, covert channel, replay and return-oriented attacks, malicious code and malicious scripting.
- Analyze malicious activity to determine weaknesses exploited, exploitation methods, effects on system and information.
- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
- Familiar with indications of Command and Control (C2) channels and what strategies attackers use to bypass enterprise defenses from a compromised host.
- Demonstrate advanced knowledge of how adversaries penetrate networks and how those attacks map to detectable events across the ATTACK framework.
- Understand how VBS, Jscript, and Powershell can be maliciously used within a network and what level of monitoring and auditing is required to detect.
- Possess deep knowledge of active directory abuse used by attackers for lateral movement and persistence.
- Provide expertise in the identification of adversarial Tactics, Techniques, and Procedures (TTPs) and in the development and deployment of signatures.
- Perform after-action reviews of team products to ensure completion of analysis.
- Lead and mentor team members as a technical expert.
Qualifications
- Eight (8) years of demonstrated experience as a CDA in programs and contracts of similar scope, type, and complexity is required. A technical bachelor's degree from an accredited college or university may be substituted for two (2) years of CDA experience on projects of similar scope, type, and complexity.
- Two (2) years of demonstrated and practical experience in TCP/IP fundamentals.
- Two (2) years of demonstrated experience with network traffic analysis tools such as Bricata, tcpdump or Wireshark.
- Three (3) years of demonstrated experience using security information and event management suites (such as Splunk, ArcSight, Kibana, LogRhythm).
- Three (3) years of demonstrated experience in network analysis and threat analysis software utilization.
- 24x7 SHIFT - 12 hour shift
Certifications Required
- Requires DoD 8570 compliance with: CSSP Analyst baseline certification
- Information Assurance Technical (IAT) Level I or Level II certification, and Computing Environment (CE) certification. The CE certification requirements can be fulfilled with either Microsoft OS, Cent OS/Red Hat OS CE certifications.
- Requires Global Information Assurances Certification (GIAC) Certified Incident Handler (GCIH) certificate or Certified Intrusion Analyst (GCIA) certificate.
- Requires successful completion of the Splunk software training course "Fundamentals 1"
Position requires active Security Clearance with appropriate Polygraph
Pay Range: 197,000-227,000
The RealmOne pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Our approach to crafting offers considers various factors to establish an equitable and competitive compensation package. These considerations include, but are not limited to, the extent and intricacy of the role's responsibilities, the candidate's educational background, their work experience, and the specific competencies crucial for success in the role.
RealmOne Benefits:
- Healthcare Coverage + Insurance: Medical: Three (3) rich healthcare options through CareFirst with 100% or majority company-paid premiums. Tax-advantaged health savings account available with generous employer contribution. Dental + Vision: 100% employer-paid for employees and family with buy-up option available.
- Retirement + Savings: 401K - 10% TOTAL CONTRIBUTION - 5% safe harbor - 5% annual profit share. Immediate vested, no match required!
- Paid Time Off + More: 4 weeks starting PTO - 11 federal holidays + 2 floating holidays - Paid hours for company-required training.
- Career Growth + Development: Access to FREE 24/7 learning via Udemy - Opportunities to participate in tech councils, industry initiatives, etc. - $7,500 annual Educational & Professional Development Assistance.
- MORE BENEFITS...FOR EVERY LIFESTYLE! - Paid parental leave - Adoption assistance - Annual swag drops - Flexible work schedules - -Generous referral bonus program - Employee appreciation + family-friendly corporate events...and much more.
About Us
- RealmOne is a mid-sized science and technology company dedicated to solving our customers' toughest mission challenges.
- Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering services and products to customers in the Government and commercial sectors.
- RealmOne delivers encompassing mission assurance and critical systems support to government customers across various U.S. locations to include Colorado, Georgia, Hawaii, Texas, Utah, and Virginia.
- RealmOne has earned numerous awards, including being named a Top Workplace by the Baltimore Sun. With more than 30+ active contracts, 12 of which are prime, RealmOne stands as a premier innovator supporting the Government and Department of Defense, with team members located nationwide.
Disclaimer: Benefits packages offered by RealmOne are subject to variation and may differ based on work
$7.5k
...Computer Network Defense Analyst 3 Location: Central Maryland Security Clearance Required: Security Clearance with appropriate Polygraph... ...this mission-critical contract providing intelligence and cyber analysis support! Your effort and expertise are crucial to the...SuggestedContract workWork experience placementImmediate startFlexible hours$7.5k
...Target Digital Network Analyst 3 Location: Central Maryland Security Clearance Required... ...contract providing intelligence and cyber analysis support! Your effort and expertise... ...Digital Network Analysts, and Cyber Network Defense Analysts, responsible for improving,...SuggestedContract workWork experience placementImmediate startFlexible hours$65 - $68 per hour
...organization in the energy industry, is seeking a Cyber Security Analyst - Incident Response to join their team.... ..., you will be part of the Cyber Defense team supporting enterprise-wide... ...and recovery of sophisticated level 2/3 cyber incidents. Coordinate and provide...SuggestedWeekly payTemporary workRemote workFlexible hours$7.5k
...Network Engineer 3 Location: Central Maryland Security Clearance Required: Security Clearance with appropriate Polygraph... ...a premier innovator supporting the Government and Department of Defense, with team members located nationwide. Disclaimer: Benefits...SuggestedContract workWork experience placementImmediate startFlexible hours$7.5k
...System Vulnerability Analyst 2 Location: Central Maryland Security... ...Scientists, Cryptologic Cyber Planners, Intrusion Analysts,... ...experience. Master's degree with 3 years of relevant experience.... ...Training (INWT), Cyber Defense Operations will be considered...SuggestedContract workWork experience placementImmediate startFlexible hours$7.5k
...Benefits: Healthcare Coverage + Insurance: Medical: Three (3) rich healthcare options through CareFirst with 100% or majority... ...a premier innovator supporting the Government and Department of Defense, with team members located nationwide. Disclaimer: Benefits...Contract workWork experience placementImmediate startFlexible hours- ...Description Tyto Athene is seeking a Senior Cyber Lead to support the Department of Defense Cyber Crime Center (DC3) Cyber... ..., forensic examiners, cyber analysts, and operational leadership to support... ..., or cyber investigative missions. 3+ years in a senior technical leadership...
$134.1k - $241.4k
...vulnerability assessments and strategic cyber report analysis to help assess... ...supports a team of Target Analyst Reporters and Target Digital... ...Minimum three (3) years' experience in three (... ...and solutions in the areas of defense, security, intelligence, infrastructure...Local areaWorldwideFlexible hours$7.5k
...Digital Network Exploitation Analyst 2 Location: Central Maryland... ...contract providing intelligence and cyber analysis support! Your effort... ...Analysts, and Cyber Network Defense Analysts, responsible for... ...experience. Master's Degree with 3 years of experience. PhD...Contract workFor contractorsWork experience placementImmediate startFlexible hours$112k - $179k
...Cyber Threat Analyst Job Locations US-MD-Linthicum Requisition ID 2026-1671... ...Requires a detailed knowledge of Department of Defense and service level (Army, Navy, Air Force... ...s Degree and 6+ years of experience; OR 3 years with PhD. A Bachelor's or Master'...Full timeContract workMonday to FridayShift work$220k - $270k
...Purpose and Impact: Amentum is seeking an Information Systems Security Engineer (ISSE) 3 for a prime contract that is based out of our Columbia, MD office. Essential Responsibilities: Participate as the primary security engineering representative on engineering...Hourly payContract workWork at officeLocal area- ...Qualifications: Minimum knowledge, skills, abilities. ~ Bachelor’s degree and 5 years of relative experience, Master's degree and 3 years of relative experience, or 9 years of relative experience in an IT field in lieu of a degree. ~ Cisco Certified Network...For contractorsLocal areaRemote workWeekend work
$120.8k - $265.8k
...Job Title: Network Engineer 3 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: None Type of Travel: None The Opportunity: CACI...Full timeContract workWork experience placementFlexible hours- ...Cyber/Security Operations Analyst Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across... ...processes based on the IT Infrastructure Library (ITIL) v.3 Framework across enterprise infrastructure operations....For contractorsWork at office
$170k - $190k
...Cyber Software Engineer Location: Linthicum Heights, MD Compensation Range: $170 -$190... ...to apply Company Overview: Cornerstone Defense is the Employer of Choice within the Intelligence... ..., Math or Information Systems) and Three (3) year of experience in software...- ...under minimal direction and independently determine and develop approach to solutions. This position may be filled at either Level 3 (Principal) or Level 4 (Senior Principal), depending on the candidate's qualifications, education, and experience. Must Have Qualifications...Full timeContract work
- ...Enterprise Architect Our client is recruiting senior engineering and support staff supporting the Office of the Undersecretary of Defense - Intelligence & Security Branch (OUSD/I&S). We are currently seeking an Enterprise Architect who will interface with functional...Work at office
$3,000 per month
...WHAT WE'RE DOING: Lockheed Martin, Cyber & Intelligence invites you to step up to... ...Offensive Cyber team, where we don't just test defenses - we pioneer the techniques, tools, and... ...variety of roles including vulnerability analysts, exploit developers, hardware/software...Full timeTemporary workWork experience placementWork at officeRelocation packageFlexible hours$3,000 per month
...! What We're Doing: Lockheed Martin, Cyber & Intelligence invites you to step up to... ...world-class offensive cyber operations and defense. The Work: A CNO (Computer Network... ...variety of roles including vulnerability analysts, exploit developers, hardware/software reverse...Full timeTemporary workWork experience placementSecond jobWork at officeRemote workRelocationRelocation packageFlexible hoursShift work$104k - $166k
...Responsibilities This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government... ...: Bachelor's degree and 5+ years of experience, or Master's and 3+ years of experience, or PhD and 0+ years of experience. A...Contract workShift work- ...Tyto Athene, LLC is seeking a Senior Cyber Lead in Linthicum, Maryland, to support the Department of Defense Cyber Crime Center. This role requires expertise in leading cyber operations, digital forensics, and incident response. The ideal candidate will have over 10 years...
$145k - $160k
...Cybersecurity Vulnerability Analyst Job Number : 32291 Location : Linthicum Heights, MD Job Description :... ...of experience; OR Master's Degree and 6+ years of experience; OR 3 years with PhD. Bachelor's or Master's degree must be one of the...Full timeFlexible hours$176.9k - $332.4k
...Job Description: Parsons is looking for a talented SETA Cyber Product Manager to join our team! In this role you will get to... ...the art as they provide services and solutions in the areas of defense, security, intelligence, infrastructure, and environmental. We promote...Local areaWorldwideFlexible hours$130k - $160k
...Posting Summary Job Title SOC Analyst/ Cybersecurity Manager Division... ...this position is to serve as the front-line defense for Morgan State University's digital... ...data and institutional assets from evolving cyber threats. Job Duties Duties &...Full time- ...Sr. Cyber Range Engineer BENEFIT ELIGIBLE Professional Security Clearance REQUIRED... ...Data Analytics Solutions to the Federal, Defense, and Intelligence communities. Headquartered... ...VCP-Cloud, or equivalent certs ~3+ years of experience with CNO/CNE/CND platforms...Full timeContract workFlexible hours
$165k - $185k
...Cyber Systems Engineer Location: Linthicum, MD Compensation Range: $165 -$185K Clearance: Active TS/SCI w/ Polygraph needed to apply Company Overview: Cornerstone Defense is the Employer of Choice within the Intelligence, Defense, and Space communities of the U.S. Government...$112k - $179k
...Required Qualifications: Well-versed in best practices for cyber security program standards, processes, and procedures compliance,... ...of experience, or Master's Degree and 6+ years of experience, or 3 years with PhD. A degree in one of the following fields of study...Full timeContract workMonday to FridayShift work$84.56k - $120.5k
...strategies to protect our organization's information assets from cyber threats. Essential Role Responsibilities Security Strategy... ...of experience in information security, with at least three (3) years in a managerial role. * Proven track record of developing...Full timeLive inWork at officeRelocationVisa sponsorshipWork visaRelocation packageMonday to Friday$117.1k - $152.65k
...Systems or application development experience with OO languages such as C#, Java - 10+ years Previous experience as an Architect - 3+ years. Strong experience modernizing and improving cloud nativity, implementing hybrid cloud strategies, and creating APIs to bridge...Work experience placementLive inLocal areaWorldwide- ...documentation with processes and procedures o Proposing, implementing automation features in a large enterprise environment • t least 3 years of experience with Linux and SQL/ODBC interfaces • t least 2 years of experience in app interface development, using REST...Remote workNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Defense Analyst 3 (CDA3). Be the first to apply!
- information security consultant Baltimore, MD
- remote cyber security analyst Baltimore, MD
- cyber security analyst Baltimore, MD
- cyber Baltimore, MD
- insurance defense paralegal Baltimore, MD
- defense security service Baltimore, MD
- defense analyst Baltimore, MD
- insurance defense attorney Baltimore, MD
- defense attorney Baltimore, MD
- defense Baltimore, MD

