Enter a job title or keyword

Cyber Defense Analysts – Senior


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 17 July 2026 (30+ days ago)
Application Deadline: 14 October 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions LLC a Koniag Government Services company is seeking a Cyber Defense Analysts Senior to support KDS and our government customer in Washington DC. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and Data Solutions a Koniag Government Services company is seeking an experienced Senior Cyber Defense Analyst to support the U.S. Small Business Administration (SBA). The ideal candidate is a skilled cybersecurity professional with a strong background in cyber defense operations advanced threat analysis and incident response within a federal government environment. This individual will play a critical role in protecting SBAs systems networks and data by performing advanced security monitoring conducting in-depth threat analysis and leading incident response activities in alignment with federal cybersecurity policies and SBA security requirements. The Senior Cyber Defense Analyst will serve as a senior-level cybersecurity operations professional responsible for performing advanced monitoring detection analysis and response to cybersecurity threats targeting SBAs enterprise IT environment. This individual will bring deep technical expertise and operational experience to the SOC team taking ownership of complex security investigations leading incident response activities and contributing to the continuous improvement of SBAs cyber defense capabilities. Principal responsibilities will include but are not limited to:Perform advanced continuous monitoring of SBA networks systems endpoints and cloud environments using SIEM platforms IDS/IPS tools EDR solutions and other security technologies to detect identify and respond to potential threats anomalies and indicators of compromise targeting SBAs enterprise IT advanced analysis and in-depth triage of security events alerts and incidents determining the validity scope severity and potential impact of identified threats and escalating confirmed or suspected incidents to the Cybersecurity Operations Technical Lead in accordance with established SBA incident response procedures and and coordinate incident response activities for significant and complex cybersecurity incidents including containment eradication recovery and post-incident review in strict accordance with SBAs incident response policies NIST SP 800-61 guidelines and applicable federal advanced threat hunting activities proactively searching SBAs enterprise environment for indicators of compromise (IOCs) hidden adversary activity and sophisticated threats that have evaded automated detection leveraging the MITRE ATT&CK framework threat intelligence and advanced analytical detailed analysis of network traffic system logs endpoint telemetry and other relevant data sources to reconstruct attack timelines characterize adversary TTPs identify root causes and determine the full scope and impact of security incidents affecting SBA systems and and recommend enhancements to SIEM detection rules correlation logic behavioral analytics and alerting thresholds based on threat hunting findings incident analysis results and emerging threat intelligence working with the Technical Lead to implement approved and operationalize threat intelligence from government and commercial sources including US-CERT CISA ISACs and commercial threat intelligence platforms applying intelligence to ongoing monitoring incident investigations and threat hunting activities to enhance SBAs cyber defense detailed high-quality incident reports after-action reviews (AARs) and technical documentation for significant security incidents capturing incident timelines root cause analysis evidence response actions and actionable recommendations for SBA leadership and with SBA IT teams system owners the Cybersecurity Architect and other stakeholders to communicate security findings coordinate remediation activities and provide expert technical guidance on the resolution of identified vulnerabilities and security and contribute to the development and maintenance of SOC Standard Operating Procedures (SOPs) incident response playbooks and runbooks ensuring documentation reflects current threats operational procedures and lessons learned from past mentorship and technical guidance to mid-level and junior SOC analysts contributing to their professional development and the continuous improvement of the SOC teams overall analytical capabilities and operational vulnerability management activities by providing advanced analysis of vulnerability scan results assessing the exploitability and real-world risk of identified vulnerabilities in the context of SBAs threat landscape and advising on remediation prioritization in tabletop exercises red team/blue team activities and purple team engagements contributing senior-level analytical expertise to validate and strengthen SBAs detection and response capabilities against realistic attack and analyze changes to the federal cybersecurity policy landscape emerging threat trends and new vulnerability disclosures applying new knowledge to continuously improve SBAs cyber defense monitoring and response all cyber defense activities comply with applicable federal cybersecurity frameworks policies and regulations including NIST FISMA and DHS/CISA directives and and Experience:Required:Bachelors degree in Cybersecurity Information Technology Computer Science or a related field from an accredited college or university.6 years of progressive experience in cybersecurity operations threat analysis or cyber defense with at least 2 years performing senior analyst functions within a SOC or cyber defense experience supporting federal government cybersecurity programs and SOC or more of the following certifications:GIAC Certified Incident Handler (GCIH)GIAC Security Operations Certified (GSOC)GIAC Certified Enterprise Defender (GCED)Certified SOC Analyst (CSA)CompTIA Cybersecurity Analyst (CySA)Certified Information Systems Security Professional (CISSP)Desired:Masters degree in Cybersecurity Information Assurance or a related field.8 years of cybersecurity operations experience within a federal government or defense contracting environment with a demonstrated focus on advanced threat analysis threat hunting and incident Skills and Competencies:Exceptional communication skills in English both written and oral with the ability to clearly convey complex technical security findings incident details and analytical recommendations to both technical and non-technical audiences including senior SBA leadership and government proficiency in security event monitoring alert triage threat detection and incident response operations within a SOC environment with demonstrated experience handling complex high-priority security incidents from detection through hands-on experience with SIEM platforms (e.g. Splunk Microsoft Sentinel ArcSight or similar) including the ability to develop and tune detection rules build advanced queries and dashboards and conduct in-depth log analysis and event correlation to support complex incident knowledge of network security concepts and protocols including TCP/IP DNS HTTP/S firewalls IDS/IPS and demonstrated ability to analyze network traffic captures and flow data using tools such as Wireshark or Zeek to identify malicious activity during incident proficiency with endpoint detection and response (EDR) tools and the ability to conduct thorough host-based investigations including the analysis of endpoint telemetry process trees registry artifacts and memory data to identify and characterize threats on SBA expertise in applying the MITRE ATT&CK framework to threat detection threat hunting and incident response activities including the ability to map observed adversary behaviors to ATT&CK tactics and techniques to inform analytical findings and detection experience conducting log analysis across diverse data sources including Windows Event Logs Syslog cloud platform logs application logs and network flow data to reconstruct attack timelines and support thorough incident leveraging threat intelligence platforms and operationalizing threat intelligence from multiple government and commercial sources to drive threat hunting priorities enhance detection capabilities and inform incident response of federal cybersecurity frameworks and compliance requirements including NIST SP 800-53 NIST SP 800-61 FISMA and CISA guidance and directives and their application to senior-level cyber defense operations within a federal civilian agency experience developing high-quality incident reports after-action reviews SOC SOPs and incident response playbooks that accurately capture incident details analytical findings and actionable remediation to serve as a technical mentor and resource for mid-level and junior SOC analysts providing guidance knowledge transfer and professional development support to elevate team analytical and problem-solving skills with the ability to manage multiple complex investigations simultaneously prioritize effectively under pressure and drive incidents through to resolution in a timely and thorough to obtain and maintain a Public Trust Skills and Competencies:Prior experience supporting SBA or other federal civilian agency SOC operations or cyber defense programs with demonstrated knowledge of SBAs IT environment threat landscape and cybersecurity program with cloud security monitoring and incident investigation in AWS Azure or GCP environments including familiarity with cloud-native logging monitoring and security services such as AWS GuardDuty Microsoft Defender for Cloud or Google Security Command with Security Orchestration Automation and Response (SOAR) platforms and experience using scripting languages such as Python or PowerShell to develop automated detection investigation and response workflows that improve SOC efficiency and analytical with digital forensics concepts and techniques including basic disk forensics memory forensics and network forensics to support advanced incident response investigations and evidence collection of Zero Trust Architecture (ZTA) principles and their implications for advanced threat detection cyber defense monitoring and incident response within a federal IT with the CDM (Continuous Diagnostics and Mitigation) program tools data requirements and their application in supporting senior-level SOC operations and cyber defense activities within federal civilian Certified Forensic Analyst (GCFA) or GIAC Network Forensic Analyst (GNFA) supporting or participating in purple team exercises collaborating with offensive security and SOC teams to validate and improve detection and response capabilities against real-world attack with cyber deception technologies including honeypots and deception platforms and their application in enhancing threat detection and adversary identification capabilities within SBAs working within FedRAMP authorized cloud environments and familiarity with FedRAMP security requirements as they relate to senior-level SOC monitoring incident response and cyber defense Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352

Required Experience:

IC


About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile