{"schemaVersion":"jobsearcher.job.v1","id":"dcd7724c057caf2ccf7183e4","url":"https://jobsearcher.com/jobs/dcd7724c057caf2ccf7183e4","canonicalUrl":"https://jobsearcher.com/jobs/dcd7724c057caf2ccf7183e4","title":"Advanced Cyber Security Analytics Engineer","description":"**ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED**\n\nReporting to the Lead of Focused Operations, under the Branch Chief of Defensive Cyber Operations, you will be tasked with developing and maintaining defensive countermeasures for the enterprise. Working within a Fusion model, will collaborate with other teams within Focused Operations with the distinct task of proactively preventing a successful compromise and eradicating persistent adversaries already in the enterprise. This will be done through various means such as reviewing future and past intelligence reports, reviewing incident reports, through regular Purple Teaming exercises, and continuously validating Defensive Countermeasures already deployed.\n\nMore about your role:\n\nAnalyzes trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents and develop or tune rules/signatures/scripts as needed.\nCoordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.\nCoordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems and develop or tune rules/signatures/scripts as needed.\nCorrelates and analyzes precursors to incidents and develop or tune rules/signatures/scripts as needed.\nWill collaborate with the Cyber Data Analytics team to achieve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed\nWork with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.\nDocuments all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis;\nProvide input to reoccurring meetings and briefings as required.\n\nRequired Qualifications:\n\nMust be a US Citizen with an Active TS/SCI.\n8+ years of related advanced cyber security analytics work experience.\nMust have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.\nExperience with data mining or building queries in a SIEM.\nStrong understanding of signature development and tuning.\nStrong understanding of network protocols and analysis with protocol analyzers.\nKnowledge of static file signatures, i.e. \"magic numbers\" and how it applies to developing countermeasures for files in transit and that reside locally on a host.\nGood working knowledge of regular expressions.\n\nPreferred Skills:\n\nComfortable in a hex editor.\nAbility to write python/bash/powershell scripts.\nAbility to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.\nGood understanding of Purple Team Tactics.\nFamiliarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining.\n\nAdditional Information\n\nAll your information will be kept confidential according to EEO guidelines.\nCompensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $90-$100k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.\nHighlights of our benefits include Health/Dental/Vision, 401(k) match, Accrued PTO, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and more!\n\nD2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals. As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience. Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.","company":"D2 Technical Services","rawCompany":"d2 technical services","city":"St Louis","state":"MO","isRemote":false,"isActive":false,"createdAt":"2026-09-09T09:57:03.646Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.06","title":"Digital Forensics Analysts","slug":"digital-forensics-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"928110","title":"National Security","slug":"national-security"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Advanced Cyber Security Analytics Engineer","description":"**ACTIVE TS/SCI SECURITY CLEARANCE REQUIRED**\n\nReporting to the Lead of Focused Operations, under the Branch Chief of Defensive Cyber Operations, you will be tasked with developing and maintaining defensive countermeasures for the enterprise. Working within a Fusion model, will collaborate with other teams within Focused Operations with the distinct task of proactively preventing a successful compromise and eradicating persistent adversaries already in the enterprise. This will be done through various means such as reviewing future and past intelligence reports, reviewing incident reports, through regular Purple Teaming exercises, and continuously validating Defensive Countermeasures already deployed.\n\nMore about your role:\n\nAnalyzes trends and patterns of data on NGA networks to identify and predict previously undiscovered events and incidents and develop or tune rules/signatures/scripts as needed.\nCoordinates with Defensive Cyber Operations and Focused Operations to develop or tune rules/signatures/scripts.\nCoordinates with other Cybersecurity Operations Services to investigate and obtain information about potential sources of compromise on enterprise systems and develop or tune rules/signatures/scripts as needed.\nCorrelates and analyzes precursors to incidents and develop or tune rules/signatures/scripts as needed.\nWill collaborate with the Cyber Data Analytics team to achieve SIEM alert efficiency though evaluation of valid alerts and false positives, and develop or tune rules/signatures/scripts as needed\nWork with the Cyber Incident Response Team by assessing ongoing incident activity to predict adversary responses and locations of compromise to assist with triage.\nDocuments all work in the authorized ticketing system with a sufficient level of detail to ensure all stakeholders can systematically reconstruct the analysis;\nProvide input to reoccurring meetings and briefings as required.\n\nRequired Qualifications:\n\nMust be a US Citizen with an Active TS/SCI.\n8+ years of related advanced cyber security analytics work experience.\nMust have a certification that is compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst.\nExperience with data mining or building queries in a SIEM.\nStrong understanding of signature development and tuning.\nStrong understanding of network protocols and analysis with protocol analyzers.\nKnowledge of static file signatures, i.e. \"magic numbers\" and how it applies to developing countermeasures for files in transit and that reside locally on a host.\nGood working knowledge of regular expressions.\n\nPreferred Skills:\n\nComfortable in a hex editor.\nAbility to write python/bash/powershell scripts.\nAbility to analyze each use case, as it pertains to detection logic, and identify the corresponding capability.\nGood understanding of Purple Team Tactics.\nFamiliarity with security in a cloud environment and how it applies to visibility gaps, data lakes and data mining.\n\nAdditional Information\n\nAll your information will be kept confidential according to EEO guidelines.\nCompensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $90-$100k. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.\nHighlights of our benefits include Health/Dental/Vision, 401(k) match, Accrued PTO, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and more!\n\nD2 Technical Services is committed to a merit-based recruitment process and encourages applications from all qualified individuals. As a Veteran-Owned Small Business, we particularly welcome applications from veterans who have the requisite skills and experience. Job applicants that are interested in one of our openings and may require a reasonable accommodation to participate in the job application or interview process, should contact us to request an accommodation.","datePosted":"2026-09-09T09:57:03.646Z","dateModified":"2026-09-09T09:57:03.646Z","hiringOrganization":{"@type":"Organization","name":"D2 Technical Services","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"St Louis","addressRegion":"MO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"dcd7724c057caf2ccf7183e4"},"url":"https://jobsearcher.com/jobs/dcd7724c057caf2ccf7183e4"}}