Amentum

Amentum

Mid-Level Cyber Defense Analyst / Incident Responder IRES - HSV

US-AL-Redstone Arsenal · Mid · Full-time

No sponsorship$127k-$136kDetected 16 hours ago
LinuxCybersecurityNetwork SecuritySIEMSOC OperationsDetection EngineeringIncident ResponseExcelFirewallResearchLeadershipCommunicationMentoringMicrosoft OfficeCompTIA

About the role

  • Our health and welfare benefits are designed to support you and your priorities.
  • Offerings include:
  • Health, dental, and vision insurance Paid time off and holidays Retirement benefits (including 401(k) matching) Educational reimbursement Parental leave Employee stock purchase plan

Responsibilities

  • Perform Defensive Cyber Operations (DCO)/Cyber Security Service Provider (CSSP) duties outlined in Evaluator Scoring Metrics (ESM).
  • Perform cybersecurity duties on customer networks (proactively and reactively) to improve enterprise-wide security posture.
  • Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents IAW CJCSM 6510.01B.
  • Lead event/incident investigations from start to conclusion, to include gathering data, analysis, and reporting.
  • Properly document all steps in the incident response process while taking care to preserve and protect incident artifacts, evidence, and chain of custody.
  • Support a Cyber Defense Analyst and Cyber Defense Incident Responder training plan by instructing, evaluating, and mentoring Junior Cyber Defense Analyst and Cyber Defense Incident Responders.
  • Support the development, establishment, review and update of DCO procedures, processes, manuals, and other documentation.
  • Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and develop SIEM content/signatures to detect known attack patterns and make recommendations for improvements.
  • Coordinate with CSSP-CERT subscribers to develop current configurations, rules, and signatures for cyber security related toolsets.
  • Provide standardized and targeted training in support of CSSP-CERT subscriber cyber defense and incident response programs.

Requirements

  • Have experience with most MS Office applications (Word, Excel, PowerPoint, and Visio).
  • Resumes, in month and year format, must be submitted with application in order to be considered for the position.
  • You can also search for a list of our current job openings and see if there are any new positions that might be a good fit for you.

Compensation

  • Details: $127,000 - $136,000 The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued.
  • Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.
  • With more than 50,000 employees on all seven continents and in more than 60 countries, Amentum delivers a broad range of operational support services to meet the critical needs of our clients.
  • If you are contacted by anyone offering employment with Amentum, you should never be asked to pay a fee for recruiting.

Benefits

  • Overview: Our health and welfare benefits are designed to support you and your priorities.
  • Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Equal opportunity

  • Amentum is proud to be an Equal Opportunity Employer.
  • Find us online at https://www.amentum.com/ If you need a reasonable accommodation for any part of the employment process, please contact us by email at TAOps@amentum.com and let us know the nature of your request and your contact information.
  • Requests for accommodation will be considered on a case-by-case basis.

Visa & Work Authorization

  • GCED | GIAC GDSA | GIAC GSEC | GIAC PenTest+ | CompTIA CySA+ | CompTIA Cloud+ | CompTIA Must have an active DoW Secret Security Clearance Desired Requirements: Have a Bachelor's degree, or higher, in Cybersecurity, Compu

This listing is sourced directly from Amentum's careers page and normalized into a canonical job model.