Splunk Cyber Threat Analyst- Remote Local Washington

4 days ago


Arlington, Virginia, United States Motion Recruitment Full time
Splunk Cyber Threat Analyst

This position is for a Cyber Threat Analyst for an organization that specializes in analyzing and producing advanced cybersecurity and threat intelligence. Responsibilities include identifying and assessing threats and potential threats to the customer's personnel, information, and information systems. The role involves providing timely and relevant intelligence to assist in mitigating cyber threats, supporting the evaluation, implementation, and operation of advanced analysis tools and technologies, and developing and supporting the Cyber Insider Threat Program.

The company is located in the Washington D.C. Metro area and will remain 100% remote, but the candidate must be local to the area.

What You Will Be Doing:
  • Support the customer's comprehensive cyber threat analysis efforts.
  • Serve as the liaison between the Splunk Engineering team and SOC operations teams to configure the Splunk Data Lake for optimal SOC functionality.
  • Create executive-level dashboards summarizing cyber status or risk level per Splunk, based on criteria published by FISMA and other Government organizations.
  • Produce metrics and trendlines for threat activity and provide in-product security research on existing and emerging threats.
  • Support the use of machine learning for event correlation and proactive cyber response capabilities.
  • Research, analyze, and draft documents such as use case requirements, system change documents, and process documents/workflows.
  • Ensure documentation is accurate, complete, and adheres to quality, editorial, and government standards.
  • Develop content including presentations, bulletins, white papers, memos, policies, briefings, and other products appropriate for the intended audience.
  • Collaborate with analysts and engineers to acquire subject knowledge.
  • Assist in coordinating projects from the planning stage, provide additional or missing materials, and edit for content format, flow, and integrity.
  • Perform Cyber Threat Assessment and Remediation Analysis within the context of SIEM configuration requirements.
  • Process, organize, and analyze incident indicators retrieved from the client environment and correlate these indicators with various intelligence data.
  • Coordinate with internal teams and assist in the creation of engagement deliverables for activities such as Insider Threats, Rule of Engagement (ROE), Threat Hunting, After Action Reports, and other artifacts supporting testing, monitoring, and protecting the enterprise.
  • Investigate network and host detection and monitoring systems to advise on engagement processes.
  • Develop core threat intelligence capabilities and subject matter expertise.
  • Develop and execute bash and python scripts to process discrete log files, extract specific incident indicators, and develop tools to aid in Tier 1 and Tier 2 functions.

    Required Skills & Experience:
    • Bachelor's degree in Computer Science, Information Systems, Mathematics, Engineering, or a related field, or an additional two (2) years of relevant experience.
    • Experience in cyber threat intelligence or intelligence analysis.
    • Cybersecurity certifications preferred but not required.
    • Strong organizational, verbal, presentation, and written communication skills. Comfortable presenting briefings to clients.
    • Proficient in using Splunk for SOC operations support.
    • Skilled in assessing SIEM data for search and visualization capabilities.
    • Demonstrated proficiency in Incident Response Process, SOC operations, and threat hunting.
    • Good understanding of system log information and data collection for Incident Events.
    • Operational knowledge of enterprise networking and security tools (firewalls, Antivirus, HIDS, IDS/IPS, proxy, WAF) and Windows and Unix/Linux systems.
    • Experienced in log analysis and reporting.
    • Skilled in creating and tracking investigations to resolution.
    • Experience with Endpoint security solutions such as Windows Defender, Tanium, FireEye Solutions, Antivirus Solutions, and EDR Tools.
    • Understanding of compliance or regulatory frameworks (e.g., FISMA, NIST, ISO).
    • Solid understanding of application, authentication, network security principles, and operating system hardening techniques.
    • General knowledge of cyber-attack frameworks (MITRE ATT&CK, Lockheed Cyber Kill Chain).
    • Understanding of Computer Network Defense (CND) policies, procedures, and regulations.
    • Experienced in SIEM monitoring and analysis, network traffic analysis, log analysis, and differentiating between potential intrusion attempts and false alarms.

      Applicants must be currently authorized to work in the United States on a full-time basis now and in the future.

      This position doesn't provide sponsorship.


  • Arlington, Virginia, United States SIXGEN Full time

    We are seeking a Cyber Warfare Threat Analyst to join our growing team. As a Cyber Warfare Threat Analyst, you will be challenged in a variety of cyber security focuses. From your knowledge of foreign threats, avenues of attack, using your intelligence experience, you will create intelligence products and briefings. You will work with Intelligence production...


  • Arlington, Virginia, United States Cordia Resources by Cherry Bekaert Full time

    Leading Cybersecurity/ Financial Services Firm Senior Cyber Threat Intelligence Analyst ($180k-$210k + 15% Bonus) Work Model: Hybrid (3x) Step into a leading cybersecurity/ financial services firm in Northern VA, unwavering in its mission to fortify our nation's pivotal financial infrastructure. Their strategic alliances with Fortune 100 corporations and...


  • Arlington, Virginia, United States Motion Recruitment Full time

    Cloud Security AnalystThe company is looking for creative individuals interested in helping grow something truly unique in their markets. While the ideal candidate is great at independently getting their work done, at the same time they are a team player who readily and proactively contributes to team activities to both the team and client's consistent...


  • Arlington, Virginia, United States Cordia Resources by Cherry Bekaert Full time

    Exciting Opportunity at a Top Cybersecurity/ Financial Services FirmSeeking Talented Senior Cyber Threat Intelligence AnalystsOffering Competitive Compensation and Benefits PackageAbout the Company:Join a prestigious cybersecurity intelligence services firm in Northern VA dedicated to enhancing the security of the nation's financial infrastructure. With...


  • Arlington, Virginia, United States Nightwing Full time

    Date Posted: Country: United States of America Location: VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA Position Role Type: Hybrid You have been redirected to RTXs career page as we have recently transitioned from RTX to become a standalone company, which provides us with greater autonomy and opportunities for...


  • Arlington, Virginia, United States SecuriGence LLC Full time

    Job Title: Security Operations Center Analyst (SOC)Location: Arlington, VirginiaClearance Level: Top Secret ClearanceSummaryWe deliver essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation. SecuriGence is seeking a talented Security Operations Center Analyst (SOC) to...


  • Arlington, Virginia, United States PassionHR Inc Full time

    EXPERIENCED NETWORK BASED SYSTEMS ANALYSTWe are looking for a skilled Cyber Network Defense Analyst (CNDA) to join our team in Arlington, Virginia. The CNDA plays a crucial role in monitoring network activities to detect suspicious behavior and protect information systems from potential threats.Coordinate teams for incident response investigationsInterface...


  • Arlington, Virginia, United States Motion Recruitment Full time

    Senior Splunk EngineerThe company is looking for creative individuals interested in helping grow something truly unique in their markets. While the ideal candidate is great at independently getting their work done, at the same time they are a team player who readily and proactively contributes to team activities to both the team and client's consistent...


  • Arlington, Virginia, United States SecuriGence LLC Full time

    Job Title: Security Operations Center Analyst (SOC) Location: Arlington, Virginia Clearance Level: Top Secret Clearance Summary We deliver essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation. SecuriGence is seeking a talented Security Operations Center Analyst (SOC)...


  • Arlington, Virginia, United States Recorded Future Full time

    With 1,000 intelligence professionals, over $300M in sales, and serving nearly 2,000 clients worldwide, Recorded Future is the world's most advanced, and largest, intelligence companyThis Role: The Strategic Intelligence team is looking for an analyst who can distill a large breadth of information into a compelling narrative for an executive audience....


  • Arlington, Virginia, United States Base One Technologies Full time

    Provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for digital forensics/incident response (DFIR) and proactively hunting for...


  • Arlington, Virginia, United States Nodel Full time

    Job DescriptionJob DescriptionInformation Systems Security Analyst / Sr Cyber Security Subject Matter ExpertLocation: Arlington, VAMust have an active Top Secret ClearanceNode is supporting a U.S. Government customer on a large mission-critical development and sustainment program to design, build, deliver, and operate a network operations environment...


  • Arlington, Virginia, United States Jacobs Full time

    Your Impact:The Systems Analyst IV position is a part of a team that delivers Cloud Development Tools to the entire enterprise. The team is fully cloud-based and focuses on the automation of all tasks utilizing a fully implemented CI/CD pipeline. This pipeline includes an automated transfer of data/projects to multiple domains via a cross-domain solution....


  • Arlington, Virginia, United States Dhara Consulting Group Full time

    Today Dept of Homeland Security Unspecified Unspecified IT Hardware Arlington, VA (ON-SITE/OFFICE)Date Posted:Country:United States of AmericaLocation:VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USAPosition Role Type:HybridYou have been redirected to RTX's career page as we have recently transitioned from RTX to...


  • Arlington, Virginia, United States Raytheon Full time

    Date Posted:Country:United States of AmericaLocation:VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USAPosition Role Type:HybridYou have been redirected to RTX's career page as we have recently transitioned from RTX to become a standalone company, which provides us with greater autonomy and opportunities for growth....


  • Arlington, Virginia, United States IVA'AL Solutions, LLC Full time

    :IVA'AL Solutions, LLC is seeking highly skilled Cyber Intelligence Planner III to provide services on a contract supporting DHS CISA Joint Cyber Defense Collaborative (JCDC).This position requires a positive attitude, strong organizational skills, a drive to focus and produce results, and the ability to lead a team to meet objectives and foster strong...


  • Arlington, Virginia, United States Ampcus Incorporated Full time

    Network Forensic Analyst Multi Year Salaried Contract 2-3 Weeks of Training in Arlington, VAConsultants living within 50 miles of Arlington, VA will need to be onsite 1 time per weekHybrid (2-3) days onsite for consultants living closer than 50 miles to Arlington, VAMust have ACTIVE TS Clearance The Client's Hunt and Incident Response Team (HIRT) secures the...


  • Arlington, Virginia, United States Rapid7 Full time

    Lead Threat Intelligence & Detection Engineer, Threat Intelligence & Detection EngineeringAbout the TeamRapid7's Threat Intelligence & Detection Engineering (TIDE) team is built from the ground up to provide our customers with high-fidelity threat detections and alerting that limit threat actor dwell time and impact across our customers' ecosystems. Our TIDE...


  • Arlington, Virginia, United States Solutions , LLC Full time

    Network Based Systems Analyst - III - NBA03 The DHSs Hunt and Incident Response Team (HIRT) secures the Nations cyber and communications infrastructure. HIRT provides DHSs front-line response for cyber incidents and proactively hunting for malicious cyber activity. Solutions3 Technologies (RTX), as a prime contractor to DHS, performs HIRT investigations to...


  • Arlington, Virginia, United States Solutions³ LLC Full time

    Network Based Systems Analyst - II - NBA02Solutions3 Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for digital...