Cyber Security Analyst

Trinity Cyber - Washington, DC

Hiring: Cyber Security Analyst Company: Trinity Cyber Location: Washington, DC Job Posted Time: 2026-09-16 14:21:12 Employment Type: On-site Target Skills & Keywords : DNS, Embedded Systems, JavaScript, PowerShell, Python, QUIC, SIEM, SOC, Security Clearance, Splunk, TCP/IP, TLS About the job Required Skills: •This position supports a major U.S. Government customer, is based on-site in the Washington, DC metro area, and requires an active Top Secret/SCI clearance. •Study adversary TTPs, analyze network traffic and PCAPs at the protocol level, and identify how adversaries abuse, or hide within legitimate traffic, then turn those findings into opportunities to counter the adversary at scale. Maintain expertise on emerging threats, malware, and FCI methodologies. •Evaluate customer network architectures, traffic flows, and enclave boundaries to advise on optimal FCI placement, coverage, and blind spots. Help analysts integrate FCI into detection, investigation, and incident response workflows, and assist cyber investigations where FCI can improve detection fidelity and operational outcomes. •Communicate technical findings and recommendations to both government and Trinity Cyber engineering teams, and capture customer operational requirements as product feedback that shapes future FCI capabilities. Qualifications: •Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance. •Local to the Washington, DC metro area, with the ability to work on-site at the customer location. •Prior experience as a Security Operations Center (SOC) analyst, threat hunter, incident responder, or in a similar cyber operations role, with a strong understanding of adversary tradecraft, analyst workflows, event triage, investigations, and incident response. •Prior hands-on experience developing, tuning, validating, or operationalizing network detection technology in production environments, with depth sufficient to scope, evaluate, and guide detection engineering performed by others. •Demonstrated ability to rapidly learn complex cybersecurity technologies and become the trusted technical authority for those capabilities. •Network traffic analysis, including expert-level packet analysis (PCAP) and deep, layer-by-layer understanding of protocols such as TCP/IP, DNS, TLS, HTTP/HTTPS, SMB, SMTP, and QUIC, including how adversaries abuse them. •Scripting and automation skills in Python, PowerShell, JavaScript, or similar, including developing and testing complex regular expressions (PCRE). •Operational familiarity with the MITRE ATT&CK framework as applied to detection development. •Excellent written and verbal communication skills, with the ability to explain complex technical concepts to analysts, engineers, and government leadership. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!