Senior Cyber Defense Analyst with Secret Clearance
CALNET, Inc. - Fort Liberty, NC
Hiring: Senior Cyber Defense Analyst with Secret Clearance Company: CALNET, Inc. Location: Fort Liberty, NC Job Posted Time: 2026-09-10 13:28:06 Target Skills & Keywords : SIEM, Secret Clearance About the job Experience: •5+ years’ IT Infrastructure experience Required Skills: •Bachelor’s Degree in an IT field preferred •U.S Citizenship and Secret Clearance is required. •5+ years’ IT Infrastructure experience •This opportunity is in Fort Bragg, NC •CALNET, Inc. offers a competitive salary and a generous benefits package. This package includes medical, dental, vision, life, short- and long-term disability insurances, a 401(k)-retirement savings plan, and generous leave time. Qualifications: •Network Security Monitoring and Event Analysis. •Conduct continuous monitoring using the enterprise SIEM platform (currently Elastic SIEM, or successor as designated by the Government) and supporting big-data analytics and detection tooling. •Analyze and correlate anomalous events across SIEM, host-based security (Trellix ENS or successor), endpoint detection (Tychon or successor), full packet capture (PCAP), NetFlow, IDS/IPS (Snort, Suricata, Sourcefire, Fidelis, Zeek), forward and reverse proxy logs, router/firewall syslog, and JRSS-equivalent boundary devices. •Perform exploratory and in-depth analysis of host-based audit logs, captured network traffic, malware artifacts, and incident report trends to characterize threats and identify Advanced Persistent Threat (APT) activity not detected via traditional means. •Develop, document, and refine a definable, repeatable triage process and support analytic scripts to enable consistent escalation across the analyst team. •Maintain and update SIEM correlation rules, watchlists, and detection logic, and coordinate signature submissions with ARCYBER signature working groups for global implementation where appropriate. •Incident Response and Internal Defensive Measures (IDM). •Execute critical blocks within two (2) hours of notification or detection (or as otherwise determined by event criticality) to mitigate ongoing threat activity within the AOR. •Execute immediate (within 24 hours) action steps to mitigate threats where the operational impact of delay would exceed acceptable risk. •Capture and perform initial analysis of volatile data, log data, and captured network traffic; maintain incident chain of custody IAW ARCYBER F&MA procedures and coordinate shipment of original forensic evidence to ARCYBER F&MA for imaging when required. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!