In this Advanced Cybersecurity Analytics Engineer III role, you will help shield enterprise networks by developing defensive countermeasures, analyzing data to detect and prevent breaches, and refining SIEM rules and signatures. Based onsite in St. Louis, youβll work across Defensive Cyber Operations and related teams to stay ahead of threats and continuously improve incident detection and response capabilities.
Responsibilities
- Examine data trends on NGA networks to uncover and anticipate previously unseen events, and craft or adjust rules, signatures, or scripts as needed
- Partner with Defensive Cyber Operations and Focused Operations to tailor or create new rules, signatures, and scripts
- Collaborate with other Cybersecurity Operations Services to investigate potential compromise sources on enterprise systems and refine countermeasures accordingly
- Correlate early indicators of incidents and translate insights into tuned detection rules and scripts
- Work with the Cyber Data Analytics team to improve SIEM alert efficiency by evaluating valid alerts and false positives, then adjust rules as needed
- Support the Cyber Incident Response Team by assessing ongoing activity to forecast adversary moves and locate compromise sites to aid triage
- Document all work in the authorized ticketing system with sufficient detail to enable stakeholders to reconstruct the analysis
- Offer input to recurring meetings and briefings as required
Requirements
- U.S. citizenship with an active TS/SCI clearance
- 8+ years of related advanced cybersecurity analytics experience
- Certification compliant with DoD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Analyst
- Experience mining data or building queries in a SIEM
- Strong knowledge of signature development and tuning
- Solid understanding of network protocols and analysis using protocol analyzers
- Knowledge of static file signatures, i.e. "magic numbers," and how they apply to countermeasures for files in transit and on hosts
- Proficiency with regular expressions
Technologies
- Python
- Bash
- PowerShell
- Hex Editor
Benefits
- Healthcare
- Wellness
- Financial
- Retirement
- Family support
- Continuing education
- Time off benefits
- Learning resources
The Opportunity
Reporting to the Lead of Focused Operations within the Defensive Cyber Operations branch, this role is responsible for developing and maintaining enterprise defense measures. Operating within a Fusion model, you will collaborate with Focused Operations teams to proactively prevent compromises and eradicate persistent adversaries already present in the environment, employing a range of approaches to strengthen the security posture.
What You Can Expect
Integrity guides the culture at CACI, with a focus on character and innovation in service of national missions. You will join a high-performing team dedicated to protecting critical operations and will have the autonomy to manage your time through flexible leave while accessing a robust set of learning resources to advance your career. The organization emphasizes continuous growth, ongoing mission impact, and opportunities to push beyond conventional boundaries in your professional path.
Pay Range
The proposed salary range for this position is: $75,200 - $158,100 per year.
CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.