Security Engineer Iii, Exploitation Analyst / Incident Responder (ts Clearance)

Security Engineer III focused on exploitation analysis and incident response, involving threat intelligence, vulnerability assessment, malware analysis, and technical reporting within a cybersecurity context. Requires a Top-Secret Clearance.

What you'd actually do

  1. Monitor networks, systems, and applications for indicators of compromise and analyze threat data to identify malicious activity.
  2. Investigate security incidents, collect and analyze logs, memory artifacts, network traffic, and support containment, eradication, and recovery activities.
  3. Identify and assess vulnerabilities in systems, networks, and applications and recommend remediation actions based on risk and exploitability.
  4. Analyze malware, exploits, and adversary tools, including reverse engineering malicious code and simulating adversary techniques in controlled environments.
  5. Prepare technical reports, briefings, and documentation that summarize findings, methodologies, and recommendations for stakeholders.

Skills

Required

  • Cyber exploitation analysis
  • Threat intelligence
  • Incident response
  • Malware analysis
  • Reverse engineering (IDA Pro, Ghidra)
  • Vulnerability assessment
  • Penetration testing
  • Red team activities
  • Network traffic analysis
  • Log analysis
  • Digital forensics
  • Windows
  • Linux
  • macOS
  • Common network protocols
  • Scripting languages (Python, PowerShell, Bash)
  • Security monitoring tools (SIEM, IDS, IPS, EDR)
  • Global Information Assurance Certification (GIAC)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Security+

Nice to have

  • Experience supporting incident response in government, defense, intelligence, or large enterprise environments
  • Experience analyzing packet captures, memory dumps, and host-based forensic artifacts
  • Experience mapping threat activity to the MITRE ATT&CK framework
  • Experience developing or tuning detections for SIEM or EDR platforms

What the JD emphasized

  • Active Top-Secret Clearance with SCI eligibility
  • 2+ years of experience within the following
  • Experience analyzing advanced persistent threats (APTs), malware, exploitation techniques, and reverse engineering tools such as IDA Pro or Ghidra
  • Experience performing vulnerability assessments, penetration testing, or red team activities
  • Experience with network traffic analysis, log analysis, digital forensics, Windows, Linux, macOS, common network protocols, scripting languages such as Python, PowerShell, or Bash, and security monitoring tools such as security information and event management (SIEM), intrusion detection systems (IDS), intrusion prevention systems (IPS), or endpoint detection and response (EDR)
  • Industry certifications such as Global Information Assurance Certification (GIAC), Certified Information Systems Security Professional (CISSP) or CompTIA Security+ is required.