Threat Detection & Response Analyst
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.
This is a contingent position based on contract win.
SkyePoint Decisions is seeking a Threat Detection & Response Analyst to supports a cybersecurity program by monitoring enterprise systems for malicious activity, investigating security events, and responding to cybersecurity incidents. The Analyst leverages security monitoring tools, threat intelligence, and incident response procedures to identify and mitigate threats impacting information systems, networks, cloud environments, and applications.
This position works closely with Incident Response personnel, Vulnerability Management Analysts, Security Engineers, RMF teams, and system owners to strengthen cybersecurity defenses and protect mission-critical systems and sensitive research data. The role contributes to continuous monitoring, threat hunting, incident investigation, and security operations activities.
Responsibilities:
- Conduct proactive threat hunting activities using intelligence-driven and hypothesis-based methodologies.
- Analyze threat actor tactics, techniques, and procedures (TTPs) to identify potential compromise within environments.
- Map observed adversary behaviors, indicators, and attack patterns to the MITRE ATT&CK framework to support detection engineering, threat hunting, and risk analysis.
- Provide threat findings, indicators, and investigations supporting RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
- Monitor security tools, dashboards, and alerts to identify potential cybersecurity threats and suspicious activity.
- Analyze events from endpoint, network, cloud, and security monitoring platforms.
- Perform triage of security alerts to determine validity, severity, and potential impact.
- Identify indicators of compromise (IOCs), attack patterns, and emerging threats.
- Escalate significant security events in accordance with established procedures.
- Investigate cybersecurity incidents, security events, and anomalous activity.
- Conduct forensic review of logs, alerts, and system data to determine root cause and scope.
- Correlate information from multiple security tools and data sources.
- Document findings, recommendations, and lessons learned from investigations.
- Support post-incident reviews and corrective action planning.
- Provide threat and incident-related information supporting risk assessments and POA&M management activities.
- Assist with audit readiness and security assessment activities when requested.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
- Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or Security Operations Center (SOC) environments.
- Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
- Experience investigating cybersecurity incidents and analyzing security events.
- Knowledge of:
- Cyber threat tactics, techniques, and procedures (TTPs)
- Security Operations Center (SOC) processes
- Incident Response methodologies
- Network security concepts
- Endpoint security technologies
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity requirements
- Strong analytical, troubleshooting, and communication skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- Security+
- CySA+
- GCIH (GIAC Certified Incident Handler)
- GCIA (GIAC Certified Intrusion Analyst)
- CISSP
- CEH (Certified Ethical Hacker)
- GSEC
- CASP+
- CISM
- Experience supporting HHS or other Federal civilian agencies.
- Experience working in a Security Operations Center (SOC) environment.
- Knowledge of MITRE ATT&CK Framework methodologies.
- Experience supporting cloud security operations within Azure, AWS, or Google Cloud environments.
- Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
- Experience protecting healthcare, biomedical, or research-focused environments.
Compensation:
Salary Range: $95,000 - $110,000
The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.
Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.
In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.
What We Can Offer You:
- At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
- Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
- Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
- Flexible Work Environment
SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.
SkyePoint Decisions is a participating E-Verify Employer.
U.S. Citizenship is required for most positions.
Equal Opportunity Employer/Veterans/Disabled.
CCPA Disclosure Notice Here
Apply for this job
*
indicates a required field