External Job Description
ADVANCED CONCEPTS is an entity within EDGE dedicated to the design and deployment of advanced, innovative technologies. ADVANCED CONCEPTS is fast-tracking the development of high-technology autonomous systems, including three Medium Endurance, High Altitude, fixed-wing unmanned aerial systems, a family of precision loitering munitions, a cost- effective family of cruise missiles, and a range of guided artillery munitions.
Core Accountabilities:
- Monitor and analyze security events and alerts from SIEM, EDR, DLP, and network security tools
- Perform incident detection, triage, investigation, and response in classified environments
- Identify and analyze cyber threats, attack patterns, and suspicious activities
- Conduct threat analysis and correlation across multiple log sources
- Perform vulnerability analysis and support remediation tracking
- Investigate unauthorized access, malware infections, and data exfiltration attempts
- Maintain incident records, reports, and forensic evidence for audit and compliance
- Ensure adherence to NIST SP 800-53 and NIST SP 800-171 standards
- Support tuning and optimization of SIEM use cases and detection rules
- Improve monitoring capabilities and alert accuracy
- Collaborate with IT and other departments to ensure security measures are integrated into projects and operations.
- Provide input to risk assessments and security posture improvements
- Support audits and compliance activities
- Participate in incident response drills and exercises
- Perform other responsibilities and additional duties as assigned in a timely manner.
Qualification / Experience
- Bachelor's degree in information Security, Information Technology, Computer Science, or a related field.
- 3–5 years in cybersecurity operations, SOC, or incident response
- Hands-on experience with SIEM, EDR/XDR, and log analysis
- Experience in classified or high-security environments preferred
- Understanding of cyber threats, attack vectors, and MITRE ATT&CK
- Knowledge of incident response lifecycle and vulnerability management
- Familiarity with network protocols and security tools
- Familiarity with vulnerability scanning and patch management process.
- Knowledge of NIST SP 800-53 and NIST SP 800-171
- Certifications: Security+, CySA+, CEH, CISSP (preferred)