Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BLUE ORIGIN

Cyber Defense Analyst II

BLUE ORIGIN

. Monitor and triage security events and alerts across SIEM, EDR, network sensors, and audit logs .

Posted 9/18/2026full-timeColorado • United StatesJuniorMid-Level💰 $90,934 - $127,307 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security operations and incident response, with a strong focus on monitoring, investigation, and documentation of security events. Proficient in utilizing SIEM and EDR tools, scripting for automation, and maintaining compliance with government security standards.

Highest-signal resume keywords
Security OperationsIncident ResponseSIEM and EDR ProficiencyActive U.S. Government Top Secret ClearanceScripting with Python, PowerShell, or Bash

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security OperationsIncident ResponseNetwork ProtocolsWindows FundamentalsLinux FundamentalsSIEM ConceptsEDR ConceptsMITRE ATT&CK FrameworkScripting with PythonScripting with PowerShell
Soft Skills
Clear Written Communication
Tools & Technologies
SIEMEDRNetwork SensorsAudit LogsClassified National Security Systems
Certifications & Qualifications
DoD 8140 CSSP AnalystIAT Level II CertificationSecurity+ CECySA+GSECGCIH
Industry Keywords
Incident InvestigationThreat HuntingPrivileged User Activity MonitoringForensicsMalware Triage

Tech Stack

Tools & technologies
LinuxPythonTypeScript

About the role

Key responsibilities & impact
  • Monitor and triage security events and alerts across SIEM, EDR, network sensors, and audit logs
  • Determine whether activity is noise, misconfiguration, or warrants escalation
  • Investigate incidents by pivoting across host, network, and identity data
  • Document investigations clearly
  • Serve as first responder during incidents
  • Execute containment steps per playbook, preserve evidence, build timelines, and support senior engineers
  • Participate in structured threat hunts
  • Perform privileged user activity monitoring and audit log review with Security and Counterintelligence
  • Provide heightened monitoring coverage during launches, mission operations, and other critical windows
  • Assist with sensor deployment, log source onboarding, and agent rollout across classified enclaves
  • Tune detections, reduce false positives, validate rule coverage, and propose new detections
  • Execute response procedures and identify playbook gaps
  • Script recurring triage, enrichment, and reporting tasks
  • Collaborate with senior engineers working on classified national security systems

Requirements

What you’ll need
  • 2+ years of hands-on experience in security operations, incident response, IT operations, or system administration, or equivalent military/government cyber experience
  • Working knowledge of network protocols and Windows and Linux fundamentals
  • Familiarity with SIEM and EDR concepts and ability to investigate events using them
  • Understanding of common attack techniques and exposure to the MITRE ATT&CK framework
  • Clear, concise written communication
  • Active U.S. Government Top Secret clearance with SCI eligibility and eligibility for SAP access determination
  • U.S. citizenship
  • DoD 8140 CSSP Analyst or IAT Level II certification (Security+ CE or equivalent) at hire or within 6 months
  • Ability to obtain and maintain access to classified facilities
  • Periodic polygraph may be required
  • A degree is not required; equivalent military, government, or hands-on technical experience is accepted
  • Preferred: prior military cyber experience or CPT/CST assignment
  • Preferred: scripting exposure with Python, PowerShell, or Bash
  • Preferred: query language familiarity with KQL, SPL, or similar
  • Preferred: prior work in classified DoD or IC environments
  • Preferred: exposure to forensics, malware triage, or detection rule development
  • Preferred: Security+, CySA+, GSEC, GCIH, or similar
  • Preferred: active TS/SCI with polygraph

Benefits

Comp & perks
  • Medical, dental, and vision insurance
  • Basic and supplemental life insurance
  • Paid parental leave
  • Short- and long-term disability
  • 401(k) with a company match of up to 5%
  • Education Support Program
  • Stock options for all regular employees working at least 20 hours/week
  • Up to four weeks of paid time off per year based on weekly scheduled hours
  • Up to 14 company-paid holidays
  • Potential benefits and bonuses based on role type, job level, individual contributions, and company results
  • Limited travel, up to 10%