FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Cyber Defense Analyst II
BLUE ORIGIN. Monitor and triage security events and alerts across SIEM, EDR, network sensors, and audit logs .
Posted 9/18/2026full-timeColorado • United StatesJuniorMid-Level💰 $90,934 - $127,307 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security operations and incident response, with a strong focus on monitoring, investigation, and documentation of security events. Proficient in utilizing SIEM and EDR tools, scripting for automation, and maintaining compliance with government security standards.
Highest-signal resume keywords
Security OperationsIncident ResponseSIEM and EDR ProficiencyActive U.S. Government Top Secret ClearanceScripting with Python, PowerShell, or Bash
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security OperationsIncident ResponseNetwork ProtocolsWindows FundamentalsLinux FundamentalsSIEM ConceptsEDR ConceptsMITRE ATT&CK FrameworkScripting with PythonScripting with PowerShell
Soft Skills
Clear Written Communication
Tools & Technologies
SIEMEDRNetwork SensorsAudit LogsClassified National Security Systems
Certifications & Qualifications
DoD 8140 CSSP AnalystIAT Level II CertificationSecurity+ CECySA+GSECGCIH
Industry Keywords
Incident InvestigationThreat HuntingPrivileged User Activity MonitoringForensicsMalware Triage
Tech Stack
Tools & technologiesLinuxPythonTypeScript
About the role
Key responsibilities & impact- Monitor and triage security events and alerts across SIEM, EDR, network sensors, and audit logs
- Determine whether activity is noise, misconfiguration, or warrants escalation
- Investigate incidents by pivoting across host, network, and identity data
- Document investigations clearly
- Serve as first responder during incidents
- Execute containment steps per playbook, preserve evidence, build timelines, and support senior engineers
- Participate in structured threat hunts
- Perform privileged user activity monitoring and audit log review with Security and Counterintelligence
- Provide heightened monitoring coverage during launches, mission operations, and other critical windows
- Assist with sensor deployment, log source onboarding, and agent rollout across classified enclaves
- Tune detections, reduce false positives, validate rule coverage, and propose new detections
- Execute response procedures and identify playbook gaps
- Script recurring triage, enrichment, and reporting tasks
- Collaborate with senior engineers working on classified national security systems
Requirements
What you’ll need- 2+ years of hands-on experience in security operations, incident response, IT operations, or system administration, or equivalent military/government cyber experience
- Working knowledge of network protocols and Windows and Linux fundamentals
- Familiarity with SIEM and EDR concepts and ability to investigate events using them
- Understanding of common attack techniques and exposure to the MITRE ATT&CK framework
- Clear, concise written communication
- Active U.S. Government Top Secret clearance with SCI eligibility and eligibility for SAP access determination
- U.S. citizenship
- DoD 8140 CSSP Analyst or IAT Level II certification (Security+ CE or equivalent) at hire or within 6 months
- Ability to obtain and maintain access to classified facilities
- Periodic polygraph may be required
- A degree is not required; equivalent military, government, or hands-on technical experience is accepted
- Preferred: prior military cyber experience or CPT/CST assignment
- Preferred: scripting exposure with Python, PowerShell, or Bash
- Preferred: query language familiarity with KQL, SPL, or similar
- Preferred: prior work in classified DoD or IC environments
- Preferred: exposure to forensics, malware triage, or detection rule development
- Preferred: Security+, CySA+, GSEC, GCIH, or similar
- Preferred: active TS/SCI with polygraph
Benefits
Comp & perks- Medical, dental, and vision insurance
- Basic and supplemental life insurance
- Paid parental leave
- Short- and long-term disability
- 401(k) with a company match of up to 5%
- Education Support Program
- Stock options for all regular employees working at least 20 hours/week
- Up to four weeks of paid time off per year based on weekly scheduled hours
- Up to 14 company-paid holidays
- Potential benefits and bonuses based on role type, job level, individual contributions, and company results
- Limited travel, up to 10%