Cyber Analytics Engineer III
Listed on 2026-08-30
-
IT/Tech
Cybersecurity
Cyber Threat Detection Engineer (SIEM / Signatures)
Location: St. Louis, MO - on site
Time Type: Full time, Exempt
Clearance Required to Start: Active TS/SCI (U.S. citizenship required)
Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)
Travel: None
Salary Range: $78,000 – $86,000
Adversaries are already inside somebody's enterprise. Make sure it isn't this one.
RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.
What You Will Do- Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
- Turn intelligence and incident reporting into deployed detection logic.
- Run regular Purple Team exercises and continuously validate countermeasures already deployed.
- Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
- Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
- Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.
- U.S. citizenship and an active TS/SCI.
- Ability to successfully obtain and maintain a Government polygraph after hire.
- Education and experience, per the contract labor category criteria:
Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. - 8+ years of related advanced cyber security analytics experience.
- A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
- Data mining or query building in a SIEM.
- Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
- Static file signatures (magic numbers) and good working knowledge of regular expressions.
- Hex editor comfort;
Python, Bash, or Power Shell scripting. - Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.
Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.
BenefitsMedical, dental, and vision insurance; 401(k) and Roth;
Paid Time Off; and 11 paid Federal Holidays.
RISA is an Equal Opportunity Employer.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).