Cyber Defense Analysts – Senior
Listed on 2026-09-13
-
IT/Tech
Cybersecurity
This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.
Koniag Operations Services, LLC (KOS), a Koniag Government Services company, is seeking a Cyber Defense Analysts – Senior to support KOS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.
We are seeking an experienced Senior Cyber Defense Analyst to support the U.S. Small Business Administration (SBA). The ideal candidate is a skilled cybersecurity professional with a strong background in cyber defense operations, advanced threat analysis, and incident response within a federal government environment. This individual will play a critical role in protecting SBA's systems, networks, and data by performing advanced security monitoring, conducting in-depth threat analysis, and leading incident response activities in alignment with federal cybersecurity policies and SBA security requirements.
The Senior Cyber Defense Analyst will serve as a senior-level cybersecurity operations professional responsible for performing advanced monitoring, detection, analysis, and response to cybersecurity threats targeting SBA's enterprise IT environment. This individual will bring deep technical expertise and operational experience to the SOC team, taking ownership of complex security investigations, leading incident response activities, and contributing to the continuous improvement of SBA's cyber defense capabilities.
PrincipalResponsibilities Will Include But Are Not Limited To
- Perform advanced, continuous monitoring of SBA networks, systems, endpoints, and cloud environments using SIEM platforms, IDS/IPS tools, EDR solutions, and other security technologies to detect, identify, and respond to potential threats, anomalies, and indicators of compromise targeting SBA's enterprise IT environment.
- Conduct advanced analysis and in-depth triage of security events, alerts, and incidents, determining the validity, scope, severity, and potential impact of identified threats, and escalating confirmed or suspected incidents to the Cybersecurity Operations Technical Lead in accordance with established SBA incident response procedures and SLAs.
- Lead and coordinate incident response activities for significant and complex cybersecurity incidents, including containment, eradication, recovery, and post-incident review, in strict accordance with SBA's incident response policies, NIST SP 800-61 guidelines, and applicable federal requirements.
- Perform advanced threat hunting activities, proactively searching SBA's enterprise environment for indicators of compromise (IOCs), hidden adversary activity, and sophisticated threats that have evaded automated detection, leveraging the MITRE ATT&CK framework, threat intelligence, and advanced analytical techniques.
- Conduct detailed analysis of network traffic, system logs, endpoint telemetry, and other relevant data sources to reconstruct attack timelines, characterize adversary TTPs, identify root causes, and determine the full scope and impact of security incidents affecting SBA systems and data.
- Develop and recommend enhancements to SIEM detection rules, correlation logic, behavioral analytics, and alerting thresholds based on threat hunting findings, incident analysis results, and emerging threat intelligence, working with the Technical Lead to implement approved improvements.
- Analyze and operationalize threat intelligence from government and commercial sources, including…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).