- Salary
- $95k – $125k/yr
- Location
- Arlington, VA
- Type
- Full-time
- Education
- Bachelor
- Clearance
- Required
- Source
- ApplicantPro
Description
JCDC Cyber Triage Analyst – TS/SCI
Company: Argo Cyber Systems, LLC
Program: Engagement Support Services (ESS) – JCDC Cyber Operations
Clearance Required: Active TS/SCI
Citizenship: U.S. Citizenship Required
Suitability: Must be able to obtain and maintain DHS Suitability
Employment Type: Full-Time
Experience Level: Mid-Level | 5-7 + Years Cybersecurity Experience
About Argo Cyber Systems
Argo Cyber Systems, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing advanced cybersecurity services to U.S. Government and commercial customers.
Our cybersecurity capabilities include Security Operations Center operations, cyber incident response, threat hunting, cyber threat intelligence, vulnerability management, cloud security, Zero Trust, digital forensics and incident response, penetration testing, and cybersecurity risk and compliance services.
Argo Cyber Systems provides opportunities for experienced cybersecurity professionals to work directly on mission-focused programs protecting federal agencies and critical infrastructure from sophisticated cyber threats.
About the Mission
Argo Cyber Systems is supporting a U.S. Government customer in the rapid deployment and management of secure, cloud-based capabilities supporting cyber incident response, threat hunting, and national-level cybersecurity operations.
Under the Engagement Support Services (ESS) program, our team helps ensure cybersecurity analysts have rapid access to the secure tools, infrastructure, and operational environments required to investigate cyber threats affecting federal agencies, state and local governments, and U.S. critical infrastructure.
Working on this program means directly supporting the nation's cybersecurity defenders. Our mission is to provide reliable, scalable, and secure capabilities when they are needed most-during active cyber incidents and emerging threat campaigns affecting America's digital infrastructure.
Position Overview
Argo Cyber Systems is seeking an experienced JCDC Cyber Triage Analyst to serve as a frontline cyber defender supporting the Joint Cyber Defense Collaborative (JCDC).
The Cyber Triage Analyst performs initial analysis and triage of cyber threat reports, indicators of compromise (IOCs), incident notifications, and other cybersecurity information submitted to the JCDC.
This is not an entry-level or developmental analyst position.
The successful candidate will operate in a role comparable to a Tier 1/Tier 2 SOC Analyst with enhanced Cyber Threat Intelligence (CTI) responsibilities. Analysts are expected to independently research cyber activity, rapidly evaluate technical information, develop defensible analytical conclusions, identify intelligence and information gaps, and recommend appropriate follow-on actions.
This position requires strong technical analysis skills combined with the ability to communicate and coordinate effectively with government organizations, private-sector partners, critical infrastructure stakeholders, and other cybersecurity professionals.
Key Responsibilities
The JCDC Cyber Triage Analyst will:
- Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
- Analyze technical indicators and artifacts including IP addresses, domain names, URLs, file hashes, network traffic patterns, malware artifacts, and related telemetry.
- Assess the credibility, severity, scope, and potential operational impact of reported cyber activity.
- Evaluate potential impacts to federal networks and U.S. critical infrastructure sectors.
- Enrich IOCs using Threat Intelligence Platforms (TIPs), OSINT resources, commercial intelligence sources, and authorized government-exclusive resources.
- Correlate indicators with known threat actors, campaigns, malware families, vulnerabilities, tactics, techniques, and procedures (TTPs).
- Develop concise, defensible cyber triage reports containing analytical findings and actionable recommendations.
- Determine when incidents or threat activity require escalation or additional technical analysis.
- Route tickets and analytical findings to appropriate JCDC teams, CISA organizations, or interagency partners.
- Coordinate with sector-specific analysts, incident responders, threat hunters, intelligence analysts, and interagency liaisons to obtain additional technical and operational context.
- Maintain complete and accurate documentation within ticketing, case management, and knowledge management systems.
- Participate in operational shift handoffs and daily cybersecurity briefings.
- Monitor emerging cyber threat campaigns, adversary activity, vulnerabilities, and trends.
- Support development and continuous improvement of cyber triage playbooks, workflows, and Standard Operating Procedures (SOPs).
- Provide appropriate feedback to submitters and partner organizations regarding ticket status, findings, and disposition.
- Support collaboration across geographically distributed government and contractor teams.
Required Qualifications
Candidates must meet the following requirements:
- U.S. Citizenship.
- Active TS/SCI security clearance.
- Ability to obtain and maintain DHS Suitability.
- 2–4+ years of progressive cybersecurity experience supporting one or more of the following:
- Security Operations Center (SOC) operations
- Cyber Threat Intelligence (CTI)
- Cyber incident response
- Network security monitoring
- Threat hunting
- Cybersecurity operations
- Demonstrated ability to independently triage and analyze cybersecurity incidents, alerts, threat reports, or intelligence.
- Experience analyzing technical indicators such as IP addresses, domains, URLs, file hashes, network traffic, and malware-related artifacts.
- Experience researching and enriching IOCs using threat intelligence and OSINT resources.
- Ability to assess the severity, credibility, and potential impact of cyber threats.
- Ability to document analytical findings and develop concise, actionable recommendations.
- Strong technical research and analytical reasoning skills.
- Strong written and verbal communication skills.
- Ability to work effectively with government personnel, technical analysts, incident responders, intelligence professionals, and partner organizations.
- Ability to work collaboratively across geographically distributed teams and physical locations.
Desired Qualifications
Highly qualified candidates may possess experience in several of the following areas:
- Previous cybersecurity experience supporting CISA, FBI, NSA, DoD, DHS, or another federal cybersecurity or intelligence organization.
- Understanding of the National Cyber Incident Scoring System (NCISS) and its application to incident prioritization and triage.
- Knowledge of common cyberattack lifecycle stages, including:
- Reconnaissance and footprinting
- Scanning and enumeration
- Initial access
- Privilege escalation
- Persistence
- Network exploitation and lateral movement
- Command and control
- Defense evasion and covering tracks
- Demonstrated ability to recognize and categorize cybersecurity vulnerabilities and associated attack techniques.
- Knowledge of Computer Network Defense (CND) policies, procedures, processes, and regulations.
- Understanding of different operational threat environments, ranging from opportunistic attackers and cybercriminal organizations to sophisticated nation-state actors.
- Knowledge of system and application security threats and vulnerabilities, including:
- Buffer overflows
- Cross-site scripting (XSS)
- SQL/PL-SQL and other injection attacks
- Malicious or mobile code
- Race conditions
- Covert channels
- Replay attacks
- Return-oriented programming/attacks
- Other common application and network exploitation techniques
- Experience working with SIEM platforms, Threat Intelligence Platforms (TIPs), case management systems, and cybersecurity ticketing platforms.
- Familiarity with cyber threat intelligence concepts, adversary TTPs, and IOC lifecycle management.
- Knowledge of U.S. critical infrastructure sectors and associated cyber risks.
- Familiarity with DHS/CISA cybersecurity products, services, alerts, advisories, and operational processes.
- Experience working in an operational SOC, watch floor, incident response center, or cyber fusion environment.
Education
Candidates must possess one of the following:
Bachelor's degree from an accredited college or university in:
- Cybersecurity
- Computer Science
- Computer Engineering
- Information Technology
- Information Systems
- Network Engineering
- Another related technical discipline
OR
High School Diploma or equivalent plus at least four additional years of directly relevant technical cybersecurity experience.
Desired Certifications
One or more of the following certifications is preferred:
- CompTIA Security+
- CompTIA CySA+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Cyber Threat Intelligence (GCTI)
- Other comparable cybersecurity, incident response, SOC, or threat intelligence certifications
What We're Looking For
This role is well suited for a cybersecurity professional who can move beyond simply reviewing alerts.
We are looking for analysts who can receive incomplete or ambiguous cyber threat information, independently research the available evidence, determine what is technically significant, identify what information is missing, and develop a defensible recommendation for what should happen next.
Successful candidates should be comfortable operating in a fast-paced cyber operations environment where accurate analysis, concise communication, sound judgment, and timely escalation directly contribute to the protection of federal systems and U.S. critical infrastructure.
Argo Cyber Systems, LLC is an Equal Opportunity Employer. Employment decisions are made based on qualifications, merit, and business requirements consistent with applicable federal, state, and local law.