theta. · 2 months ago
CSOC Sr. Cyber Defense Analyst
Theta. is a SBA-Certified 8(a) & HUBZone digital integration and management firm based in Baltimore, MD, working to create a world where tech works for everybody. They are seeking a Sr. Cyber Defense Analyst to support the Department of Veterans Affairs’ Cybersecurity Operations Center, focusing on detection engineering and automation to enhance national systems security.
Cloud InfrastructureDatabaseInformation TechnologySoftware
Responsibilities
Engineer and tune detections across Splunk, Microsoft Sentinel, Defender for Endpoint, and other monitoring tools to detect advanced threats in real time
Design and implement detection logic, map activity to MITRE ATT&CK, and reduce false positives through feedback loops and automated correlation
Leverage SOAR platforms to automate enrichment, containment, and remediation workflows for high-priority threats
Onboard and operationalize new data sources, ensuring data quality, completeness, and performance consistency
Apply machine learning and pattern analysis techniques to identify anomalies and improve detection accuracy
Lead detection optimization efforts across cloud, SaaS, identity, and networking environments
Collaborate with cross-functional teams (IR, Forensics, Threat Intel, IT, and Network Engineering) to align threat detection with enterprise operations
Participate in cybersecurity exercises, simulations, and continuous improvement of analytics and automation processes
Qualification
Required
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline —or equivalent practical experience
8+ years of experience supporting large-scale IT or cybersecurity programs, including 4+ years in enterprise SOC or IR environments
Deep understanding of security analytics, detection engineering, and incident response methodologies
Proficiency with SIEM, IDS/IPS, EDR, and SOAR platforms (e.g., Splunk, Microsoft Sentinel, Defender for Endpoint)
Experience mapping detections to MITRE ATT&CK and tuning detections for high signal fidelity
Strong scripting or query development skills (SPL, KQL, or Python)
Excellent written and verbal communication skills
U.S. Citizenship required
Must be able to meet any other requirements for government contracts for which they are hired (e.g., must reside in the U.S., Security Clearances)
Some of our clients may occasionally request or require travel
Preferred
SANS certifications such as GCFE, GCIH, GNFA, or equivalent level are strongly preferred
Experience operationalizing detections in cloud-native security tooling (Azure Sentinel, AWS GuardDuty, Google Chronicle)
Familiarity with machine learning models and behavioral analytics for anomaly detection
Experience developing and implementing feedback processes for continuous tuning and performance improvement
Benefits
Comprehensive health benefits
Retirement plans
Flexible work arrangements