Back to Jobs
Copper River Management Co.
Development 17h ago

Threat Detection & Response Analyst

Copper River Management Co.
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

QA EngineerBestseller 🔥
Learn in 10 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
CybersecurityAutomation Engineer

Want to know if you're a match for this job?

Calculate My Match Score

Copper River Cyber Solutions is seeking a highly motivated Threat Detection & Response Analyst to support the NIH cybersecurity program by monitoring enterprise systems for malicious activity, investigating security events, and responding to cybersecurity incidents. The Analyst leverages security monitoring tools, threat intelligence, and incident response procedures to identify and mitigate threats impacting NIH information systems, networks, cloud environments, and applications.

This position works closely with Incident Response personnel, Vulnerability Management Analysts, Security Engineers, RMF teams, and system owners to strengthen cybersecurity defenses and protect mission-critical systems and sensitive research data. The role contributes to continuous monitoring, threat hunting, incident investigation, and security operations activities.

Responsibilities (include but are not limited to):

  • Conduct proactive threat hunting activities using intelligence-driven and hypothesis-based methodologies.
  • Analyze threat actor tactics, techniques, and procedures (TTPs) to identify potential compromise within NIH environments.
  • Map observed adversary behaviors, indicators, and attack patterns to the MITRE ATT&CK framework to support detection engineering, threat hunting, and risk analysis.
  • Provide threat findings, indicators, and investigations supporting RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
  • Monitor security tools, dashboards, and alerts to identify potential cybersecurity threats and suspicious activity.
  • Analyze events from endpoint, network, cloud, and security monitoring platforms.
  • Perform triage of security alerts to determine validity, severity, and potential impact.
  • Identify indicators of compromise (IOCs), attack patterns, and emerging threats.
  • Escalate significant security events in accordance with established procedures.
  • Investigate cybersecurity incidents, security events, and anomalous activity.
  • Conduct forensic review of logs, alerts, and system data to determine root cause and scope.
  • Correlate information from multiple security tools and data sources.
  • Document findings, recommendations, and lessons learned from investigations.
  • Support post-incident reviews and corrective action planning.
  • Provide threat and incident-related information supporting risk assessments and POA&M management activities.
  • Assist with audit readiness and security assessment activities when requested.

Essential Job Qualifications and Requirements:

Education:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field

Required Qualifications:

  • Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or Security Operations Center (SOC) environments.
  • Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
  • Experience investigating cybersecurity incidents and analyzing security events.
  • Knowledge of:
    • Cyber threat tactics, techniques, and procedures (TTPs)
    • Security Operations Center (SOC) processes
    • Incident Response methodologies
    • Network security concepts
    • Endpoint security technologies
  • Familiarity with:
    • NIST RMF (SP 800-37)
    • NIST SP 800-53 Rev. 5
    • FISMA
    • Federal cybersecurity requirements
  • Strong analytical, troubleshooting, and communication skills.
  • Ability to obtain and maintain an NIH Public Trust.

Preferred Qualifications:

  • One or more of the following certifications:
    • Security+
    • CySA+
    • GCIH (GIAC Certified Incident Handler)
    • GCIA (GIAC Certified Intrusion Analyst)
    • CISSP
    • CEH (Certified Ethical Hacker)
    • GSEC
    • CASP+
    • CISM
  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience working in a Security Operations Center (SOC) environment.
  • Knowledge of MITRE ATT&CK Framework methodologies.
  • Experience supporting cloud security operations within Azure, AWS, or Google Cloud environments.
  • Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
  • Experience protecting healthcare, biomedical, or research-focused environments.

How would you rate this job post?

See what other professionals think about this role.

banner
logo

Copper River Management Co.

View Company Profile

Copper River Management Co. (operating at copperrivermc.com) is a federal government contracting platform/engineered for specialized services. Founded in 2006 by unknown founders and headquartered in Chantilly, VA, Copper River Management Co. specializes in federal and healthcare sectors instead of general contracting. Under the hood, the company leverages its expertise and workforce to deliver high-quality services. This allows clients to access critical health and social services, natural resource/environmental education, jobs, job training, and other essential programs. Backed by revenues between 100 million and 250 million dollars.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More