Cyber Network Defense Analyst (CNDA) III - Cloud Forensics Job at ARGO Cyber Systems, Arlington, VA

bTg3YUs2SkN1MXVoVUVLeUJHRVludlhydUE9PQ==
  • ARGO Cyber Systems
  • Arlington, VA

Job Description

Cyber Network Defense Analyst (CNDA) - Cloud Forensics

Location: Remote / Onsite (as required)
Clearance: Active TS/SCI (DHS EOD eligibility required)
Company: Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small Business (SDVOSB)
About Argo Cyber Systems

Argo Cyber Systems delivers advanced cybersecurity and threat-hunting capabilities to safeguard federal and critical infrastructure environments. Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission experience with innovation-empowering our customers to detect, disrupt, and defeat adversaries in real time.
Position Overview

Argo Cyber Systems is seeking Cyber Network Defense Analysts (CNDA) with deep Cloud Forensics expertise to support a high-visibility federal mission. The CNDA will lead advanced investigations into sophisticated intrusions across hybrid and multi-cloud environments, identifying attacker tactics, techniques, and procedures (TTPs), correlating artifacts, and driving containment and remediation actions in partnership with government cyber teams.
Key Responsibilities
  • Conduct end-to-end forensic acquisition and analysis across on-premises, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, SaaS).
  • Investigate identity-based and credential-abuse incidents targeting cloud control planes and hybrid identity infrastructure .
  • Correlate cloud telemetry (Azure Activity Logs, AWS CloudTrail, GCP Logs, VPC Flow Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs).
  • Develop and deploy automated detection logic , threat-hunting scripts, and analytical playbooks using Microsoft Sentinel, Defender, AWS GuardDuty, and GCP Chronicle .
  • Produce comprehensive technical and executive-level reports , integrating findings across endpoints, networks, and cloud assets to inform threat containment and strategic recommendations.
  • Support continuous improvement of incident response procedures, forensics workflows, and threat-hunting operations .
  • Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen enterprise detection and response posture.
Required Qualifications
  • U.S. Citizenship and active TS/SCI clearance (with ability to obtain DHS EOD Suitability).
  • Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR).
  • Proven expertise in cloud forensics, identity security, and hybrid infrastructure defense.
  • Proficiency in M365/Azure AD, AWS IAM, and SaaS investigative methodologies.
  • Deep understanding of SaaS/PaaS/IaaS architectures , including common attack vectors and defensive measures.
  • Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting.
Desired Qualifications
  • Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript .
  • Familiarity with Terraform, Kubernetes, Docker, CloudFormation, or Azure Resource Manager for automation and orchestration.
  • Understanding of MITRE ATT&CK for Cloud and adversary emulation techniques.
  • Strong communication and collaboration skills for working across multidisciplinary teams.
Education
  • Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field
    or
  • High School Diploma and 10+ years of directly relevant DFIR experience.
Preferred Certifications
  • GIAC Cloud Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
  • AWS and Microsoft security/cloud certifications (e.g., Azure Security Engineer, AWS Security Specialty)
Why Argo Cyber Systems

At Argo, you'll be part of a mission-driven, veteran-founded cybersecurity team protecting America's most critical systems. We combine hands-on technical excellence with operational precision to outpace the threat. Join us to defend, detect, and innovate at the cyber edge.

Job Tags

Remote work

Similar Jobs

Westchester Institute for Human Development

Medical Receptionist Job at Westchester Institute for Human Development

 ...Full Time Medical Receptionist Location: Valhalla, NY Schedule: Monday thru Friday, 8:30am 4:30pm Summary of Receptionist Position: WIHD is recruiting a full time Medial Receptionist to serve as the primary point of contact for patients, caregivers,... 

National Coalition of Healthcare Recruiters

Medical Technologist OR Medical Laboratory Scientist or MLT in Raleigh Job at National Coalition of Healthcare Recruiters

 ...consideration applicants must have a B.S. or A.S, degree in Medical Technology|Medical Laboratory Technician as well as a MT or MLS or MLT ASCP Certifications (or equivalent). Experienced applicants and new graduates are encouraged to apply! Compensation includes... 

Logitech

Digital Marketing Intern Job at Logitech

 ...Digital Account-based Marketing Intern Logitech is the sweet spot for people who want their actions to have a positive global impact while having...  ...within a fast-paced marketing team. This internship provides hands-on experience in cutting-edge account-based... 

Hot Air Express, Inc

Delivery Driver for FedEx Contractor - Full-Time and Part-Time Job at Hot Air Express, Inc

 ...Job Description Overview Hot Air Express, Inc. is a third-party contractor for FedEx. We are seeking reliable and motivated Delivery Drivers to join our team. We need full-time and part-time drivers. The ideal candidate will be responsible for transporting goods... 

Maxion Corp

Remote Online Data Entry Work From Home - Entry Level Job at Maxion Corp

 ...PasadenaFullertonPomonaGlendaleLos AngelesDowneyWest CovinaNorwalkComptonSouth GateThe 10 most popular job searches in El Monte, CA are:governmentamazonconstructionfactory workerwork from homewarehouseamazon warehouseonlinecitycashier#J-18808-Ljbffr...