TS/SCI eligibility, including eligibility for reciprocal acceptance, preferred.
Advanced cybersecurity certifications, such as CISSP, CASP+, CySA+, CEH, GIAC GCIH, GCIA, GCED, GCTI, or comparable credentials.
Experience supporting DISA, Department of Defense networks, Cyber Security Service Provider operations, Cyber Protection Teams, or a large enterprise SOC.
Experience conducting threat hunting and cyber investigations across NIPRNet, SIPRNet, JWICS, cloud, commercial, or similarly complex enterprise environments.
Experience using SIEM, EDR, threat-intelligence, and network-analysis tools—such as Splunk, Elastic, Microsoft Defender for Endpoint, Microsoft Sentinel, Google Threat Intelligence, VirusTotal, Wireshark, PCAP, and NetFlow—to develop or tune correlation searches, detection rules, signatures, threat blocks, analytic queries, dashboards, and automated enrichment workflows.
Familiarity with commercial threat-intelligence platforms; malware analysis; digital and network forensics; endpoint telemetry; intrusion detection; vulnerability research; cloud security; and intelligence-driven defense methodologies, including MITRE ATT&CK; and Cyber Kill Chain.
Familiarity with query languages and scripting tools, such as SPL, KQL, Lucene, SQL, Python, PowerShell, and Unix/Linux command-line utilities.
Experience producing intelligence products, operational reports, and executive briefings for executives, General Officer/Flag Officer, Executive Service, or equivalent leadership; demonstrated ability to lead complex cyber investigations or threat hunts and mentor junior technical staff