Host Based Systems Analyst - IV – SME with Security Clearance

Base One Technologies
Arlington, Virginia 22202 United States  View Map
Posted: May 30, 2026
  • Full Time
  • Federal Government
  • Summary

    Responsibilities:
    • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
    • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
    • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
    • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
    • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
    • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
    • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings. Required Skills:
    • U.S. Citizenship
    • Active TS/SCI clearance
    • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
    • 5+ years of experience in cyber forensic investigations with leading tools and techniques.
    • Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.
    • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
    • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
    • Knowledge of AWS, IAM, and best practices for cloud identity security. Desired Skills:
    • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
    • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
    • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker). Required Education:
    BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 7+ years relevant experience. Desired Certifications:
    GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS or Microsoft Cloud/Security certifications
  • Job Description

    Responsibilities:
    • Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
    • Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
    • Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
    • Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
    • Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
    • Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
    • Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings. Required Skills:
    • U.S. Citizenship
    • Active TS/SCI clearance
    • Ability to obtain Department of Homeland Security (DHS) Entry on Duty (EOD) Suitability
    • 5+ years of experience in cyber forensic investigations with leading tools and techniques.
    • Strong understanding of SaaS, PaaS, and IaaS in cloud environments, and hybrid identity security.
    • Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
    • Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
    • Knowledge of AWS, IAM, and best practices for cloud identity security. Desired Skills:
    • Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
    • Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
    • Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker). Required Education:
    BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 7+ years relevant experience. Desired Certifications:
    GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS or Microsoft Cloud/Security certifications
  • ABOUT THE COMPANY

    • Government Careers
    • Government Careers

    Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

    Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

    Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

    Show more

MORE JOBS

  • Traffic Control Flagger

    • Athens, Georgia
    • US Traffic Control
    • May 30, 2026
    • Full Time
    • Federal Government
    • Transportation or Transit
  • C4ISR Analyst

    • Dayton, Ohio
    • Radiance Technologies
    • May 30, 2026
    • Full Time
    • Federal Government
  • Administrative Specialist - SECRET Clearance Jobs

    • Little Rock, Arkansas
    • ClearanceJobs
    • May 30, 2026
    • Full Time
    • Federal Government
  • Luxury SUV Driver | Nights and Weekends (91776)

    • San Gabriel, California
    • ALTO
    • May 30, 2026
    • Full Time
    • Federal Government
    • Other
  • Account Specialist

    • Austin, Nevada
    • TradeJobsWorkforce
    • May 30, 2026
    • Full Time
    • Accounting and Finance
    • Federal Government
  • Full Time Gig Driver | Nights and Weekends (91702)

    • Azusa, California
    • ALTO
    • May 30, 2026
    • Full Time
    • Federal Government
    • Other
Show More
Apply Now Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.
Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.