Cyber Defense Analyst at Amentum in OCONUS-Australia-Alice Springs
- Company: Amentum
- Location: OCONUS-Australia-Alice Springs
- Posted: Sep 23, 2026
- Type: Full-time
- Experience: 10+ years
Overview
As a Cyber Defense Analyst, you will provide strategic guidance and technical analysis to detect incident response of adversarial cyber activity. Monitors and ensures proper functionality of network security devices across the enterprise, responding to Tiered alerts and escalating incidents as neces…
Job description
- As a Cyber Defense Analyst, you will provide strategic guidance and technical analysis to detect incident response of adversarial cyber activity.
Responsibilities
- Monitors and ensures proper functionality of network security devices across the enterprise, responding to Tiered alerts and escalating incidents as necessary.
- Conducts network traffic analysis using raw packet data, net flow, IDS/IPS, custom sensor output, and other tools to detect and mitigate cybersecurity threats in communications networks.
- Identifies and assesses security risks/exposures, analyzes root causes of security violations, and develops strategies/procedures to prevent future incidents.
- Develops and maintains documentation for processes and procedures to ensure effective and repeatable incident response activities.
- Creates comprehensive incident reports and post-incident briefs that provide in-depth technical details and situational analysis for investigations and decision-makers.
- Collaborates with DoD/Government Leaders and cross-functional teams to develop, maintain, and improve Cybersecurity Defense and Incident Response strategies.
- Monitors and analyzes intrusion detection and defense appliances using security tools like Splunk, Elastic, and related platforms, generating actionable intelligence and trends.
- Researches, evaluates, and tracks emerging threats, vulnerabilities, and advanced threat actor tactics, techniques, and procedures (TTP) to strengthen the network's overall security posture.
- Provides expertise in the analysis of packet captures, software exploits, and obfuscated code to support incident handling/response activities.
- Develops insights based on cybersecurity frameworks such as MITRE ATT&CK and the Cyber Kill Chain for operational improvement.
Requirements
- Network security appliances (Firewalls, IDS/IPS devices)
- Proficient understanding of network security protocols and architectures, such as TCP/IP, DNS, HTTP, ICMP, SSL/TLS, and how they relate to risks like DNS spoofing, DDoS attacks, or Man-in-the-Middle attacks.
- Experience with large-scale data processing hardware for cybersecurity applications, such as threat analytics, anomaly detection, and data correlation.
- Hands-on experience with tools like Snort, Suricata, or proprietary IDS/IPS solutions to monitor, analyze, and mitigate malicious traffic.
- Proficient in tools such as Wireshark and tcpdump for deep analysis of network traffic and identification of anomalies, misconfigurations, or malicious activities.
- Strong communication skills and the ability to engage with varied stakeholders along with presenting incident response briefing
- Experience with MS Officer operating system
- Bachelor’s Degree 8-10 years’ experience or a Master’s with 6-8 years’ experience
- Undergraduate degree
- Equivalent demonstrated experience
- GCIH or any relevant incident response DoD 8140 certification
- Field: Relevant or related discipline
- It is a condition of employment that employees obtain and retain the appropriate level of security clearance and medical clearance applicable to each role. The employee will require a Top-Secret Positive Vetting (TSPV) Department of Defence Security Clearance (Australian) or TS/SCI (U.S.) clearance w/ Poly
- Current Drivers License
- CPR
- White Card
- First Aid
- At least 18 years of age
- Able to fluently read, write, and speak the English language
- This position is designated as a safety sensitive position.
- As part of our commitment to maintaining a safe and compliant work environment, Amentum is a drug-free workplace and requires all personnel to comply with company drug and alcohol policies as a condition of employment. Employment is contingent upon successful completion of the drug screening process. Please note that this may include pre-hire screening for marijuana, as well as other federally controlled substances due to Amentum’s role as a federal contractor and trusted partner to the US Government.
- DHS/CBP suitability clearance
- Equivalent demonstrated experience
Skills
Preferred
- DHS/CBP suitability clearance
- CPR
- White Card
- First Aid