Job Description
Position Summary
ECS is seeking a Cybersecurity Analyst (CDAP) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This position supports Task 3 — Cybersecurity Operations Support, contributing to a comprehensive and proactive cybersecurity program that defends ARNG classified and unclassified network environments and enables Defensive Cyberspace Operations – Internal Defensive Measures (DCO-IDM) across the DoDIN-Army-NG area of responsibility. The Cybersecurity Analyst (CDAP) performs monitoring and analysis of security telemetry within CDAP, conducts alert triage and log analysis, documents findings, supports remediation tracking, and assists with dashboard updates and detection tuning in coordination with SOC and defensive cyber personnel.
In this role, the analyst helps protect mission-critical enterprise services supporting more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories. The position operates within the ARNG cyber mission supporting Title 10 and Title 32 operations, mobilization readiness, domestic emergency response, and both classified SIPRNet and unclassified environments. The role aligns with ENOCS cybersecurity operations that leverage integrated SIEM/C2C/DLP analytics, USIEM data sources, MITRE ATT&CK-based analytics, and coordination with the NETCOM Global Cyber Center and DISA DCDC to strengthen continuous monitoring, threat detection, and ARNG cybersecurity policy compliance.
Please Note: This position is contingent upon contract award.
Responsibilities
- Monitor and analyze CDAP security telemetry to identify potential threats, anomalous activity, and security misconfigurations affecting ARNG classified and unclassified network environments.
- Perform alert triage, log review, and basic correlation using established analytic rules to support Task 3 cybersecurity operations and continuous monitoring objectives.
- Document investigative findings, maintain clear records of observed conditions, and support remediation tracking in coordination with SOC and defensive cyber personnel.
- Assist with dashboard updates to improve visibility into cyber conditions, incident trends, and operational status across the DoDIN-Army-NG area of responsibility.
- Support detection tuning under senior oversight to improve the quality and relevance of cyber alerts and monitoring outputs within CDAP.
- Contribute to monitoring activities that align with integrated SIEM/C2C/DLP analytics and USIEM-enabled visibility used to centralize threat detection and response.
- Apply established analytic approaches that support MITRE ATT&CK-based detection and analysis methods used across ENOCS cybersecurity operations.
- Coordinate with cybersecurity operations stakeholders supporting 24x7x365 monitoring, incident escalation, and defensive actions in concert with broader SOC processes.
- Support cybersecurity activities performed in coordination with the NETCOM Global Cyber Center and DISA DCDC to help maintain ARNG cyber freedom of action and policy compliance.
