Host Based Systems Analyst III
@ ARSIEMHost Based Systems Analyst III
This job is still taking applications, but it's been up a while.
About the job
ARSIEM supports US government clients with innovative security solutions. The role focuses on cloud forensics, incident analysis, and automating detection to enhance cybersecurity.
Requirements
- 5+ years of cyber forensic investigations
- Experience with cloud environments
- Knowledge of SaaS, PaaS, IaaS
- Strong scripting skills
- Understanding of hybrid identity security
Qualifications
- BS in Computer Science or related
- Active TS/SCI clearance
- Experience with cloud attack mitigation
- Relevant security certifications
Full job description
Responsibilities
- Conduct forensic acquisition and analysis from on-premises and cloud platforms (Entra ID/Azure AD, M365, AWS, GCP, SaaS) to identify compromise activity, persistence mechanisms, and data exfiltration.
- Investigate and respond to incidents and attacks targeting cloud and hybrid identity.
- Correlate cloud control-plane events and network telemetry (e.g., Azure Activity Logs, AWS CloudTrail, VPC Flow Logs) to reconstruct attacker timelines, validate IOCs, and identify post-compromise privilege escalation.
- Develop and operationalize detection logic and automation using cloud-native tools (Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle) and scripting (PowerShell, Python, Bash), integrating threat intelligence feeds and indicators.
- Produce technical reports, incident documentation, and containment recommendations integrating cloud, identity, and endpoint findings; support development of incident response playbooks and procedures for cloud and hybrid environments.
- Support cloud development and automation projects to enhance threat emulation, investigative, and hunting capabilities.
- Coordinate with internal teams, government staff, and external stakeholders to validate alerts and investigate preliminary findings.
Minimum Qualifications
- BS in Computer Science, Cybersecurity, Computer Engineering, or related field; OR HS Diploma with 7+ years relevant experience.
- 5+ years of experience in cyber forensic investigations with leading tools and techniques.
- Strong understanding of SaaS, PaaS, and IaaS in cloud environments and hybrid identity security.
- Expertise in acquiring forensically sound evidence, analyzing attacks, and reporting findings.
- Knowledge of M365/Azure, hybrid identity, and threats targeting these solutions.
- Knowledge of AWS, IAM, and best practices for cloud identity security.
Preferred Qualifications
- Strong API and scripting skills (PowerShell, Python, Bash, JavaScript) for automation and threat detection.
- Knowledge of common and advanced cloud attacks and techniques, and how to detect and mitigate these threats.
- Proficiency with cloud automation and orchestration tools (Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker).
- GCLD, GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP, AWS, or Microsoft Cloud/Security certifications.
Similar jobs
- 5
Commercial Referral Partner (Independent, Commission-Based)
5 · Columbus, OH
Posted 2 months ago - J
HVAC Truck Based Journeymen Mechanic (union)
Johnson Controls · United States Of America, Ohio, Dublin
Posted 1 day ago - A
Senior IT Systems Engineer
Anduril Industries · Ashville, Ohio, United States
Posted 1 month ago - F
Senior Manager, Quality Systems
Forge Biologics · Columbus, Ohio, United States
Posted 1 month ago - A
Portfolio Operations, Intelligence Systems
Anduril Industries · Ashville, Ohio, United States
Posted 4 weeks ago - A
Production Coordinator, Intelligence Systems
Anduril Industries · Ashville, Ohio, United States
Posted 1 month ago