{"id":2086217,"url":"https://alion.io/job/saic-senior-cybersecurity-analyst-2","title":"Senior Cybersecurity Analyst","company":{"id":58788,"name":"SAIC","domain":"saic.com","url":"https://alion.io/company/saic","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":80,"open_postings":54,"ghost_share":0,"stale_share":0.981,"repost_share":0,"time_to_fill_p50_days":12,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Washington, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":108000,"max_usd":215000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":974},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DNS","optional":false},{"name":"Linux","optional":false},{"name":"SIEM","optional":false},{"name":"TCP/IP","optional":false},{"name":"Windows","optional":false},{"name":"MITRE ATT&CK","optional":true},{"name":"OWASP","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"SQL","optional":true}],"status":"live","first_seen_at":"2026-09-03T16:42:16Z","employer_posted_date":"2026-09-03","last_verified_at":"2026-10-10T23:24:54Z","board_verified":true,"closed_at":null,"days_open":37,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":37},"description":"SAIC is looking for a Senior Cybersecurity Analyst supports Security Operations functions while helping establish and mature the organization's offensive security capability in support of a critical U.S. Government agency.\nThis position is responsible for advanced incident detection, investigation, response, threat analysis, and security monitoring across on-premises and cloud environments. In addition to traditional SOC responsibilities, the analyst performs authorized offensive security activities, including manual vulnerability validation, reproduction of penetration test findings, remediation verification, and security control validation to identify and validate security weaknesses requiring manual analysis beyond automated vulnerability scanning.\nThe position supports the development of repeatable security validation processes and the agency's evolving offensive security capability, which may expand over time to include application security assessments, adversary emulation, and purple team activities.\nONSITE 3 Days / Remote 2 days - Washington DC\nKey Responsibilities:\nMonitor, analyze, investigate, and respond to cybersecurity alerts and incidents using SIEM, endpoint detection and response (EDR), network monitoring, email security, identity security, and other enterprise security technologies.\nPerform advanced incident triage to determine scope, impact, attack vectors, and recommend appropriate containment, eradication, recovery, and mitigation activities.\nAnalyze network traffic, endpoint telemetry, authentication events, application logs, system logs, and threat intelligence to identify malicious activity and indicators of compromise.\nLead or support investigations involving phishing, malware, unauthorized access, insider threats, data exposure, and other cybersecurity events.\nDevelop, maintain, and improve incident response procedures, investigative workflows, technical documentation, and response playbooks.\nReview, assign, document, and track cybersecurity incidents and operational activities using approved ticketing and documentation systems.\nSupport investigations involving DHS, CISA, US-CERT, vendor advisories, and other cybersecurity notifications affecting agency systems.\nProvide technical leadership, mentorship, and knowledge sharing to junior cybersecurity analysts.\nConduct authorized offensive security activities, including manual vulnerability validation, reproduction of penetration test findings, remediation verification, and security control validation.\nPerform recurring validation testing of known vulnerabilities and security deficiencies to verify exploitability, assess technical impact, and confirm remediation effectiveness.\nPerform manual testing of applications, APIs, identity services, wireless technologies, and other designated systems using approved security assessment tools and methodologies.\nDistinguish confirmed vulnerabilities from false positives, configuration issues, environmental conditions, and non-exploitable findings, and document technical evidence, remediation recommendations, and validation results.\nDevelop repeatable testing procedures, validation methodologies, assessment documentation, and technical guidance to support recurring security validation activities.\nCollaborate with Security Operations, Patch and Vulnerability Management, application teams, infrastructure teams, system owners, and external assessors to improve the agency's overall security posture.\nIdentify opportunities to improve security monitoring, detection logic, logging, defensive controls, and incident response based on manual security assessment results.\nResearch emerging threats, vulnerabilities, and offensive security techniques to support continuous improvement of organizational cybersecurity capabilities.\nSupport the continued development of internal offensive security, application security, adversary emulation, and purple team capabilities while performing all activities within approved authorization, scope, rules of engagement, and operational safeguards.\n Qualifications & Experience:\nBachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Additional relevant experience may be substituted in lieu of a degree.\nFive or more years of experience in cybersecurity operations, Security Operations Center (SOC) activities, incident response, vulnerability management, security engineering, or related cybersecurity disciplines.\nAbility to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. \nDemonstrated experience investigating, analyzing, and responding to cybersecurity incidents.\nStrong understanding of cybersecurity principles, attack methodologies, common threat vectors, and NIST incident response guidance.\nExperience analyzing network traffic, endpoint telemetry, authentication activity, application logs, system logs, and threat indicators.\nExperience with enterprise cybersecurity technologies, including SIEM, EDR, email security, identity security, privileged access management, and threat intelligence platforms.\nWorking knowledge of TCP/IP, DNS, HTTP/HTTPS, authentication protocols, Windows, Linux, cloud environments, enterprise networking, and common application architectures.\nUnderstanding of web applications, APIs, authentication, authorization, session management, and common application security vulnerabilities.\nAbility to learn, adapt to, and effectively utilize agency-approved offensive security methodologies, manual security assessment techniques, and supporting technologies.\nAbility to reproduce technical findings, validate vulnerabilities, document repeatable testing procedures, and communicate technical results.\nStrong analytical, troubleshooting, organizational, technical writing, and communication skills.\nAbility to work independently while collaborating effectively across technical teams, application owners, and government stakeholders.\nPreferred Qualifications:\nExperience conducting manual vulnerability validation, application security testing, remediation verification, or penetration testing activities.\nExperience reproducing and validating findings identified through penetration testing, vulnerability assessments, or independent security assessments.\nFamiliarity with OWASP Top 10, OWASP API Security Top 10, MITRE ATT&CK, and common offensive security methodologies.\nExperience evaluating authentication, authorization, business logic, API security, identity security, wireless security, or other application security controls.\nExperience supporting federal cybersecurity operations, FISMA compliance, or DHS/CISA cybersecurity activities.\nExperience developing scripts or automating security tasks using Python, PowerShell, SQL, or similar technologies.\nRelevant cybersecurity certifications such as CISSP, Security+, CySA+, PenTest+, GPEN, GWAPT, GWEB, PNPT, OSCP, or equivalent.","description_format":"text","description_chars":6897,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Digital Government","Engineering Services"],"lifecycle":[{"event":"open","at":"2026-10-08T12:16:30Z"}],"visa":[],"liveness":{"score":12,"band":"cold","label":"Long shot","p_open":1,"p_active":0.354,"p_room":0.35,"age_days":36,"expected_fill_days":12,"reasons":["conf:2","stale_co","velocity","win:tail","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/saic-senior-cybersecurity-analyst-2","json_url":"https://alion.io/job/saic-senior-cybersecurity-analyst-2.json","meta":{"generated_at":"2026-10-11T01:28:16Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2202,"day_limit":5000,"remaining_today":2798,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":58788},"rest":"https://alion.io/mcp/rest/get_company?id=58788"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fsaic-senior-cybersecurity-analyst-2"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fsaic-senior-cybersecurity-analyst-2"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fsaic-senior-cybersecurity-analyst-2"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/saic-senior-cybersecurity-analyst-2\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fsaic-senior-cybersecurity-analyst-2"}]}