DoW directory
Naval Criminal Investigative Service (NCIS)
View company profile

Cyber Defense Analyst

Location

  • DC

Summary description:

This position is for the NCIS Cyber Operations Field Office (CBFO) and provides advanced cyber investigations and operations to the U.S. Navy with the primary mission to detect, disrupt, and neutralize nefarious cyber activity. Eligible service members must have cyber operations functional experience and other highly desirable skills/experience to include digital network analysis, exploitation, interactive on-net operations, cyberspace operations planning, cyber defense analysis, and cyber threat emulation operations. This opportunity will provide value to cyber related counter-intelligence investigations, operations, and functional services in support of the National Defense Strategy of the United States and Department of Defense.

Job description:

I. INTRODUCTIONWithin the Department of the Navy (DON), the Naval Criminal Investigative Service (NCIS) isthe civilian Federal law enforcement agency uniquely responsible for investigating felony crime,preventing terrorism, and protecting secrets for the Navy and Marine Corps. NCIS defeatsthreats from across the foreign intelligence, terrorist, and criminal spectrum by conducting operations and investigations ashore, afloat, and in cyberspace, to protect and preserve thesuperiority of the DON warfighter. NCIS relies on a highly skilled, diverse, and agile professional workforce to navigate a rapidly evolving threat landscape. Each of our positions—from Special Agents to Intelligence Specialists to human resources and beyond—plays a criticalrole in executing the NCIS Mission.The position is assigned to the Cyber Exploitation Division (Code 20E) in the Cyber Directorate (Code 20) and is responsible for monitoring network activity to identify, report on and help resolve threats posed by foreign cyber actors against DON/NCIS networks infrastructure, personnel and technology with emphasis on law enforcement (LE) and counterintelligence (CI) processes and procedures. This is a career ladder position leading to GS-13 (PD# NA629), the full performance level.II. MAJOR DUTIES AND RESPONSIBILITIESConducts cyber threat hunting to detect, assess, report and help resolve cyber threats (90%)Identifies U.S. government and organizational (DON/NCIS) intelligence requirements to focus collection and analytical activities.Searches for threats and actual/potential intrusions using the full range of cyber threat hunting tools and techniques including Security Information and Event Management (SIEM) tools, Managed Detection and Response (MDR) systems, encryption software, access control/monitoring and penetration testing. Identifies, monitors, and assesses potential threats through network data such as NetFlow, email headers, PCAP analysis, network logs and Transport Layer Security (TLS) Certificate Pivoting. Conducts in-depth investigations of any anomalies and irregularities to find the root cause of an incident and takes swift action including adversary tracking and incident reporting and response.Collects relevant intelligence and network data and conducts cyber analysis to inform the decision-making process.Creates reports that highlight key findings for NCIS, DON, the U.S. Intelligence Community and other ‘friendly’ cyber threat hunters.Recommends and, as authorized, implements effective responses to defeat the threat and reduce vulnerability. Responses typically include cooperative work with other Cybersecurity or Information Security (INFOSEC), plus CI and LE, personnel in NCIS and DON.Writes Intelligence Information Reports (IIRs); perfects one’s skills in content reporting.Prepares documentation to support system operations: Originates documentation reflecting unique system characteristics, as well as security, local policy and operating considerations.Briefs Division officials on key cyber defense issues, including the threat landscape or critical NCIS systemic vulnerabilities and recommended or implemented cybersecurity responses, as assigned.Adheres to Department of Defense (DoD), DON, NCIS, National Institute of Standards and Technology (NIST), Cybersecurity and Infrastructure Security Agency (CISA) and other relevant cybersecurity frameworks and protocols.Other (10%)Keeps abreast of new information technologies applicable to cyber defense of NCIS systems and improves one’s own knowledge and skills in cybersecurity with emphasis on cyber defense. Uses a computer, a wide range of cyber defense tools and techniques to perform cyber defense work as well as administrative work (communicate, word process, record, calculate, prepare presentations, etc.). Performs related duties as assigned.

.

Eligibility factors:

Air Force, Army, Coast Guard, Marine Corps, Navy, Space Force
This position is limited to transitioning services members with a military occupational specialty, rate, or specialty code pertaining to cyber operations and who possess an active TS/SCI clearance and are able to participate at the CBFO in Washington, DC.
Run this SkillBridge program?Claim and verify your company to manage this listing, and to publish your company updates.Claim your company →
Submit & track your application through CareerPCS · Marked active by DoW · last checked October 11, 2026Apply now