Cyber Defense Analyst

BLUE ORIGINDenver, CO
$74,537 - $113,838Onsite

About The Position

At Blue Origin, we envision millions of people living and working in space for the benefit of Earth. We’re working to develop reusable, safe, and low-cost space vehicles and systems within a culture of safety, collaboration, and inclusion. Join our team of problem solvers as we add new chapters to the history of spaceflight! The role is part of the In-Space Systems business unit, which is focused on addressing two of the most compelling challenges in spaceflight today: space infrastructure and increasing mobility on-orbit. Blue National Security (BNS) builds and operates space systems for the Intelligence Community and Department of Defense. Someone has to be watching those systems continuously — and that's this role. We're looking for a Cyber Defense Analyst to monitor, investigate, and respond across BNS classified enclaves, mission ground systems, and labs. You'll work real events on real national security systems, and you'll do it alongside senior engineers who will teach you the environment rather than hand you a queue and walk away. This is a hands-on-keyboard role. You'll spend your days in consoles, terminals, and logging data. You'll also get your hands on the tooling itself, helping deploy sensors, onboard log sources, and tune detections under the direction of our senior engineers. That's how you'll learn this environment, and it's the fastest path to becoming the engineer who designs the next one. If you're coming off a military cyber protection team, a government SOC, or a service watch floor and you want to keep growing technically rather than get slotted into a ticket queue, this is a strong landing spot.

Requirements

  • Entry level hands-on experience in security operations, incident response, IT operations, or system administration or equivalent military/government cyber experience
  • Working knowledge of network protocols and Windows and Linux fundamentals
  • Familiarity with SIEM and EDR concepts and the ability to investigate events using them
  • Understanding of common attack techniques and exposure to the MITRE ATT&CK framework
  • Clear, concise written communication — your investigation notes will be read by senior staff and government customers
  • Genuine curiosity and the instinct to keep pulling on a thread when something doesn't add up
  • Active U.S. Government Top Secret clearance with SCI eligibility and eligibility for SAP access determination
  • DoD 8140 CSSP Analyst or IAT Level II certification (Security+ CE or equivalent) at hire or within [6] months
  • A degree is not required. Equivalent military, government, or hands-on technical experience is fully accepted.

Nice To Haves

  • Prior military cyber experience (17C, 1B4, CTN, 1721, or equivalent) or CPT/CST assignment
  • Any scripting exposure — Python, PowerShell, or Bash
  • Query language familiarity — KQL, SPL, or similar
  • Prior work in classified DoD or IC environments
  • Exposure to forensics, malware triage, or detection rule development
  • Security+, CySA+, GSEC, GCIH, or similar
  • Active TS/SCI with polygraph

Responsibilities

  • Monitor and triage security events and alerts across SIEM, EDR, network sensors, and audit logs. Determine what's noise, what's misconfiguration, and what warrants escalation.
  • Investigate by pivoting across host, network, and identity data to build a picture of what actually happened, and document it clearly.
  • Serve as first responder during incidents. Execute containment steps per playbook, preserve evidence, build timelines, and support senior engineers leading the response.
  • Participate in structured hunts, initially alongside senior team members and increasingly on your own hypotheses as you learn what "normal" looks like here.
  • Support audit and insider threat review by performing privileged user activity monitoring and audit log review in partnership with Security and Counterintelligence.
  • Stand watch during mission events, providing heightened monitoring coverage during launches, mission operations, and other critical windows.
  • Assist with sensor deployment, log source onboarding, and agent rollout across enclaves under engineering direction.
  • Tune and improve detections by reducing false positives, validating rule coverage, and proposing new detections based on findings in the data.
  • Improve the playbooks by executing response procedures and flagging gaps, driving rewrites.
  • Automate recurring triage, enrichment, and reporting tasks.

Benefits

  • Medical
  • dental
  • vision
  • basic and supplemental life insurance
  • paid parental leave
  • short and long-term disability
  • 401(k) with a company match of up to 5%
  • Education Support Program
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours
  • up to 14 company-paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service