Cyber Triage Analyst Level III

Argo Cyber Systems•Arlington, VA
•$95,000 - $125,000

About The Position

Argo Cyber Systems is seeking an experienced JCDC Cyber Triage Analyst to serve as a frontline cyber defender supporting the Joint Cyber Defense Collaborative (JCDC). The Cyber Triage Analyst performs initial analysis and triage of cyber threat reports, indicators of compromise (IOCs), incident notifications, and other cybersecurity information submitted to the JCDC. This is not an entry-level or developmental analyst position. The successful candidate will operate in a role comparable to a Tier 1/Tier 2 SOC Analyst with enhanced Cyber Threat Intelligence (CTI) responsibilities. Analysts are expected to independently research cyber activity, rapidly evaluate technical information, develop defensible analytical conclusions, identify intelligence and information gaps, and recommend appropriate follow-on actions. This position requires strong technical analysis skills combined with the ability to communicate and coordinate effectively with government organizations, private-sector partners, critical infrastructure stakeholders, and other cybersecurity professionals.

Requirements

  • U.S. Citizenship.
  • Active TS/SCI security clearance.
  • Ability to obtain and maintain DHS Suitability.
  • 2–4+ years of progressive cybersecurity experience supporting one or more of the following: Security Operations Center (SOC) operations, Cyber Threat Intelligence (CTI), Cyber incident response, Network security monitoring, Threat hunting, Cybersecurity operations
  • Demonstrated ability to independently triage and analyze cybersecurity incidents, alerts, threat reports, or intelligence.
  • Experience analyzing technical indicators such as IP addresses, domains, URLs, file hashes, network traffic, and malware-related artifacts.
  • Experience researching and enriching IOCs using threat intelligence and OSINT resources.
  • Ability to assess the severity, credibility, and potential impact of cyber threats.
  • Ability to document analytical findings and develop concise, actionable recommendations.
  • Strong technical research and analytical reasoning skills.
  • Strong written and verbal communication skills.
  • Ability to work effectively with government personnel, technical analysts, incident responders, intelligence professionals, and partner organizations.
  • Ability to work collaboratively across geographically distributed teams and physical locations.

Nice To Haves

  • Previous cybersecurity experience supporting CISA, FBI, NSA, DoD, DHS, or another federal cybersecurity or intelligence organization.
  • Understanding of the National Cyber Incident Scoring System (NCISS) and its application to incident prioritization and triage.
  • Knowledge of common cyberattack lifecycle stages, including: Reconnaissance and footprinting, Scanning and enumeration, Initial access, Privilege escalation, Persistence, Network exploitation and lateral movement, Command and control, Defense evasion and covering tracks
  • Demonstrated ability to recognize and categorize cybersecurity vulnerabilities and associated attack techniques.
  • Knowledge of Computer Network Defense (CND) policies, procedures, processes, and regulations.
  • Understanding of different operational threat environments, ranging from opportunistic attackers and cybercriminal organizations to sophisticated nation-state actors.
  • Knowledge of system and application security threats and vulnerabilities, including: Buffer overflows, Cross-site scripting (XSS), SQL/PL-SQL and other injection attacks, Malicious or mobile code, Race conditions, Covert channels, Replay attacks, Return-oriented programming/attacks, Other common application and network exploitation techniques
  • Experience working with SIEM platforms, Threat Intelligence Platforms (TIPs), case management systems, and cybersecurity ticketing platforms.
  • Familiarity with cyber threat intelligence concepts, adversary TTPs, and IOC lifecycle management.
  • Knowledge of U.S. critical infrastructure sectors and associated cyber risks.
  • Familiarity with DHS/CISA cybersecurity products, services, alerts, advisories, and operational processes.
  • Experience working in an operational SOC, watch floor, incident response center, or cyber fusion environment.
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Other comparable cybersecurity, incident response, SOC, or threat intelligence certifications

Responsibilities

  • Perform initial triage and assessment of incoming cyber threat tickets, incident reports, IOC submissions, and cybersecurity notifications.
  • Analyze technical indicators and artifacts including IP addresses, domain names, URLs, file hashes, network traffic patterns, malware artifacts, and related telemetry.
  • Assess the credibility, severity, scope, and potential operational impact of reported cyber activity.
  • Evaluate potential impacts to federal networks and U.S. critical infrastructure sectors.
  • Enrich IOCs using Threat Intelligence Platforms (TIPs), OSINT resources, commercial intelligence sources, and authorized government-exclusive resources.
  • Correlate indicators with known threat actors, campaigns, malware families, vulnerabilities, tactics, techniques, and procedures (TTPs).
  • Develop concise, defensible cyber triage reports containing analytical findings and actionable recommendations.
  • Determine when incidents or threat activity require escalation or additional technical analysis.
  • Route tickets and analytical findings to appropriate JCDC teams, CISA organizations, or interagency partners.
  • Coordinate with sector-specific analysts, incident responders, threat hunters, intelligence analysts, and interagency liaisons to obtain additional technical and operational context.
  • Maintain complete and accurate documentation within ticketing, case management, and knowledge management systems.
  • Participate in operational shift handoffs and daily cybersecurity briefings.
  • Monitor emerging cyber threat campaigns, adversary activity, vulnerabilities, and trends.
  • Support development and continuous improvement of cyber triage playbooks, workflows, and Standard Operating Procedures (SOPs).
  • Provide appropriate feedback to submitters and partner organizations regarding ticket status, findings, and disposition.
  • Support collaboration across geographically distributed government and contractor teams.

Benefits

  • Opportunities for experienced cybersecurity professionals to work directly on mission-focused programs protecting federal agencies and critical infrastructure from sophisticated cyber threats.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service