ECS is seeking a Cybersecurity Analyst (CDAP) - Journeyman to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this Task 3 role supporting Cybersecurity Operations Support, the Analytic Developer/Insider Threat Analyst develops, implements, and tunes analytic rules and detection logic to identify anomalous user activity, insider threat indicators, and high-risk behavioral patterns across ARNG enterprise environments. The position correlates data from multiple security and user activity sources, performs alert triage and investigative analysis, documents findings with supporting evidence, and supports case development and reporting in coordination with SOC/CIRT, CTIC, defensive cyber, and security engineering teams to strengthen Defensive Cyberspace Operations – Internal Defensive Measures (DCO-IDM) across the DoDIN-Army-NG area of responsibility. This role directly supports the ARNG mission to deliver and defend DoDIN services for more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories, including Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The analyst contributes to a 24x7x365 cybersecurity operations environment that coordinates with the NETCOM Global Cyber Center and DISA DCDC and leverages ARNG’s Unified Security Information & Event Management (USIEM) analytics ecosystem, integrated SIEM/C2C/DLP analytics, MITRE ATT&CK-based detections, Zeek metadata, Sysmon-informed monitoring, EDR, SOAR, and continuous monitoring processes to improve visibility, detection fidelity, and response across classified and unclassified network environments.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed