About The Position

SarelaTech is seeking an experienced Cybersecurity Incident Response & Threat Detection Analyst to support a Department of War (DoW) cybersecurity mission in Columbus, Ohio. This position will participate in 24x7x365 monitoring of Security Information and Event Management (SIEM) and other cybersecurity monitoring tools to detect and respond to cybersecurity threats within the enterprise network environment. The Cybersecurity Incident Response & Threat Detection Analyst will perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity and employ cybersecurity capabilities and deliberate actions in response to specific alerts and emerging threats. The position will review logged events for trends indicative of attack or compromise and actively monitor logs and network traffic for Advanced Persistent Threats (APT) and “low and slow” attacks. The analyst will maintain awareness of potential threats through intelligence resources, including Open Source Intelligence (OSINT). The position will also provide technical analysis and sustainment support for enterprise cybersecurity tools and applications and assist with the application of Defense-in-Depth signatures and perimeter defense controls to reduce network threats.

Requirements

  • Five (5) years of relevant experience.
  • Two (2) years of experience performing root cause analysis of cybersecurity events and incidents.
  • Working knowledge of at least two (2) of the following security tool areas: Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), Host-based antivirus, Data Loss Prevention (DLP), Vulnerability Management, Digital Forensics, Malware Analysis, Device Hardening.
  • Understanding of Defense-in-Depth.
  • Ability to build scripts and tools to enhance threat detection and incident response capabilities, preferably using SPL, Python, or PowerShell.
  • Must possess: CompTIA Security+.
  • Must possess at least one current certification meeting DoD 8570/8140 Cybersecurity Service Provider Incident Responder (CSSP-IR) requirements (e.g., CEH, CFR, Cisco Certified CyberOps Associate, CHFI, CySA+, PenTest+, GCFA, GCIH, SSCP).
  • Active DoD TS/SCI clearance.

Responsibilities

  • Participate in 24x7x365 monitoring of SIEM and other cybersecurity monitoring tools.
  • Detect and respond to cybersecurity threats within the enterprise network environment.
  • Perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity.
  • Employ cybersecurity capabilities and deliberate actions in response to specific alerts and emerging threats.
  • Review logged events for trends indicative of attack or compromise.
  • Actively monitor logs and network traffic for Advanced Persistent Threats (APT) and “low and slow” attacks.
  • Maintain awareness of potential threats through intelligence resources, including Open Source Intelligence (OSINT).
  • Provide technical analysis and sustainment support for enterprise cybersecurity tools and applications.
  • Assist with the application of Defense-in-Depth signatures and perimeter defense controls to reduce network threats.

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Profit sharing
  • Training & development
  • Tuition assistance
  • Vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service