Senior Integrated Assessment / Malware Analyst

Sentar•Fort Bragg, NC
•Onsite

About The Position

Sentar is seeking a Senior Integrated Assessment / Malware Analyst in Ft. Bragg, NC to form the standing assessment cell for Computer Defense Assistance Program missions, share the annual web-assessment portfolio, perform malware and artifact analysis in the isolated lab, own tooling lifecycle and configuration management, and provide first-line planned watch relief. Both positions are configured as broad, senior cross-domain practitioners with mutual backup rather than a primary specialist and a junior alternate.

Requirements

  • Bachelor's degree and 5 years of experience, or AA with 7+ years
  • Army Penetration Testing Course (APTC) completion, or Government-accepted equivalent, required before conducting any production assessment activity
  • DoDM 8140.03 qualification for the DCWF Vulnerability Assessment Analyst work role at Intermediate proficiency (PWS cites 512; current catalog indicates 541; verify at hire) and DCWF 511 Cyber Defense Analyst at Intermediate proficiency (watch relief)
  • DoDM 8140.03 qualification for DCWF 521 Cyber Defense Infrastructure Support Specialist at Intermediate proficiency for tool/lab ownership duties; DCWF 531 Cyber Defense Incident Responder at Intermediate where assigned NDA incident-response duties
  • Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access
  • US Citizenship required
  • Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
  • Ability to obtain and maintain a DoD Common Access Card and USARC installation access
  • Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
  • Demonstrated experience executing authorized network and web application assessments in a DoD environment under formal Rules of Engagement
  • Hands-on proficiency with: ACAS, Nessus, and Nessus Web App
  • Hands-on proficiency with: Metasploit Framework and Cobalt Strike or approved adversary-emulation equivalent
  • Hands-on proficiency with: Burp Suite Pro and OWASP ZAP
  • Hands-on proficiency with: BloodHound, Impacket, Wireshark, and Kali Linux
  • Experience collecting and preserving forensic artifacts and maintaining chain of custody
  • Proficiency with CVSSv3 scoring and with translating technical findings into prioritized, actionable remediation guidance
  • Hands-on static and dynamic malware-analysis skills, including disassembler/debugger use, Windows internals and Win32 API knowledge, assembly-code interpretation, and documentation of malware behavior, indicators, and mitigation recommendations
  • Hands-on experience configuring, patching, troubleshooting, and validating security tools and isolated Windows/Linux lab environments, including STIG/SRG baselines, IAVM remediation, controlled connectivity, and tested rollback procedures
  • Ability to stand watch on an enterprise SIEM when assigned relief
  • Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
  • Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
  • The ability to communicate complex technical findings clearly to non-technical audiences
  • A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
  • A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies
  • APTC or Government-accepted equivalent before any production assessment work
  • DoDM 8140.03 qualified for Vulnerability Assessment Analyst (Intermediate), 511 (Intermediate) for watch relief, and 521 (Intermediate) for tool and lab ownership
  • DoDM 8140.03 qualified for DCWF 531 Cyber Defense Incident Responder at Intermediate where assigned NDA incident-response duties

Nice To Haves

  • Both positions are configured as broad, senior cross-domain practitioners with mutual backup rather than a primary specialist and a junior alternate.

Responsibilities

  • Plan and execute Network Assistance Visits (average one per month) under Government-approved Rules of Engagement: pre-coordination and in-brief; network survey, technical assistance, and organizational repairs; executive summary, out-brief, and final report on encrypted media within 30 calendar days
  • Deploy within four hours of notification for Network Damage Assessments; validate compromise, determine depth of intrusion, gather host logs and forensic artifacts, conduct on-site anomaly-detection scans and incident handling, provide leadership updates every two hours, and deliver the formal NDA report within five business days
  • Manage the engagement lifecycle: signed scope authorization, ROE, kickoff, daily situational reports, written scope-change requests, immediate notification of active adversary or data-spill findings, 24-hour hot wash, and draft report within seven business days
  • Execute annual web assessments of all registered public-facing websites in the AOR (approximately 920 per year) using approved tools (OWASP ZAP, Burp Suite Pro, Nessus Web App); cover at minimum XSS, SQL injection, embedded credentials, and common port vulnerabilities; rule out false positives before delivery; assist site owners with remediation
  • Validate remediation through 30/60/90-day re-tests by severity; provide closure certification to the ISSO for eMASS POA&M entry; escalate failed re-tests within five business days; produce quarterly finding-closure trend reports
  • Perform malware and artifact analysis in the isolated DCO test lab and package findings for incident, CTI, and signature use
  • Serve as primary or backup owner of tooling lifecycle and configuration management: CNF/ERVB tool authorization, Tool Authorization Register, STIG/SRG baselines, ACAS/Tenable scanning and IAVM remediation, upgrade test and rollback, lab isolation and egress control, and the semiannual Technology Refresh Plan
  • Provide planned watch relief on the 24/7/365 rotation to cover training, leave, and surge without consuming Key Personnel capacity
  • Support exercises, hunts, and signature testing as scheduled by the Blue Team Lead

Benefits

  • Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
  • Tuition reimbursement
  • Professional development reimbursement
  • Recognition and Awards programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service