Copper River Cyber Solutions is seeking a highly motivated Threat Detection & Response Analyst to support the NIH cybersecurity program by monitoring enterprise systems for malicious activity, investigating security events, and responding to cybersecurity incidents. The Analyst leverages security monitoring tools, threat intelligence, and incident response procedures to identify and mitigate threats impacting NIH information systems, networks, cloud environments, and applications.
This position works closely with Incident Response personnel, Vulnerability Management Analysts, Security Engineers, RMF teams, and system owners to strengthen cybersecurity defenses and protect mission-critical systems and sensitive research data. The role contributes to continuous monitoring, threat hunting, incident investigation, and security operations activities.
Responsibilities (include but are not limited to):
- Conduct proactive threat hunting activities using intelligence-driven and hypothesis-based methodologies.
- Analyze threat actor tactics, techniques, and procedures (TTPs) to identify potential compromise within NIH environments.
- Map observed adversary behaviors, indicators, and attack patterns to the MITRE ATT&CK framework to support detection engineering, threat hunting, and risk analysis.
- Provide threat findings, indicators, and investigations supporting RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
- Monitor security tools, dashboards, and alerts to identify potential cybersecurity threats and suspicious activity.
- Analyze events from endpoint, network, cloud, and security monitoring platforms.
- Perform triage of security alerts to determine validity, severity, and potential impact.
- Identify indicators of compromise (IOCs), attack patterns, and emerging threats.
- Escalate significant security events in accordance with established procedures.
- Investigate cybersecurity incidents, security events, and anomalous activity.
- Conduct forensic review of logs, alerts, and system data to determine root cause and scope.
- Correlate information from multiple security tools and data sources.
- Document findings, recommendations, and lessons learned from investigations.
- Support post-incident reviews and corrective action planning.
- Provide threat and incident-related information supporting risk assessments and POA&M management activities.
- Assist with audit readiness and security assessment activities when requested.
Essential Job Qualifications and Requirements:
Education:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
Required Qualifications:
- Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or Security Operations Center (SOC) environments.
- Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
- Experience investigating cybersecurity incidents and analyzing security events.
- Knowledge of:
- Cyber threat tactics, techniques, and procedures (TTPs)
- Security Operations Center (SOC) processes
- Incident Response methodologies
- Network security concepts
- Endpoint security technologies
- Familiarity with:
- NIST RMF (SP 800-37)
- NIST SP 800-53 Rev. 5
- FISMA
- Federal cybersecurity requirements
- Strong analytical, troubleshooting, and communication skills.
- Ability to obtain and maintain an NIH Public Trust.
Preferred Qualifications:
- One or more of the following certifications:
- Security+
- CySA+
- GCIH (GIAC Certified Incident Handler)
- GCIA (GIAC Certified Intrusion Analyst)
- CISSP
- CEH (Certified Ethical Hacker)
- GSEC
- CASP+
- CISM
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience working in a Security Operations Center (SOC) environment.
- Knowledge of MITRE ATT&CK Framework methodologies.
- Experience supporting cloud security operations within Azure, AWS, or Google Cloud environments.
- Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
- Experience protecting healthcare, biomedical, or research-focused environments.
About Copper River & The Native Village of Eyak:
Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration’s (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE’s ability to facilitate economic advancement.
The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.
Copper River’s Culture
The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.
Benefits
- Comprehensive medical, dental, and vision coverage
- Flexible Spending Account - healthcare and dependent care
- Health Savings Account - high deductible medical plan
- Retirement 401(k) with employer match
- Open leave policy and paid holidays
- Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more!
Note: Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.
Disclaimer:
The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.