Back to search
General Atomics Linkedin · Posted 4d ago

Cyber Incident/Forensic Analyst

San Diego, California, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Job Summary

General Atomics (GA), and its affiliated companies, is one of the world’s leading resources for high-technology systems development ranging from the nuclear fuel cycle to remotely piloted aircraft, airborne sensors, and advanced electric, electronic, wireless and laser technologies.

DUTIES AND RESPONSIBILITIES:

Primary Focus

Incident response, risk analysis, and advanced troubleshooting. Responsible for the day-to-day management and monitoring of security systems after implementation by the Cybersecurity teams. Performs network observability, threat detection, security metrics reporting, and automation-driven operational workflows to maintain continuous visibility into the organization’s security posture and enable rapid identification and response to security events. Escalates complex changes or advanced troubleshooting to engineers. This role is part of the Cybersecurity Defense Operations career track, focusing on security monitoring, enforcement, and operational risk reduction.

Security Policy Enforcement & Engineering

Implement and integrate enterprise security technologies, ensuring security policies are effectively enforced across hybrid environments. Analyze policy effectiveness, recommend policy adjustments. Ensures that security policies remain enforced across security systems and services as part of operational security responsibilities. Work closely with engineers for major updates and reconfigurations. Leverage networks observability data and security telemetry to support threat detection, validate policy effectiveness, and produce actionable metrics for reporting for operational and executive visibility. Automation workflows should be applied to policy enforcement and validation processes where applicable.

Technical Consulting & Business Support

Advise internal teams on security control best practices, aligning security solutions with business needs. Provide data-driven consulting, supported by metrics and threat intel to improve decision making. This role will provide on-site support for cybersecurity, infrastructure, and business solutions.

Cybersecurity Asset & Patch Management

Monitor patch compliance, troubleshoot patch-related security issues. Incorporates security telemetry and network observability to identify patch-related risk exposure, enhance threat coverage, and support metrics reporting on compliance posture.

Complex Security Solution Development

Develop scripts and automation to streamline security solution deployments, focusing on segmentation and VPN automation. Expand workflow observability and metrics reporting pipelines to measure solution deployment effectiveness and security impact.

Security System Implementation & Optimization

Optimize security tools for better efficiency and integration. Maintain and manage deployed security systems such as firewalls, VPNs, and segmentation controls, ensuring continued security enforcement and policy compliance. Optimize enterprise security enforcement technologies, ensuring efficiency and seamless integration. Support the design and implementation of security enforcement technologies. Integrates network observability frameworks and threat detection capabilities into deployed systems and provide performance, risk, and compliance visibility. Automation workflow should be used to enhance monitoring, tuning, and operational response processes.

Collaboration with Cybersecurity Teams

Support operational security teams by ensuring all security technologies are correctly integrated and aligned with enforcement policies. Create and advance automation workflows that improve operational efficiency and incident response effectiveness. Mentor other analysts and engineers. Contribute to process improvements.

Career Progression

This track leads to advanced roles in security operations, incident response, and strategic cybersecurity defense leadership.

We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.

Job Qualifications

  • Typically requires a bachelors degree in a related discipline and two or more years of progressive professional experience in cyber security or a related field. Equivalent professional experience may be substituted in lieu of education.
  • 3–5 years of hands-on cybersecurity experience preferred.
  • Some understanding of security practices and threat landscapes.
  • Quickly adopts new tools and contributes to process improvement.
  • Effective communicator with end users and technical teams.
  • Capable of resolving moderately complex technical issues.
  • Works well independently and collaboratively.
  • Desired: GSEC, CEH, CySA+, or equivalent intermediate certification.
  • Desired: Experience in Next-Generation Firewall (NGFW) technologies
  • Desired: Experienced in some of the following: Python, Powershell, Java, Bash, KQL/SQL
  • Relevant: AWS Solutions Architect – Associate, Microsoft Azure Administrator, CompTIA Cloud+, Cisco CCNA, Palo Alto, M365 Security.
  • Effective communicator, collaborative team player, and adaptable under pressure.
  • Ability to obtain and maintain a DoD Secret clearance.

This position may transition to fully on-site as the business demand/requirements change.

Job Type: Full-Time Salary

Salary range: 73,700 - 128,780

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search