1

Cyber Network Defense Analyst Jobs (NOW HIRING)

Leidos is seeking a Cyber Network Defense Analyst (CNDA) to join our team on a highly visible cyber security single-award IDIQ vehicle that provides Network Operations Security Center (NOSC) support ...

Cyber Network Defense Analyst

Washington, DC · On-site

$69.55K - $125.73K/yr

Leidos is seeking a Cyber Network Defense Analyst (CNDA) to join our team on a highly visible cyber security single-award IDIQ vehicle that provides Network Operations Security Center (NOSC) support ...

Cyber Network Defense Analyst

Washington, DC · On-site

$69.55K - $125.73K/yr

Leidos is seeking a Cyber Network Defense Analyst (CNDA) to join our team on a highly visible cyber security single-award IDIQ vehicle that provides Network Operations Security Center (NOSC) support ...

next page

Showing results 1-20

Cyber Network Defense Analyst information

See salary details

$34K

$112.9K

$176K

How much do cyber network defense analyst jobs pay per year?

As of May 30, 2026, the average yearly pay for cyber network defense analyst in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Network Defense Analyst, and why are they important?

To thrive as a Cyber Network Defense Analyst, you need a strong foundation in computer networking, cybersecurity principles, and incident response, often supported by a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and certifications like CompTIA Security+ or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are essential soft skills for identifying threats and conveying risk to stakeholders. These skills and qualifications are crucial for effectively protecting organizational assets and responding to evolving cyber threats.

What are some common challenges faced by Cyber Network Defense Analysts in their daily work?

Cyber Network Defense Analysts often face the challenge of keeping up with constantly evolving cyber threats and attack techniques. They must quickly analyze large volumes of network traffic and security logs to identify potential intrusions while minimizing false positives. Collaboration with other IT and security teams is crucial, particularly when responding to incidents or implementing new security measures. Staying current with the latest security tools and threat intelligence is essential for effective defense and career growth in this field.

What is a Cyber Network Defense Analyst?

A Cyber Network Defense Analyst is a cybersecurity professional responsible for monitoring, analyzing, and responding to security threats on computer networks. Their main duties include detecting and investigating suspicious activities, mitigating cyber attacks, and implementing strategies to protect sensitive data and systems. They often use tools like intrusion detection systems, firewalls, and security information and event management (SIEM) platforms to identify vulnerabilities and ensure the organization's networks remain secure. This role is critical in preventing data breaches and maintaining the integrity of an organization’s digital infrastructure.

What is the difference between Cyber Network Defense Analyst vs Cyber Security Analyst?

AspectCyber Network Defense AnalystCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentFocus on network security, intrusion detection, and threat mitigationBroader security responsibilities including policies, risk assessment, and compliance
Employer & Industry UsagePrimarily in cybersecurity firms, government agencies, and large corporationsWidespread across various industries including finance, healthcare, and tech

The Cyber Network Defense Analyst specializes in protecting network infrastructure from cyber threats, focusing on intrusion detection and response. In contrast, the Cyber Security Analyst has a broader role that includes policy development, risk management, and overall security strategy. Both roles require similar certifications and often work in similar environments, but their core responsibilities differ in scope and focus.

More about Cyber Network Defense Analyst jobs
Infographic showing various Cyber Network Defense Analyst job openings in the United States as of May 2026, with employment types broken down into 2% Internship, 83% Full Time, 2% Part Time, and 13% Contract. Highlights an 94% Physical, and 6% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.
Cyber Network Defense Analyst (CNDA) III - Cloud Forensics

Cyber Network Defense Analyst (CNDA) III - Cloud Forensics

Argo Cyber Systems

Arlington, VA • On-site

$95K - $135K/yr

Full-time

Posted 8 days ago


Job description

Cyber Network Defense Analyst (CNDA) - Cloud Forensics
Location: Remote / Onsite (as required)
Clearance: Active TS/SCI (DHS EOD eligibility required)
Company: Argo Cyber Systems, LLC - A Service-Disabled Veteran-Owned Small Business (SDVOSB)
About Argo Cyber Systems
Argo Cyber Systems delivers advanced cybersecurity and threat-hunting capabilities to safeguard federal and critical infrastructure environments. Our teams provide rapid incident response, digital forensics, proactive hunt operations, and continuous cyber defense across host-based, network-based, and cloud-based systems. We combine mission experience with innovation-empowering our customers to detect, disrupt, and defeat adversaries in real time.
Position Overview
Argo Cyber Systems is seeking Cyber Network Defense Analysts (CNDA) with deep Cloud Forensics expertise to support a high-visibility federal mission. The CNDA will lead advanced investigations into sophisticated intrusions across hybrid and multi-cloud environments, identifying attacker tactics, techniques, and procedures (TTPs), correlating artifacts, and driving containment and remediation actions in partnership with government cyber teams.
Key Responsibilities
  • Conduct end-to-end forensic acquisition and analysis across on-premises, cloud, and hybrid environments (Azure AD/Entra ID, M365, AWS, GCP, SaaS).
  • Investigate identity-based and credential-abuse incidents targeting cloud control planes and hybrid identity infrastructure.
  • Correlate cloud telemetry (Azure Activity Logs, AWS CloudTrail, GCP Logs, VPC Flow Logs) and network evidence to reconstruct attacker timelines and validate indicators of compromise (IOCs).
  • Develop and deploy automated detection logic, threat-hunting scripts, and analytical playbooks using Microsoft Sentinel, Defender, AWS GuardDuty, and GCP Chronicle.
  • Produce comprehensive technical and executive-level reports, integrating findings across endpoints, networks, and cloud assets to inform threat containment and strategic recommendations.
  • Support continuous improvement of incident response procedures, forensics workflows, and threat-hunting operations.
  • Collaborate with Argo and government stakeholders to triage alerts, assess risk, and strengthen enterprise detection and response posture.
Required Qualifications
  • U.S. Citizenship and active TS/SCI clearance (with ability to obtain DHS EOD Suitability).
  • Minimum 8 years of hands-on experience conducting digital forensics and incident response (DFIR).
  • Proven expertise in cloud forensics, identity security, and hybrid infrastructure defense.
  • Proficiency in M365/Azure AD, AWS IAM, and SaaS investigative methodologies.
  • Deep understanding of SaaS/PaaS/IaaS architectures, including common attack vectors and defensive measures.
  • Skilled in evidence acquisition, volatile data capture, artifact analysis, and technical reporting.
Desired Qualifications
  • Scripting and automation proficiency in PowerShell, Python, Bash, or JavaScript.
  • Familiarity with Terraform, Kubernetes, Docker, CloudFormation, or Azure Resource Manager for automation and orchestration.
  • Understanding of MITRE ATT&CK for Cloud and adversary emulation techniques.
  • Strong communication and collaboration skills for working across multidisciplinary teams.
Education
  • Bachelor's Degree in Computer Science, Cybersecurity, Computer Engineering, or a related field
    or
  • High School Diploma and 10+ years of directly relevant DFIR experience.
Preferred Certifications
  • GIAC Cloud Defender (GCLD), GCFR, GCFA, GCFE, GCIH, EnCE, CCE, CFCE, CISSP, CCSP
  • AWS and Microsoft security/cloud certifications (e.g., Azure Security Engineer, AWS Security Specialty)
Why Argo Cyber Systems
At Argo, you'll be part of a mission-driven, veteran-founded cybersecurity team protecting America's most critical systems. We combine hands-on technical excellence with operational precision to outpace the threat. Join us to defend, detect, and innovate at the cyber edge.