Investigator - Huntsville, AL

 Posted 2 hours ago
     
 $120K - $180K per year
  
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Conduct all-source investigations using breach data and OSINT to attribute threat actors and map adversary infrastructure for government customers. Integrate AI tooling into analytical workflows and deliver product training and capability demonstrations to cleared personnel.

SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud’s solutions thwart cyberattacks and protect more than 4 billion accounts worldwide. Cybersecurity is an exciting, evolving space, and being at the forefront of the fight to disrupt cybercrime makes SpyCloud a special place to work. If you’re driven to align your career with a fantastic mission, look no further!

SpyCloud collects recaptured breach data, malware-exfiltrated credentials, session cookies, and commercially available information at scale. The Investigations team turns that data into investigative reports and analytical products -- attribution packages, infrastructure assessments, identity exposure reports, and analytical support for government and enterprise customers.

This is a customer-facing role supporting government and IC-aligned customers across a range of national security mission areas. The analyst will conduct original investigations, respond to requests for information, deliver training and capability demonstrations to cleared personnel, and develop AI-assisted analytical workflows using SpyCloud's platform and tooling.

 

What You'll Do:

  • Investigations
    • Conduct all-source investigations using breach data, malware-exfiltrated logs, OSINT, and commercially available information to attribute threat actors, map adversary infrastructure, and assess identity and credential exposure.
    • Respond to requests for information from government and program stakeholders, producing analytical reports and investigation packages on short timelines.
    • Analyze infostealer log files to extract credential exposure, behavioral indicators, and infrastructure intelligence relevant to ongoing analytical requirements.
    • Pivot across SpyCloud data using the Investigations Portal, API, and Python-based notebooks to develop leads and close attribution gaps.
  • AI-Assisted Analysis
    • Integrate large language models and AI tooling into investigative workflows -- building prompts, synthesizing multi-source data, and validating outputs against primary evidence.
    • Develop and document reusable analytical workflows, prompt libraries, and notebook-based processes that improve team throughput and consistency.
    • Stay current on emerging AI capabilities relevant to OSINT, CAI analysis, and analytical production.
  • Training and Customer Support
    • Deliver product training and live capability demonstrations to cleared government personnel, tailoring content to the analytical mission and maturity of each audience.
    • Build scenario-based training materials and leave-behind products drawn from real investigation findings.
    • Support onboarding of new customers and users, helping them connect SpyCloud capabilities to their specific analytical requirements.
  • Reporting and Coordination
    • Track RFI fulfillment, investigative outcomes, and analyst credit usage, reporting results to SpyCloud leadership.
    • Represent SpyCloud at relevant community events, conferences, and working groups as needed.

 

Requirements:

  • Education
    • Bachelor's degree in intelligence studies, computer science, cybersecurity, international relations, criminal justice, or a related field -- or five or more years of equivalent professional experience in lieu of a degree.
  • Clearance
    • Active TS/SCI required.
    • Preferred background: Department of Defense, Defense Intelligence Agency, Central Intelligence Agency, or affiliate of the Intelligence Community.
  • Experience
    • Five or more years in an all-source, OSINT, or CAI analytical role within a government, defense, or IC-aligned environment.
    • Demonstrated experience supporting RFI pipelines and delivering analytical reports to operational or program stakeholders.
    • Prior experience delivering training or capability demonstrations to cleared analytical audiences.
    • Familiarity with adversary TTPs across one or more threat areas: cyber operations, foreign procurement, critical infrastructure, influence operations, or illicit finance.
  • Technical Skills
    • Proficient in OSINT collection and CAI analysis: domain research, identity resolution, infrastructure mapping, and entity attribution.
    • Practical experience incorporating AI and large language models into analytical work, including prompt development and output validation.
    • Comfortable working with REST APIs and scripted data queries; Python preferred.
    • Familiarity with commercial investigative platforms and ability to adapt them to new data sources and mission requirements.
    • Familiarity with adversary analysis frameworks -- including MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model -- as contextual tools for structuring and communicating investigation findings.
    • Working knowledge of structured analytic techniques (SATs) for evaluating evidence, surfacing assumptions, and reducing analytical bias.
  • Communication
    • Writes clear, well-structured analytical reports: BLUF-first, properly sourced, readable by both analysts and senior leaders.
    • Confident briefing cleared program managers, unit leadership, or senior officials on investigation findings.
    • Organized and self-directed; able to manage concurrent workstreams without close supervision.
  • Travel
    • Up to 25% travel required to support customer sites, training engagements, and community events.

 

Nice to Have:

  • Foreign language proficiency in Russian, Mandarin, Farsi, Korean, or Spanish.
  • Experience with cryptocurrency tracing or illicit finance analysis.
  • Prior speaking engagements at intelligence or cybersecurity conferences or working groups.

 

Base Salary Range: $120,000 – $180,000

The salary range reflects the expected base compensation for a fully qualified candidate at this level based on experience, qualifications, and market data at the time of posting.

U.S.-Based Benefits + Perks (for Full Time Employees):

At SpyCloud, we are committed to working alongside individuals who are equally passionate about preventing cybercrime, regardless of their department or role. Guided by our core values in all business decisions, we prioritize unity in our mission and ensure all SpyCloud employees have the support and benefits they need to stay focused on our goals. In addition to our engaging workspace in South Austin, flexible and remote-friendly work options, and competitive salary package, we offer our employees a comprehensive benefits package that includes:

  • 401(k) with Employer Contribution
  • Health, Vision, and Dental Insurance
    • Health Savings Account (HSA) available with Employer Contribution
  • Employer Paid Life, Short-term, and Long-term Disability Insurance
  • Generous PTO Plan and 16 paid holidays per year

U.K.-Based Benefits + Perks (for Full Time Employees):

  • Retirement Savings Plan with Employer Contribution
  • Employer Provided Private Health Insurance and Healthcare Cashplan
  • Employer Paid Life Insurance and Income Replacement
  • Generous Holiday Plan and 14 paid holidays per year

About SpyCloud:

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and  protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.

To learn more and see insights on your company's exposed data, visit spycloud.com.

Our Mission:

Our mission is to make the internet a safer place by disrupting the criminal underground. Together with our customers and partners, we aim to end criminals’ ability to profit from stolen information.

Who We Are:

SpyCloud is a place for innovative, collaborative, and problem-solvers to thrive. Individually, we’re amazing, but together, we’re unstoppable. We celebrate diversity and various perspectives and aim to create an inclusive and supportive environment for all. We are proud to be an Equal Employment Opportunity and Affirmative Action employer of choice. All aspects of employment decisions will be based on merit, performance, and business needs. We do not discriminate on the basis of any status protected under federal, state, or local law. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Women, minorities, individuals with disabilities, and protected veterans are encouraged to apply. SpyCloud complies with applicable state and local laws governing nondiscrimination in employment. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

SpyCloud expressly prohibits any form of workplace harassment. Improper interference with the ability of SpyCloud's employees to perform their job duties may result in discipline up to and including discharge. SpyCloud shares the right to work and participates in the E-Verify program in all locations.

If you need assistance or accommodation due to a disability, you may contact us.

Our Culture:

Our culture is something really special. We’re all driven to disrupt the cybercriminal economy as we keep customer accounts safe from compromise. We support a truly worthy and serious mission, but we have fun doing it together. If you are driven, inventive, and collaborative, you’ll fit right in.

SpyCloud’s Recruitment Policy:

We will never ask an applicant for sensitive or personal financial information during the recruitment process. We advise all applicants seeking employment with SpyCloud to review available information on recruitment fraud. Anyone who suspects that they have been contacted by someone falsely representing SpyCloud should email careers@spycloud.com.

Compensation Transparency Policy: 

At SpyCloud, we believe in transparency and fairness in compensation. We strive to ensure that all employees are fairly compensated for their contributions, and we openly discuss our compensation philosophy and structure. We are committed to providing competitive salaries and benefits packages to attract and retain top talent, and we encourage open dialogue and feedback regarding compensation matters.

Learn more and apply: SpyCloud Careers

SpyCloud is not sponsoring visas at this time.

For applicants residing in California, please click here to read SpyCloud's CCPA Notice.

For applicants residing in the UK, please click here to read SpyCloud's Employee Privacy Notice.

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified