AOUSC - Incident Response Analyst

cFocus Software Incorporated

Washington (District of Columbia)

Hybrid

USD 110,000 - 135,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role is Hybrid with onsite in Washington, DC, and requires a Public Trust clearance.

You will perform in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates should have 3+ years IR experience, strong scripting in Python/PowerShell, and knowledge of Velociraptor, Splunk ES and Microsoft Sentinel.

Qualifications

  • Active Public Trust clearance required.
  • BS in Computer Science, IT, or related field.
  • 3+ years in an incident response role.
  • 2+ years scripting with Python and PowerShell for decoding obfuscated payloads.
  • 2 years in live triage, log correlation, and detection rule refinement with Velociraptor, Splunk ES and Sentinel.
  • 1 year in federal incident handling guidelines per NIST CSWP-29 and SP-800-61.
  • Active SANS GCIH or GCIA certification.

Skills

Active Public Trust clearance
IR experience
Python & PowerShell scripting
Live triage & log correlation
NIST incident handling familiarity

Education

BS in Computer Science/IT/related

Tools

Python
PowerShell
Velociraptor
Splunk ES
Microsoft Sentinel

Job description

cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.

Qualifications
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 3+ years of experience in an IR role.
  • 2+ years’ experience using Python and PowerShell scripts for decoding/decryption of obfuscated payloads.
  • 2 years of experience in performing live triage, log correlation, detection rule refinement, to include usage of Velociraptor, Splunk ES and Sentinel.
  • 1 year of experience in federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.
  • Active SANS GCIH or GCIA certification
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Insider Threat Analyst
AOUSC - Insider Threat Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 80,000 - 100,000
AOUSC - Cybersecurity Triage Analyst
AOUSC - Cybersecurity Triage Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 70,000 - 100,000
AOUSC - Cybersecurity Shift Lead
AOUSC - Cybersecurity Shift Lead

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 150,000
AOUSC - Threat Hunt Analyst
AOUSC - Threat Hunt Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 160,000
AOUSC - SOC Manager
AOUSC - SOC Manager

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 190,000
AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 130,000 - 170,000
Senior Incident Response Analyst - Tier 2 (Hybrid)
Senior Incident Response Analyst - Tier 2 (Hybrid)

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 135,000
AOUSC - Threat Hunt Lead
AOUSC - Threat Hunt Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 170,000
AOUSC - Cyber Exercises Support Lead
AOUSC - Cyber Exercises Support Lead

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 160,000
AOUSC - Digital Forensics Analyst
AOUSC - Digital Forensics Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 90,000 - 120,000