CSOC Tier 3 Analyst III

RISA

Springfield (VA)

On-site

USD 87,000 - 95,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
11 paid Federal Holidays

Job summary

RISA is seeking a highly skilled Incident Responder / Malware Analyst (CSOC Tier 3) to join the on-site team in Springfield, VA. You will lead containment, eradication, and recovery efforts for government-grade incidents, perform malware analysis and memory forensics, and develop indicators of compromise.

You will document findings and coordinate with CI, law enforcement, and internal stakeholders. The role requires active TS/SCI clearance, ability to obtain a polygraph, and a Bachelor’s degree

Qualifications

  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.

Responsibilities

  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.

Skills

Incident response
Malware analysis
Forensics
Threat intelligence coordination
Documentation discipline

Education

Bachelor's degree plus 6 years of relevant experience

Job description

Incident Responder / Malware Analyst (CSOC Tier 3)
Cyber Security Operations Specialist III - CSOC Tier 3

Location: Springfield, VA - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Schedule: Supports a 24x7x365 incident response operation

Travel: None

Salary Range: $87,000 – $95,000

When an incident happens, you are the one who contains it.

RISA is hiring a CSOC Tier 3 analyst for the incident response team defending an Intelligence Community customer's enterprise. This is the top of the escalation chain: containment, eradication, and recovery, plus malware and implant analysis and forensic artifact work. When a Cyber Incident Response Team stands up, you work under the Government CIRT Commander; between incidents, you run the exercises that make the next response better. You will talk to the owner here, not a recruiting queue.

What You Will Do
  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.
What You'll Bring
  • S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.
  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.
Nice to Have
  • Master's degree.
  • IAT Level III already in hand.
About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.

Benefits
  • Medical, dental, and vision insurance
  • 401(k) and Roth
  • Paid Time Off
  • 11 paid Federal Holidays

RISA is an Equal Opportunity Employer.

  • Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSOC Tier 3 Incident Responder: Malware & Forensics
CSOC Tier 3 Incident Responder: Malware & Forensics

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cyber Security Operations Specialist Tier 3
Cyber Security Operations Specialist Tier 3

D2 Consulting • Springfield (VA)

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
PTO (paid time off)
+1
Cyber Implementation Engineer III
Cyber Implementation Engineer III

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
+1
Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Fort Meade (MD)

On-site
USD 88,000 - 118,000
Senior CSOC Cybersecurity Incident Responder (TS/SCI)
Senior CSOC Cybersecurity Incident Responder (TS/SCI)

D2 Consulting • Springfield (VA)

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
PTO (paid time off)
+1
Soc Tier 3 Analyst
Soc Tier 3 Analyst

Global Alliant Inc • Crownsville (MD)

Hybrid
USD 130,000 - 190,000
Cyber Security Operations Specialist III - Tier 3
Cyber Security Operations Specialist III - Tier 3

CACI International Inc • Springfield (VA)

On-site
USD 86,600 - 181,800
SOC Analyst IV
SOC Analyst IV

ecsfederal • Virginia (MN)

Hybrid
USD 120,000 - 140,000