CSOC Tier 3 Incident Responder: Malware & Forensics

RISA

Springfield (VA)

On-site

USD 87,000 - 95,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
11 paid Federal Holidays

Job summary

RISA is seeking a highly skilled Incident Responder / Malware Analyst (CSOC Tier 3) to join the on-site team in Springfield, VA. You will lead containment, eradication, and recovery efforts for government-grade incidents, perform malware analysis and memory forensics, and develop indicators of compromise.

You will document findings and coordinate with CI, law enforcement, and internal stakeholders. The role requires active TS/SCI clearance, ability to obtain a polygraph, and a Bachelor’s degree

Qualifications

  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.

Responsibilities

  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.

Skills

Incident response
Malware analysis
Forensics
Threat intelligence coordination
Documentation discipline

Education

Bachelor's degree plus 6 years of relevant experience

Job description

RISA is seeking a highly skilled Incident Responder / Malware Analyst (CSOC Tier 3) to join the on-site team in Springfield, VA. You will lead containment, eradication, and recovery efforts for government-grade incidents, perform malware analysis and memory forensics, and develop indicators of compromise.

You will document findings and coordinate with CI, law enforcement, and internal stakeholders. The role requires active TS/SCI clearance, ability to obtain a polygraph, and a Bachelor’s degree

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSOC Tier 3 Analyst III
CSOC Tier 3 Analyst III

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Lead Cybersecurity Incident Response Analyst (TS/SCI)
Lead Cybersecurity Incident Response Analyst (TS/SCI)

Si Tec Consulting • Springfield (VA)

On-site
USD 130,000 - 170,000
Senior Cyber Incident Responder (TS/SCI)
Senior Cyber Incident Responder (TS/SCI)

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 160,000
Incident Response Senior Analyst (Tier 3)
Incident Response Senior Analyst (Tier 3)

Forensic Focus Limited • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Incident Response Analyst (Tier 3) — TS/SCI Eligible
Senior Incident Response Analyst (Tier 3) — TS/SCI Eligible

Resource Management Concepts, Inc. • Quantico (VA)

On-site
USD 135,000 - 150,000
Relocation assistance
Paid vacation & holidays
Healthcare plans
+2
Senior Cybersecurity Incident Response Analyst (TS/SCI)
Senior Cybersecurity Incident Response Analyst (TS/SCI)

mysitec • Springfield (VA)

On-site
USD 110,000 - 170,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

SITEC Consulting, LLC. • Springfield (VA)

On-site
USD 110,000 - 140,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 160,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

Si Tec Consulting • Springfield (VA)

On-site
USD 130,000 - 170,000
Senior Incident Response Analyst (Tier 3) – On‑Site Quantico
Senior Incident Response Analyst (Tier 3) – On‑Site Quantico

RMC - Resource Management Concepts Inc. • Quantico (VA)

On-site
USD 135,000 - 150,000
Relocation assistance
Paid vacation and holidays
Healthcare plans
+1