CSSP/IR Analyst

Bespoke Corps LLC

Ashburn (VA)

On-site

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bespoke Corps LLC is seeking a Cybersecurity Service Provider / Incident Response Analyst in Arlington, VA (The Pentagon). This full-time role involves providing onsite support, conducting incident response, and writing detailed reports. A current TS security clearance and IAT-II certification are required, along with the ability to handle CSSP/IR tools. The role offers a Monday to Friday schedule with no travel expected. Join us to engage in vital cybersecurity operations within a dynamic team environment.

Qualifications

  • Current TS security clearance with SCI access within the past 24 months.
  • Knowledge of CSSP/IR incident categorization.
  • Experience with scripting languages like Python is a plus.

Responsibilities

  • Provide onsite support for incident response and cybersecurity tasks.
  • Conduct active hunting for network intrusions.
  • Create detailed reports on cybersecurity threats and mitigations.

Skills

Technical skills in CSSP/IR tools
Ability to perform network intrusion detection
Report writing for cybersecurity concerns
Team collaboration

Education

DoD 8140 IAT-II or higher certification
Certified Ethical Hacker (CEH)

Tools

SIEM Tools
Yara
Snort

Job description

Position Title
  • Cybersecurity Service Provider (CSSP) / Incident Response (IR) Analyst
Department/Job Family
  • Operations
Reports To
  • IR Lead
Employment Type
  • Full-Time
Security Clearance Requirement
  • Have the ability to obtain and maintain a TS/SCI clearance
Position Description/Summary

Bespoke Corps, LLC (Bespoke) is looking for a qualified candidate to provide day‑to‑day onsite support to one of our valued customers. We seek a candidate responsible for supporting the accomplishments of the engagement. They will assist with project staff on‑site, provide technical/penetration testing, support work assignments, and act as liaison between project staff and project managers. In addition, the individual will present the customer staff regarding issues or conflicts and ensure the quality of all deliverables. The candidate must be a self‑starter who achieves in individual and team‑oriented activities.

Demonstrated Experience/Core Responsibilities (Minimum 3 years)
  • Strong technical skills and a firm and thorough understanding of CSSP/IR tools (i.e. SIEM Tools) as well as a demonstrated ability to identify new and emerging threats
  • Providing detailed triage of CSSP/IR incidents including: implementing intrusion detection and prevention signatures
  • Conducting active hunting for network intrusions involving manual packet capture analysis, DNS log review, open source, and closed source intel analysis
  • Knowledge of Advanced Persistent Threats (APT), network attack patterns, detection techniques, trends, threat actors, and techniques for defending a network against these attacks
  • Creating detailed reports on attack trends and recommended mitigations that are suitable for both senior leaders and technical audiences
  • Extensive experience creating detailed reports pertaining to various cybersecurity‑related concerns or events
  • Gathering, analyzing, and implementing defenses against Indicators of Compromise (IoCs) gathered from open forums, closed forums, mailing lists, and directed research
  • Ability to collaborate well within a team construct
Qualifications (required)
  • Current TS security clearance with current SCI access, or have been granted SCI access within the past 24 months
  • DoD 8140 IAT-II or above professional certification (i.e., Security+, GCIH)
  • Current Certified Ethical Hacker (CEH) certification, or have the ability to obtain an active CEH certification within 90 days
  • Knowledge and experience categorizing CSSP/IR incidents with CJCSM 6510 Incident Response Categories
  • Experience with creating and implementing custom Yara, Snort and ESS rules
Preferred Qualifications
  • Knowledge of scripting languages such as Python is a plus
Work Demands and Environment

The work environment and physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to talk or hear. The employee is frequently required, sometimes for extended periods, to walk, stand, or sit. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines. The employee is occasionally required to climb ladders or stairs; use hands to type, finger, handle, or feel; reach with hands and arms; balance, stoop, kneel, crouch, or crawl; and get in and out of vehicles. The employee must occasionally lift and/or move small or large objects up to 50 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, depth perception, and the ability to adjust focus.

Job Location
  • Arlington, VA (The Pentagon)
Weekly Schedule
  • Monday – Friday, 7:00am - 3:00pm (Occasional Rotational Holiday Support)
Travel
  • There is no travel expected for this position
Candidate Type
  • W-2 candidates are welcome to apply (please include a current copy of your resume)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Service Provider/Incident Response (CSSP/IR) Analyst
Cybersecurity Service Provider/Incident Response (CSSP/IR) Analyst

Bespoke Corps LLC • Arlington (VA)

On-site
USD 80,000 - 110,000
Cyber Security Operations Jr Analyst
Cyber Security Operations Jr Analyst

Spahrsolutionsgroup • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Onsite CSSP/IR Analyst — TS/SCI Clearance (Pentagon)
Onsite CSSP/IR Analyst — TS/SCI Clearance (Pentagon)

Bespoke Corps LLC • Ashburn (VA)

On-site
USD 80,000 - 110,000
Cybersecurity Service Provider (CSSP) Operations Team Lead
Cybersecurity Service Provider (CSSP) Operations Team Lead

Cwsc • Indianapolis (IN)

On-site
USD 140,000 - 190,000
Security Operation Center (SOC) Analyst II
Security Operation Center (SOC) Analyst II

General Dynamics Information Technology • Colorado Springs (CO)

On-site
USD 112,000 - 138,000
Medical plan options
Dental and Vision plan options
401(k) plan with company match
Lead Cyber Defense Incident Responder On-site - TS/SCI
Lead Cyber Defense Incident Responder On-site - TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 175,000 - 180,000
Professional certifications support
Leadership development
Regular company updates
+3
SITEC - Cybersecurity Analyst (JNY) - Fort Bragg, NC
SITEC - Cybersecurity Analyst (JNY) - Fort Bragg, NC

Peraton • North Carolina

On-site
USD 70,000 - 100,000
Incident Response Team Lead
Incident Response Team Lead

Agile Defense • Reston (VA)

On-site
USD 100,000 - 130,000
Lead Cyber Defense Incident Responder TS/SCI
Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Professional certification support
Leadership accessibility
Regular company updates
+1
Personnel Security Specialist
Personnel Security Specialist

Advantage SCI • Reston (VA)

On-site
USD 90,000 - 140,000