Cyber Incident Responder / Malware Analyst (CSOC)

RISA

Springfield (VA)

On-site

USD 87,000 - 95,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
11 paid Federal Holidays

Job summary

RISA in Springfield, VA is seeking an Incident Responder / Malware Analyst (CSOC Tier 3) to join the on-site incident response team defending a federal customer. You will lead containment, eradication, and recovery efforts and perform malware analysis and forensics.

This role requires US citizenship, active TS/SCI clearance, and the ability to obtain a government polygraph. The position supports 24x7 operations and offers a competitive salary and benefits.

Qualifications

  • Bachelor's degree in a field applicable to the position plus 6 years of relevant experience (equivalents accepted – Master’s + 4, Associate’s + 8, or HS diploma + 10)
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start]
  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.

Responsibilities

  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.

Skills

Incident response
Malware analysis
Forensics
US citizenship
Active TS/SCI clearance
Government polygraph readiness

Education

Bachelor's degree in a field applicable to the position
Master's degree (nice to have)

Job description

Incident Responder / Malware Analyst (CSOC Tier 3)
Cyber Security Operations Specialist III - CSOC Tier 3

Location: Springfield, VA - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Schedule: Supports a 24x7x365 incident response operation

Travel: None

Salary Range: $87,000 – $95,000

When an incident happens, you are the one who contains it.

RISA is hiring a CSOC Tier 3 analyst for the incident response team defending an Intelligence Community customer's enterprise. This is the top of the escalation chain: containment, eradication, and recovery, plus malware and implant analysis and forensic artifact work. When a Cyber Incident Response Team stands up, you work under the Government CIRT Commander; between incidents, you run the exercises that make the next response better. You will talk to the owner here, not a recruiting queue.

What You Will Do
  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.
What You'll Bring
  • S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.
  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.
Nice to Have
  • Master's degree.
  • IAT Level III already in hand.
About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

RISA is an Equal Opportunity Employer.

  • Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CSOC Tier 3 Analyst III
CSOC Tier 3 Analyst III

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
CSOC Tier 3: Cyber Incident Responder & Malware Analyst
CSOC Tier 3: Cyber Incident Responder & Malware Analyst

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
CSOC Tier 3 Incident Responder: Malware & Forensics
CSOC Tier 3 Incident Responder: Malware & Forensics

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior CSOC Cybersecurity Incident Responder (TS/SCI)
Senior CSOC Cybersecurity Incident Responder (TS/SCI)

D2 Consulting • Springfield (VA)

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
PTO (paid time off)
+1
Cyber Security Operations Specialist Tier 3
Cyber Security Operations Specialist Tier 3

D2 Consulting • Springfield (VA)

On-site
USD 110,000 - 115,000
Health/Dental/Vision
401(k) match
PTO (paid time off)
+1
Cyber Implementation Engineer III
Cyber Implementation Engineer III

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
+1
Cybersecurity Implementation Engineer (EDR, NDR, AWS)
Cybersecurity Implementation Engineer (EDR, NDR, AWS)

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
CSOC Tier 3 Cyber Engineer
CSOC Tier 3 Cyber Engineer

General Dynamics Information Technology, Inc. • Springfield (VA)

On-site
USD 147,000 - 199,000
Cyber Security Operations Specialist - Tier 2
Cyber Security Operations Specialist - Tier 2

D2 Consulting • Springfield (VA)

On-site
USD 90,000 - 95,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3