Cybersecurity Analyst, Incident Responder

Digital Global Connectors

McLean (VA)

Hybrid

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Digital Global Connectors is seeking a seasoned Cybersecurity Analyst – Tier 2 (Incident Responder) to support a Federal information security program. The role conducts advanced incident analysis, containment, eradication, and recovery for enterprise systems, networks, and cloud resources.

The candidate will work with SOC personnel, engineers, threat hunters, ISSOs, and system owners to minimize impact and strengthen cyber defenses. U.S.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.
  • Minimum four (4) years of experience performing cybersecurity incident response or cyber defense operations.
  • Experience investigating enterprise cybersecurity incidents.
  • Experience using SIEM, EDR, XDR, and log analysis platforms.
  • Understanding of networking protocols, operating systems, malware behavior, and common attack techniques.

Responsibilities

  • Investigate cybersecurity incidents affecting enterprise information systems, applications, cloud services, and networks.
  • Perform incident triage to determine scope, severity, and operational impact.
  • Execute containment, eradication, and recovery procedures in accordance with incident response plans.
  • Coordinate response activities with technical teams and program leadership.
  • Validate successful remediation before incident closure.
  • Maintain incident timelines and documentation throughout the response lifecycle.

Skills

Incident Response
Cyber Defense Operations
Digital Forensic Triage
Malware Analysis
Threat Detection
Threat Intelligence

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline

Tools

SIEM
EDR
XDR
Log Analysis Tools
Forensic Tools

Job description

Cybersecurity Analyst, Incident Responder

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst – Tier 2 (Incident Responder) to support a Federal information security program. The Tier 2 Incident Responder is responsible for investigating, containing, eradicating, and recovering from cybersecurity incidents affecting enterprise information systems, networks, cloud environments, and critical business operations.

This position performs advanced analysis of cybersecurity events, coordinates incident response activities, conducts forensic triage, analyzes malware and attacker tactics, and collaborates with Security Operations Center (SOC) personnel, Security Engineers, Threat Hunters, ISSOs, and System Owners to minimize operational impact and strengthen the organization's cybersecurity posture.

The successful candidate will possess strong technical investigative skills, experience responding to sophisticated cyber threats, and the ability to perform effective incident analysis within complex enterprise environments.

Essential Duties and Responsibilities
Incident Response
  • Investigate cybersecurity incidents affecting enterprise information systems, applications, cloud services, and networks.
  • Perform incident triage to determine scope, severity, and operational impact.
  • Execute containment, eradication, and recovery procedures in accordance with established incident response plans.
  • Coordinate response activities with technical teams and program leadership.
  • Validate successful remediation before incident closure.
  • Maintain incident timelines and documentation throughout the response lifecycle.
Security Investigation
  • Analyze suspicious network traffic, endpoint activity, authentication events, and system logs.
  • Identify indicators of compromise (IOCs), indicators of attack (IOAs), and attacker behaviors.
  • Determine root cause and attack vectors.
  • Assess the extent of compromise across affected systems.
  • Identify persistence mechanisms and unauthorized access.
  • Recommend remediation and long-term defensive improvements.
Digital Forensic Triage
  • Collect and preserve digital evidence in accordance with forensic best practices.
  • Perform preliminary forensic analysis of endpoints, servers, and cloud resources.
  • Review memory captures, event logs, registry artifacts, file systems, browser artifacts, and authentication records.
  • Support chain-of-custody documentation.
  • Coordinate with Digital Forensics Analysts for advanced forensic examinations when required.
Malware Analysis Support
  • Analyze suspicious files and malicious code using approved analysis tools.
  • Identify malware behavior and associated indicators.
  • Review sandbox analysis results.
  • Document malware characteristics and recommended detection signatures.
  • Coordinate with Threat Intelligence and Threat Hunting personnel regarding emerging threats.
Threat Detection and Analysis
  • Investigate alerts generated by SIEM, EDR, IDS/IPS, and XDR platforms.
  • Correlate data from multiple security tools to identify attack patterns.
  • Evaluate threat intelligence to determine relevance to ongoing investigations.
  • Recommend improvements to detection logic based on investigative findings.
  • Assist in developing new detection use cases.
Security Tool Operations

Utilize technologies including:

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud
  • CrowdStrike Falcon
  • Palo Alto Cortex XDR
  • Trellix
  • Cisco Secure
  • Wireshark
  • Velociraptor
  • Security Information and Event Management (SIEM)
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
Reporting and Documentation

Develop and maintain:

  • Incident Reports
  • After-Action Reports
  • Root Cause Analyses
  • Investigation Summaries
  • Lessons Learned
  • Security Recommendations
  • Executive Briefings
  • Incident Metrics
  • Threat Assessments
  • Standard Operating Procedures

Ensure documentation is complete, technically accurate, and suitable for operational and audit purposes.

Collaboration
  • Coordinate with Tier 1 SOC Analysts, Threat Hunters, Digital Forensics Analysts, Security Engineers, ISSOs, System Owners, and Government stakeholders.
  • Participate in incident response working groups.
  • Provide technical guidance during active cybersecurity incidents.
  • Support enterprise cybersecurity exercises and tabletop events.
  • Share investigative findings with cross-functional cybersecurity teams.
Continuous Improvement
  • Recommend improvements to incident response procedures and playbooks.
  • Participate in lessons-learned reviews following significant incidents.
  • Assist with development of new detection capabilities.
  • Monitor emerging attack techniques and defensive technologies.
  • Maintain technical proficiency through ongoing training and professional certification.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.
  • Minimum four (4) years of experience performing cybersecurity incident response or cyber defense operations.
  • Experience investigating enterprise cybersecurity incidents.
  • Experience using SIEM, EDR, XDR, and log analysis platforms.
  • Understanding of networking protocols, operating systems, malware behavior, and common attack techniques.
  • Strong analytical, investigative, documentation, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
  • Experience supporting a Federal civilian agency.
  • Experience performing digital forensic triage or malware analysis.
  • Experience supporting cloud incident response in Microsoft Azure or AWS environments.
  • Experience utilizing MITRE ATT&CK during investigations.
  • GIAC Certified Incident Handler (GCIH)
  • CompTIA CySA+
  • CompTIA Security+
  • GIAC Certified Forensic Analyst (GCFA)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Ethical Hacker (CEH) (preferred)
Knowledge, Skills, and Abilities
  • Incident Response
  • Cyber Defense Operations
  • Digital Forensic Triage
  • Malware Analysis
  • Threat Detection
  • Threat Intelligence
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Security Information and Event Management (SIEM)
  • Wireshark
  • Velociraptor
  • Log Analysis
  • Network Traffic Analysis
  • Windows Security
  • Linux Security
  • Cloud Security
  • MITRE ATT&CK Framework
  • NIST SP 800-61 Incident Response
  • NIST Cybersecurity Framework
  • Technical Documentation
  • Root Cause Analysis
  • Microsoft Office Suite
  • ServiceNow
  • Jira
Security Requirements
  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support incident response activities, emergency cybersecurity operations, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
  • Must maintain strict confidentiality while handling sensitive incident data, forensic evidence, investigative records, and Federal information systems.
  • Ability to respond effectively to cybersecurity incidents in a fast-paced operational environment while coordinating with Government stakeholders, technical teams, and program leadership to minimize risk and restore secure operations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 150,000
Digital Forensics / Malware Analyst
Digital Forensics / Malware Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 90,000 - 150,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
Cybersecurity Analyst, Threat Hunter
Cybersecurity Analyst, Threat Hunter

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 180,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 170,000
Security Engineer
Security Engineer

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 160,000
Tier 2 Cyber Incident Response (Shift Lead)
Tier 2 Cyber Incident Response (Shift Lead)

AGR, LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Tier 2 Cyber Incident Responder (Shift Lead)
Tier 2 Cyber Incident Responder (Shift Lead)

Twenty8 Technology, LLC • Beltsville (MD)

On-site
USD 130,000 - 170,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000