Cybersecurity Incident and Application Analyst

Gunnison

Bethesda (MD)

Hybrid

USD 130,000 - 145,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

3 weeks Personal Leave
11 paid Holidays
Flexible Time Off for training
401(k) company match
Health, Dental, Vision Insurance
Certifications/Training Allowance

Job summary

Gunnison Consulting Group is seeking an experienced cybersecurity professional to support incident detection, analysis, and response across NIH CIT environments. You will triage security events, determine severity, and coordinate containment and recovery with diverse teams.

The role requires hands‑on experience with SIEM tools (e.g., Splunk), Palo Alto/FireEye technologies, and vulnerability management. Hybrid work with on‑site collaboration in Bethesda, MD is available.

Qualifications

  • Experience in cybersecurity incident response lifecycle, from detection to post‑incident analysis.
  • Proficient in SIEM tools (e.g., Splunk) and threat‑detection technologies (Palo Alto, FireEye).
  • Knowledge of NIST SP 800‑61 incident‑handling guidance and incident playbooks.

Responsibilities

  • Support incident detection, analysis, response, containment, and recovery across NIH CIT environments.
  • Monitor and triage security events, assign severity, and escalate per procedures.
  • Lead or support post‑incident reviews and lessons‑learned activities.

Skills

Cybersecurity
Incident response
Network security
Threat monitoring
SIEM analysis

Education

Bachelor’s degree in cybersecurity or related field

Tools

Splunk
Palo Alto
FireEye
Tenable
EDR/IDS

Job description

  • This position is contingent upon a future opening with Gunnison.

Salary: $130,000 - $145,000/year

  • Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments.
  • Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures.
  • Apply the enterprise incident‑response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post‑incident analysis.
  • Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security‑tool alerts to identify malicious, anomalous, or unauthorized activity.
  • Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses.
  • Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat‑detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability‑management tools, and related security operations tools.
  • Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data‑security risks.
  • Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security‑control configurations relevant to incident investigation and response.
  • Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders.
  • Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans.
  • Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures.
  • Lead or support post‑incident reviews and lessons‑learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements.
  • Assist with annual incident‑response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident‑response documentation.
  • Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders.
  • Maintain familiarity with NIST SP 800‑61 incident‑handling guidance and apply it to daily incident‑response operations.
Description
  • This position is contingent upon a future opening with Gunnison.

Salary: $130,000 - $145,000/year

  • Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments.
  • Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures.
  • Apply the enterprise incident‑response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post‑incident analysis.
  • Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security‑tool alerts to identify malicious, anomalous, or unauthorized activity.
  • Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses.
  • Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat‑detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability‑management tools, and related security operations tools.
  • Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data‑security risks.
  • Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security‑control configurations relevant to incident investigation and response.
  • Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders.
  • Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans.
  • Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures.
  • Lead or support post‑incident reviews and lessons‑learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements.
  • Assist with annual incident‑response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident‑response documentation.
  • Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders.
  • Maintain familiarity with NIST SP 800‑61 incident‑handling guidance and apply it to daily incident‑response operations.
Work location

Hybrid, 2-3 days per week on‑site in Bethesda, MD.

  • Support cybersecurity incident detection, analysis, response, containment, recovery, and post‑incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments.
  • Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures.
  • Apply the enterprise incident‑response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post‑incident analysis.
  • Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security‑tool alerts to identify malicious, anomalous, or unauthorized activity.
  • Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses.
  • Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat‑detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability‑management tools, and related security operations tools.
  • Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data‑security risks.
  • Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security‑control configurations relevant to incident investigation and response.
  • Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders.
  • Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans.
  • Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures.
  • Lead or support post‑incident reviews and lessons‑learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements.
  • Assist with annual incident‑response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident‑response documentation.
  • Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders.
  • Maintain familiarity with NIST SP 800‑61 incident‑handling guidance and apply it to daily incident‑response operations.
Requirements

Minimum of two (2) to five (5) years of progressively responsible experience in cybersecurity incident response, security operations, network security, application security, cloud security, threat detection, or a related discipline.

Candidates Should Demonstrate Experience In
  • Security-event monitoring, alert triage, incident investigation, incident documentation, escalation, and response coordination.
  • Enterprise incident‑response processes, including preparation, detection and analysis, containment, eradication, recovery, and post‑incident activities.
  • Network security, web application security, cloud technologies, endpoint security, and security monitoring.
  • Identifying vulnerable services, insecure ports and protocols, default or weak configurations, and common network/application security weaknesses.
  • SIEM analysis, preferably Splunk, including log searches, dashboards, correlation, alert analysis, and report generation.
  • IDS/IPS, firewalls, endpoint detection and response, vulnerability‑management, and threat‑detection technologies, including Palo Alto, FireEye or comparable platforms, and Tenable.
  • Windows and Linux operating systems, including basic system/log analysis and security troubleshooting.
  • NIST SP 800‑61 and the creation or use of incident‑response playbooks, RACI charts, escalation procedures, SOPs, and lessons‑learned documentation.
  • Preparing technical findings, incident reports, management updates, and executive‑level summaries.
  • Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, computer science, information systems, computer engineering, network engineering, digital forensics, systems engineering, or a closely related technical discipline.
  • EC-Council Certified Incident Handler (E|CIH), current and active
  • Offensive Security Certified Professional (OSCP), current and active
  • GIAC Certified Incident Handler (GCIH), current and active
  • Current Splunk certification, such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Core Certified Advanced Power User, or an equivalent Splunk security/engineering credential
Clearance Requirement

Ability to obtain and maintain a Public Trust.

Desired Qualifications
  • Master’s degree in cybersecurity, information assurance, computer science, digital forensics, information systems, engineering, data analytics, or a related technical discipline.
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Penetration Tester (GPEN)
  • CompTIA Security+, CySA+, PenTest+, or CASP+
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) or related Palo Alto credential
  • Tenable/Nessus platform training or certification
  • FireEye, Trellix, Microsoft Defender, CrowdStrike, SentinelOne, or comparable EDR/XDR training
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • Cisco CyberOps Associate/Professional, CCNP Security, or equivalent network‑security certification
  • ITIL Foundation, particularly for candidates supporting formal incident, problem, and change‑management processes

The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.

Benefits

Gunnison Consulting Group's total compensation package also includes bonus and profit‑sharing opportunities, depending on company and employee performance. Available employee benefits include:

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications (self‑study is ineligible)
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!
Why Join Gunnison
  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.

In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident and Application Analyst
Cybersecurity Incident and Application Analyst

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave your first year
11 paid Holidays each year
Flexible Time Off for training/certs
+5
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 145,000 - 160,000
Medical, Dental and Vision Insurance
401(k) company match
Paid Holidays
+1
Security Assessment & Authorization (SA&A) Lead
Security Assessment & Authorization (SA&A) Lead

Gunnison • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks of Personal Leave
11 paid Holidays
5 days Flexible Time Off
+5
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Gunnison • Bethesda (MD)

Hybrid
USD 140,000 - 190,000
3 weeks of Personal Leave
11 paid Holidays
Flexible Time Off
+5
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Gunnison • Alexandria (VA)

Hybrid
USD 170,000 - 190,000
Bonus and profit-sharing
Personal Leave
Holidays
+5
Cyber Incident Management Lead
Cyber Incident Management Lead

Gunnison Consulting Group • Alexandria (VA)

On-site
USD 160,000 - 180,000
3 weeks of Personal Leave your first y
11 paid Holidays each year
5 days of Flexible Time Off
+5
Security Assessment & Authorization (SA&A) Lead
Security Assessment & Authorization (SA&A) Lead

Gunnison Consulting Group • Bethesda (MD)

Hybrid
USD 130,000 - 145,000
3 weeks Personal Leave
11 paid Holidays
5 days Flexible Time Off
+5
Cyber Incident Management Lead
Cyber Incident Management Lead

Gunnison • Alexandria (VA)

Hybrid
USD 160,000 - 180,000
Bonus and profit-sharing
401(k) company match
Medical, Dental and Vision Insurance
+2
Cybersecurity Program Manager
Cybersecurity Program Manager

Gunnison • Bethesda (MD)

Hybrid
USD 150,000 - 165,000
3 weeks Personal Leave
11 paid Holidays
Flexible Time Off
+5
Digital Forensics Analyst
Digital Forensics Analyst

Gunnison • Alexandria (VA)

Hybrid
USD 125,000 - 145,000
401(k) employer match
Medical, Dental & Vision
Professional development funds
+2