Cybersecurity Incident Response Triage Analyst

Accenture Federal Services Careers Marketplace

Arlington (VA)

On-site

USD 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Accenture Federal Services in Arlington, VA, seeks a Cybersecurity Incident Response Triage Analyst to join the CIRT team within the CISO organization. The role involves monitoring, triaging, and analyzing alerts from SIEM and security sensors, coordinating with incident response and operations teams to qualify events and determine false positives.

Candidates should have 1–2 years in information security, experience with event/log analysis and SIEM, and strong communication skills.

Qualifications

  • 1-2 years of information security experience or equivalent education/work experience.
  • Experience performing event and log analysis with security tools including SIEM.
  • Familiarity with TCP/IP, malware analysis concepts, and endpoint analysis.
  • Strong written and verbal communication skills and attention to detail.
  • Understanding of incident response lifecycles and security operations.

Responsibilities

  • Actively monitor and respond to cybersecurity incidents related to alerted policy violations.
  • Analyze and investigate incidents to determine nature and scope.
  • Coordinate with team leads for effective incident resolution.
  • Document incidents and response activities in detail.
  • Stay updated with latest cybersecurity threats and trends.
  • Assist in developing incident response strategies and procedures.
  • Collaborate with operations, legal, HR, and management to interview subjects and determine true/false positives.

Skills

Incident response
Event and log analysis
Communication skills
Network security basics

Tools

SIEM
Firewalls
Antivirus
Web proxies
DLP tools
NIDS/IPS

Job description

Cybersecurity Incident Response Triage Analyst

Arlington, VA

The Work

The Cybersecurity Incident Response Junior Analyst and Triage Analyst role will work in the CIRT team in the CISO organization. This role works on a shift under the analysis and triage team lead to relate, scope, and triage alerts and notifications from the SIEM, security sensors, ticketing system, walk-ins, and phone calls. Requires technical understanding to collaborate with the incident response and operations teams to qualify events as relevant and determine true and false positives. Knowledge in incident response lifecycles, common cyber-attacks, and federal incident reporting requirements.

Primary responsibilities:

  • Actively monitor and respond to cybersecurity incidents related to alerted policy violations
  • Analyze and investigate incidents to determine their nature and scope.
  • Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution.
  • Document incidents and response activities in detail.
  • Stay updated with the latest cybersecurity threats and trends.
  • Assist in developing and refining incident response strategies and procedures.
  • Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives.

What you need

  • 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience.
  • 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus,
  • Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions.
  • Excellent written and oral communication skills, attention to detail, and interpersonal skills.
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages.
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages.
  • Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same.
  • Familiarity with static and dynamic malware analysis concepts.
  • Experience with indicators of attack and compromise.
  • Familiarity with Windows / Linux architecture and endpoint analysis of the same.
  • Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc

Bonus if you have

  • SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM

#LI-DNI

What We Believe

As a company wholly dedicated to serving the US federal government, we bring together the best talent to help reinvent how federal agencies operate and deliver greater value for their mission and the American people. We have an unwavering commitment to creating a culture in which all our people are respected, feel a sense of belonging, and have equal opportunity. As a business imperative, every person at Accenture Federal Services has the responsibility to create and sustain a culture where everyone feels welcomed and included. This is grounded in our core values and our experience that hiring and developing great people who reflect different perspectives, experiences, and backgrounds is key to driving innovation and delivering the results that our clients and the country count on.

Equal Employment Opportunity Statement

We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. For details, view a copy of the Accenture Federal Services Equal Opportunity Policy Statement. Accenture Federal Services is an Equal Employment Opportunity employer. Additionally, as an Affimative Action Employer for Veterans and Individuals with Disabilities, Accenture Federal Services is committed to providing veteran employment opportunities to our service men and women.

Requesting An Accommodation

Accenture Federal Services is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture Federal Services and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.

If you are being considered for employment opportunities with Accenture Federal Services and need an accommodation for a disability or religious observance during the interview process or for the job you are interviewing for, please speak with your recruiter.

Other Employment Statements

Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States.

Candidates who are currently employed by a client of Accenture Federal Services or an affiliated Accenture business may not be eligible for consideration.

Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information.

California requires additional notifications for applicants and employees. If you are a California resident, live in or plan to work from Los Angeles County upon being hired for this position, please click here for additional important information.

As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland . The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.

The pay range for the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland is:

$57,200 - $109,400 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture-Federal-Services-2 • Arlington (VA)

On-site
USD 57,000 - 109,000
Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture • Arlington (VA)

On-site
USD 57,000 - 109,000
Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture Federal Services • Arlington (VA)

On-site
USD 57,000 - 109,000
Senior Cloud Infrastructure Support Engineer
Senior Cloud Infrastructure Support Engineer

Accenture Federal Services • Charlottesville (VA)

On-site
USD 181,000 - 220,000
Incident Response and Forensics Lead
Incident Response and Forensics Lead

Accenture Federal Services • Germantown (MD)

On-site
USD 100,000 - 204,000
Systems Engineer - mid-level
Systems Engineer - mid-level

Linuxconfig • McLean (VA)

Hybrid
USD 78,000 - 149,000
Cybersecurity Engineer
Cybersecurity Engineer

Accenture • Fort Meade (MD)

On-site
USD 126,000 - 243,000
Security Engineer
Security Engineer

Accenture Federal Services • Clearfield (UT)

On-site
USD 116,900 - 243,100
Security Architect Specialist
Security Architect Specialist

Accenture Federal Services • Arlington (VA)

On-site
USD 79,000 - 160,000
Cyber Defense Engineer
Cyber Defense Engineer

Accenture Federal Services • St. Louis (MO)

On-site
USD 85,000 - 221,000