Defense Cyber Incident Response Analyst

Via Logic LLC

Seaside (CA)

On-site

USD 87,000 - 157,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking an experienced Incident Response Analyst to support the DMDC CyberPRIMES program. The role entails investigating and responding to cybersecurity events affecting DHRA systems and coordinating with SOC analysts, CSSPs, and government stakeholders.

The position covers the full incident-response lifecycle across NIPRNet and SIPRNet environments, with after-hours recall and rigorous documentation requirements. Active Secret clearance and U.S. citizenship are required.

Qualifications

  • Bachelor’s degree and 5 or more years of relevant cybersecurity experience.
  • Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation.
  • Experience performing analysis of cybersecurity events and determining appropriate response or escalation actions.
  • Experience supporting incident containment, eradication, recovery, and post-incident activities.
  • Experience monitoring and analyzing enterprise cybersecurity tools and security telemetry.
  • Experience documenting incident timelines, investigative findings, evidence, response actions, and status.
  • Experience coordinating cybersecurity incidents across technical teams and stakeholder organizations.

Responsibilities

  • Support preparation, detection, analysis, containment, eradication, recovery, and post-incident activities for cybersecurity events and incidents.
  • Investigate cybersecurity incidents affecting NIPRNet and SIPRNet environments.
  • Perform proactive security monitoring and analysis to identify potential intrusion attempts and other malicious activity.
  • Analyze security information from SIEM platforms, endpoint-security capabilities, firewalls, IDS, IPS, web-security systems, antispam capabilities, malware-prevention systems, and related enforcement technologies.
  • Recognize potential intrusion attempts, malicious activity, or other cybersecurity conditions requiring immediate investigation or mitigation.
  • Assess cybersecurity events to determine scope, potential impact, affected systems, and required response actions.
  • Support containment and mitigation of active cybersecurity threats in accordance with approved Government procedures.
  • Coordinate eradication and recovery activities with system owners, administrators, network personnel, cybersecurity teams, and other technical stakeholders.
  • Collect and preserve technical evidence associated with cybersecurity events and incidents.
  • Maintain complete and accurate incident records, timelines, supporting evidence, investigative findings, response actions, and status information.
  • Develop and contribute to required cybersecurity event and incident reporting.
  • Coordinate incident-response activities with Security Operations Center analysts, CSSPs, system owners, technical teams, and Government stakeholders.
  • Support escalation of significant cybersecurity events and incidents in accordance with established procedures.
  • Provide timely status updates during active investigations and incident-response activities.
  • Support post-incident analysis and lessons learned to identify opportunities to improve monitoring, detection, response procedures, and defensive capabilities.
  • Participate in after-hours incident response when assigned and meet the contract-required one-hour recall requirement.

Skills

Incident response
SOC operations
Cyber defense
Security-event analysis
Documentation
Stakeholder coordination

Education

Bachelor’s degree

Tools

SIEM platforms
Endpoint security
Firewalls
IDS/IPS
Web security
Antispam
Malware prevention

Job description

Leidos is seeking an experienced Incident Response Analyst to support the DMDC CyberPRIMES program. The role entails investigating and responding to cybersecurity events affecting DHRA systems and coordinating with SOC analysts, CSSPs, and government stakeholders.

The position covers the full incident-response lifecycle across NIPRNet and SIPRNet environments, with after-hours recall and rigorous documentation requirements. Active Secret clearance and U.S. citizenship are required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Defense Cyber Incident Responder
Defense Cyber Incident Responder

Koitecc Solutions • Seaside (CA)

On-site
USD 87,000 - 157,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

Via Logic LLC • Alexandria (VA)

On-site
USD 87,000 - 157,000
Senior Incident Response Analyst – Cyber Defense
Senior Incident Response Analyst – Cyber Defense

Leidos • Seaside (OR)

On-site
USD 87,000 - 157,000
Remote Incident Response Analyst – Cyber Defense
Remote Incident Response Analyst – Cyber Defense

Leidos Inc • Alexandria (VA)

On-site
USD 87,000 - 157,000
Remote Incident Response Analyst
Remote Incident Response Analyst

Leidos Inc • Seaside (CA)

On-site
USD 87,000 - 157,000
DoD Incident Response Analyst | Secret Clearance Required
DoD Incident Response Analyst | Secret Clearance Required

Koitecc Solutions • Alexandria (VA)

On-site
USD 87,000 - 157,000
Tier 2 SOC Analyst: Cyber Defense & Incident Response
Tier 2 SOC Analyst: Cyber Defense & Incident Response

Leidos Inc • Alexandria (VA)

On-site
USD 87,000 - 157,000
Incident Response Analyst
Incident Response Analyst

Leidos • Seaside (OR)

On-site
USD 87,000 - 157,000
Senior Tier 2 SOC Analyst - Remote CyberOps (DMDC)
Senior Tier 2 SOC Analyst - Remote CyberOps (DMDC)

Via Logic LLC • Alexandria (VA)

On-site
USD 87,000 - 157,000
Incident Response Analyst — Secret Clearance, GovCon
Incident Response Analyst — Secret Clearance, GovCon

Xcelerate-Solutions-5 • Alexandria (VA)

On-site
USD 94,000 - 127,000