Incident Response Analyst

Jobtailor

California (MO)

On-site

USD 110,000 - 150,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks a senior cybersecurity incident responder to lead containment, eradication and recovery for government networks, including NIPRNet and SIPRNet. You will analyze SIEM data, coordinate with SOC analysts and system owners, document investigations, and preserve evidence to support post-incident lessons learned.

U.S. citizenship and an active Secret security clearance are required; DoD or Federal experience is preferred.

Qualifications

  • Bachelor’s degree and 5+ years of relevant cybersecurity experience; degree may be substituted by specific training
  • Experience supporting cybersecurity incident response, SOC operations, cyber defense, or security-event investigation
  • Experience analyzing cybersecurity events and determining response or escalation actions
  • Experience supporting containment, eradication, recovery, and post-incident activities
  • Experience monitoring and analyzing enterprise cybersecurity tools and telemetry
  • Experience documenting incident timelines, evidence, response actions, and status
  • Experience coordinating cybersecurity incidents across technical teams and stakeholders
  • U.S. Citizenship required; active Secret security clearance required

Responsibilities

  • Support preparation, detection, analysis, containment, eradication, recovery, and post-incident activities for cybersecurity events
  • Investigate cybersecurity incidents affecting NIPRNet and SIPRNet environments
  • Perform proactive security monitoring and analysis to identify intrusion attempts and threats
  • Analyze security information from SIEM platforms, endpoint tools, firewalls, IDS/IPS, web security, antispam, and malware systems
  • Assess events to determine scope, impact, and required response actions
  • Coordinate eradication and recovery activities with system owners, administrators, and security teams
  • Collect and preserve technical evidence and maintain incident records and timelines
  • Coordinate incident-response activities with SOC analysts, system owners, and stakeholders
  • Support escalation and after-hours response per procedures
  • Provide timely status updates during investigations and contribute to post-incident lessons learned

Skills

Cybersecurity Incident Response
SOC Operations
SIEM Analysis
Incident Documentation
Network & Endpoint Security Monitoring

Education

Bachelor's degree
Active Secret Security Clearance

Tools

SIEM Platforms
Endpoint Security Tools
Firewalls
Intrusion Detection Systems
Intrusion Prevention Systems
Web-Security Systems
Antispam Technologies
Malware-Prevention Systems

Job description

  • Support preparation, detection, analysis, containment, eradication, recovery, and post-incident activities for cybersecurity events and incidents
  • Investigate cybersecurity incidents affecting NIPRNet and SIPRNet environments
  • Perform proactive security monitoring and analysis to identify potential intrusion attempts and malicious activity
  • Analyze security information from SIEM platforms, endpoint-security capabilities, firewalls, IDS, IPS, web-security systems, antispam capabilities, malware-prevention systems, and related enforcement technologies
  • Assess cybersecurity events to determine scope, potential impact, affected systems, and required response actions
  • Support containment and mitigation of active cybersecurity threats in accordance with approved Government procedures
  • Coordinate eradication and recovery activities with system owners, administrators, network personnel, cybersecurity teams, and technical stakeholders
  • Collect and preserve technical evidence associated with cybersecurity events and incidents
  • Maintain accurate incident records, timelines, supporting evidence, investigative findings, response actions, and status information
  • Develop and contribute to required cybersecurity event and incident reporting
  • Coordinate incident-response activities with SOC analysts, CSSPs, system owners, technical teams, and Government stakeholders
  • Support escalation of significant cybersecurity events and incidents in accordance with established procedures
  • Provide timely status updates during active investigations and incident-response activities
  • Support post-incident analysis and lessons learned to improve monitoring, detection, response procedures, and defensive capabilities
  • Participate in after-hours incident response when assigned and meet the contract-required one-hour recall requirement
Requirements
  • Bachelor’s degree and 5 or more years of relevant cybersecurity experience; specific experience, education and training may be considered in lieu of degree
  • Experience supporting cybersecurity incident response, Security Operations Center operations, cyber defense, or security-event investigation
  • Experience analyzing cybersecurity events and determining appropriate response or escalation actions
  • Experience supporting incident containment, eradication, recovery, and post-incident activities
  • Experience monitoring and analyzing enterprise cybersecurity tools and security telemetry
  • Experience documenting incident timelines, investigative findings, evidence, response actions, and status
  • Experience coordinating cybersecurity incidents across technical teams and stakeholder organizations
  • Working knowledge of network, endpoint, and enterprise cybersecurity monitoring concepts
  • Ability to recognize potential intrusion activity and support rapid mitigation of cybersecurity threats
  • Ability to communicate clearly during active cybersecurity incidents and maintain accurate documentation under time-sensitive conditions
  • Ability to support after-hours incident response and the required one-hour recall when assigned
  • U.S. Citizenship required
  • Active Secret security clearance required at time of consideration
  • Preferred: experience supporting cybersecurity incident response within Department of Defense or Federal environments
  • Preferred: experience responding to incidents in both unclassified and classified network environments
  • Preferred: experience with SIEM platforms and enterprise security-monitoring capabilities
  • Preferred: experience analyzing endpoint-security, firewall, IDS, IPS, web-security, antispam, or malware-prevention data
  • Preferred: experience supporting evidence collection and preservation during cybersecurity investigations
  • Preferred: experience coordinating incident response with SOC personnel, CSSPs, system owners, network teams, and other technical organizations
  • Preferred: experience operating in a 24x7 cybersecurity operations environment or supporting after-hours incident response
  • Preferred: familiarity with Department of Defense cybersecurity incident-response processes and requirements
  • Preferred: familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments
Core Competencies

Demonstrates expertise in cybersecurity incident response, including containment, eradication, and recovery activities. Proficient in analyzing security information from various cybersecurity tools and coordinating incident response across technical teams and stakeholders.

Highest-signal resume keywords
  • Cybersecurity Incident Response
  • Security Operations Center Operations
  • SIEM Platform Analysis
  • Incident Documentation and Reporting
  • Network and Endpoint Security Monitoring
Hard Skills
  • Cybersecurity Analysis
  • Incident Containment
  • Malware Prevention
  • Intrusion Detection Systems
  • Firewall Management
  • Endpoint Security
  • Security Telemetry Monitoring
  • Evidence Collection
  • Post-Incident Analysis
  • Cyber Defense
Soft Skills
  • Clear Communication
  • Time Management
  • Collaboration
Certifications & Qualifications
  • Active Secret Security Clearance
Industry Keywords
  • NIPRNet
  • SIPRNet
  • Department of Defense
  • Federal Environments
  • Cybersecurity Operations
  • Incident Response Procedures
Tools & Technologies
  • SIEM Platforms
  • Endpoint-Security Tools
  • Firewalls
  • Intrusion Detection Systems
  • Intrusion Prevention Systems
  • Web-Security Systems
  • Antispam Technologies
  • Malware-Prevention Systems
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 150,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Network Based Systems Analyst III
Network Based Systems Analyst III

Solutions³ LLC • Virginia (MN)

On-site
USD 120,000 - 170,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Jobtailor • California (MO)

On-site
USD 95,000 - 125,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance