Incident Response Analyst

Cyber Synergy Consulting Group

Washington (District of Columbia)

Hybrid

USD 75,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience with enterprise incident response tools and a good understanding of federal cybersecurity frameworks. Remote work is permitted with occasional on-site duties in the Washington, D.C. area.

Qualifications

  • Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.) is a plus.
  • Certifications such as Security+, CySA+, CEH, GCIH preferred.
  • Knowledge of scripting languages (Python, PowerShell) is beneficial.

Responsibilities

  • Perform initial triage of security events across various platforms.
  • Conduct incident investigations including forensics and log analysis.
  • Provide daily updates on incident status and investigative steps.
  • Contribute to improvement of incident response processes.

Skills

CrowdStrike Falcon (EDR)
FireEye/Trellix
Splunk
NetWitness
Magnet AXIOM
Strong understanding of adversary techniques
Ability to document investigations

Education

2–5+ years of experience in cybersecurity operations

Tools

ServiceNow
Packet analysis tools (Wireshark)

Job description

Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)

Location: Remote with occasional on-site (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)

We are seeking an experienced Incident Response Analyst to support Task 4 – Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.

The ideal candidate has hands-on experience with enterprise IR tooling: CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM – and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB).

Key Responsibilities
  • Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.
  • Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.
  • Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.
  • Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.
  • Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.
  • Support containment, eradication, and recovery efforts aligned to federal IR procedures.
  • Participate in tabletop exercises, readiness assessments, and operational continuity testing.
  • Monitor and manage the Incident Response Team (IRT) mailbox; elevate urgent items within required SLAs.
  • Assist with audit support, evidence gathering, and post-incident reviews.
  • Contribute to continuous improvement of incident response processes and playbooks.
Required Qualifications
  • 2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response.
  • Direct hands‑on experience with IR tools, including:
    • CrowdStrike Falcon (EDR)
    • FireEye/Trellix (HX, Helix, or equivalent)
    • Splunk (SIEM, dashboards, search queries)
    • NetWitness (network forensics, packet analysis)
    • Magnet AXIOM (host forensics)
  • Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts.
  • Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance.
  • Ability to clearly document investigations and communicate findings to technical and non‑technical audiences.
  • Eligibility to obtain and maintain a Public Trust clearance.
Preferred Qualifications
  • Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).
  • Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.
  • Experience performing threat hunting across EDR, SIEM, and NDR tools.
  • Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).
  • Experience with ServiceNow or similar ticketing platforms.
Work Schedule & Expectations
  • Core hours: 7:00 AM – 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.
  • Participation in on‑call rotations may be required.
  • Remote work permitted with reliable connectivity and camera‑enabled participation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 150,000
Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital Global Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
Tier 2 Cyber Incident Responder (Shift Lead)
Tier 2 Cyber Incident Responder (Shift Lead)

Twenty8 Technology, LLC • Beltsville (MD)

On-site
USD 130,000 - 170,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Tetrad Digital Integrity LLC • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Incident Response (IR) and Forensics Lead (Q Clearance)
Incident Response (IR) and Forensics Lead (Q Clearance)

ShorePoint • Germantown (MD)

On-site
USD 150,000 - 190,000
PTO 144 hours
11 holidays
Health insurance coverage 85%
+3
Part-Time Tier 2 Incident Response Analyst (Weekend Nights)
Part-Time Tier 2 Incident Response Analyst (Weekend Nights)

Tyto Athene, LLC • Washington

Hybrid
USD 85,000 - 120,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MANTECH • McLean (VA)

On-site
USD 90,000 - 130,000
Cyber Defense Incident Responder - Swing Shift
Cyber Defense Incident Responder - Swing Shift

ASRC Federal • Quantico (VA)

On-site
USD 90,000 - 120,000
Health care
401(k)
Education assistance
+1
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000