Incident Response Analyst - Overnight Shift

rb

Richmond (VA)

Hybrid

USD 90,000 - 120,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work option
Shift differential

Job summary

The Federal Reserve Bank of Richmond is seeking an Incident Response Analyst to triage and respond to security events with minimal oversight. The role emphasizes SOC support, forensics, threat hunting, and developing tools to improve detection and response.

Remote work within a commutable distance is possible, with a shift and strong collaboration across teams. Ideal candidates will have 3+ years of experience, a solid understanding of IT infrastructure, and the ability to communicate complex

Qualifications

  • Bachelor's Degree or equivalent experience with 3+ years of relevant work experience.
  • Knowledge of SIEM/SOAR to analyze security events from multiple sources.
  • Understanding of incident response methodologies and TTPs.
  • Familiarity with cyber threats, vulnerabilities, and attack stages.
  • Ability to communicate complex information clearly in a fast-paced environment.
  • Collaborative mindset with cross-functional teamwork to leverage expertise.

Responsibilities

  • Perform security event triage and analysis with knowledge of threats and techniques.
  • Analyze large volumes of data from multiple sources to identify suspicious activity.
  • Conduct postmortem analysis of traffic flows and network forensics.
  • Perform follow up analysis throughout the incident life cycle.
  • Develop scripts and tools to improve detection and response efficiency.
  • Interface with NIRT customers and stakeholders.

Skills

SIEM/SOAR usage
Incident response
Threat hunting
Forensics
Network forensics
Communication skills

Education

Bachelor's Degree or equivalent experience

Tools

Forensic tools

Job description

Company Federal Reserve Bank of Richmond

When you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic team for our future.

The Federal Reserve System (FRS) National Incident Response Team (NIRT) is seeking an Incident Response Analyst. The NIRT, a national service provider for the FRS, delivers effective intrusion detection, incident response, forensics, security intelligence, threat assessment, and penetration testing services.

The role is for an incident triage and response professional. You will be expected to be able to investigate and respond to security events within the FRS with minimal oversight. The ideal candidate will have some more specialized skills such as Security Operations Center (SOC) support, disk and/or memory forensics, phone forensics, malware analysis, and/or threat hunting skills.

Key Activities
  • Perform security event triage and analysis with knowledge in current security threats and techniques.
  • Analyze a large volume of security event data from multiple sources to identify suspicious and malicious activity.
  • Perform postmortem analysis of traffic flows.
  • Conduct network forensics.
  • Conduct follow up analysis throughout the incident life cycle.
  • Complete projects and tasks associated with security monitoring, detection, and incident response.
  • Analyze all relevant data sources for attack indicators and potential network and host compromises.
  • Respond to different attack vectors such as data exfiltration, DDoS, malware, insider risk, and phishing.
  • Develop scripts and tools to improve the efficiency of incident detection and response processes.
  • Interface with NIRT customers and stakeholders.
Qualifications

Bachelor's Degree or equivalent experience with 3+ years of relevant work experience.

In-depth understanding of a variety of information technologies and information security topics.

Specifically, this should include the following:

  • SIEM/SOAR utilization skills to analyze security events from multiple monitoring and logging sources to identify, investigate and confirm suspicious activity.
  • Knowledge of incident response and handling methodologies.
  • Knowledge of common adversary tactics, techniques, and procedures (TTPs).
  • Knowledge of cyber threats and vulnerabilities.
  • Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those system files).
  • Knowledge to analyze all relevant data sources for attack indicators and potential network and host compromises.
  • Knowledge of current security threats, techniques, and landscape, and a dedicated approach to research current information security landscape.
  • Understanding of IT Infrastructure designs, technologies, products, and services. This should include knowledge of networking protocols, firewall functionality, host and network intrusion detection systems, operating systems, databases, encryption, load balancing, and other technologies.
  • Hold one or more relevant security certifications/degrees and/or commensurate experience.
  • Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means, evaluate information for reliability, validity, and relevance, and function effectively in a dynamic, fast-paced environment.
  • Function in a collaborative environment, seeking continuous consultation with other analysts and experts-both internal and external to the organization-to leverage analytical and technical expertise, think critically and think like threat actors.
  • Ability to develop productive working relationships with a broad range of business and operational area professionals.
Additional Information
How We Work :
  • Location(s): Boston, MA
  • New York, NY
  • Philadelphia, PA
  • Cleveland, OH
  • Richmond, VA
  • Atlanta, GA
  • Chicago, IL
  • St. Louis, MO
  • Minneapolis, MN
  • Kansas City, MO
  • Dallas, TX
  • San Francisco, CA

This position will generally require working three (3) consecutive twelve (12) hour night shifts from 8:00pm - 8:00am ET, followed by four (4) days off. It may be required to shift days to ensure coverage when other team members are out.

This position will have the ability to work remotely, within a commutable distance to a Federal Reserve Bank location.

This position is eligible for a shift differential while working the 3rd shift.

Citizenship Requirements : United States citizenship is required for this position.

Screening Requirements : This position has additional screening requirements due to the information acce

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Analyst - Overnight Shift
Incident Response Analyst - Overnight Shift

Federal Reserve Bank of Boston • Boston (MA)

Hybrid
USD 100,000 - 130,000
Incident Response Analyst - Overnight Shift
Incident Response Analyst - Overnight Shift

Federal Reserve Bank of New York • Richmond (VA), Northern (KY)

On-site
USD 95,000 - 130,000
Remote work option within commutable距离
Remote Incident Response Analyst (Night Shift)
Remote Incident Response Analyst (Night Shift)

rb • Richmond (VA)

Hybrid
USD 90,000 - 120,000
Remote work option
Shift differential
Night-Shift Incident Response Analyst
Night-Shift Incident Response Analyst

Federal Reserve Bank of New York • Richmond (VA), Northern (KY)

Hybrid
USD 95,000 - 130,000
Remote work option within commutable距离
Senior Red Team Cybersecurity Specialist
Senior Red Team Cybersecurity Specialist

Federal Reserve Bank of New York • Richmond (VA)

Hybrid
USD 130,000 - 179,000
Medical benefits
Pension and 401(k) with employer match
Paid time off
+3
Cyber Security Analyst III/Senior
Cyber Security Analyst III/Senior

Federal Reserve Bank of Cleveland • Cleveland (OH)

On-site
USD 100,000 - 150,000
Information Security Specialist
Information Security Specialist

Federal Reserve Bank of New York • New York (NY)

On-site
USD 140,000 - 190,000
Incident Response Lead Specialist, Vice President
Incident Response Lead Specialist, Vice President

MUFG Bank, Ltd. • Tempe (AZ)

Hybrid
USD 126,000 - 180,000
Health benefits
Retirement plans
Educational assistance
+2
FRFS SMO Senior Specialist
FRFS SMO Senior Specialist

Federal Reserve Bank of New York • Boston (MA)

On-site
USD 121,800 - 182,600
Incident Responder I
Incident Responder I

SchoolsFirst Federal Credit Union • United States

Hybrid
USD 58,424 - 87,642