Incident Response/Security Analyst - Temporary

Anavationllc

Washington (District of Columbia)

On-site

USD 95,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401k with match
Paid leave

Job summary

AnaVation is seeking a Security Administrator to join our on-site team in Washington, DC. You will create, track, monitor and investigate security events/incidents through closure, while administering policies in EDR and SIEM tools like CrowdStrike and Splunk.

We require 4 years of incident response and vulnerability analysis experience, familiarity with TenableSC, Nessus, and conducting vulnerability scans, plus strong communication skills and the ability to obtain Top Secret clearance or

Qualifications

  • Bachelor's degree in a related field or equivalent demonstrated experience.
  • 4 years’ experience as a Security Administrator.
  • Hands-on incident response activities and vulnerability analysis experience.
  • Experience with vulnerability scans and tools like Tenable.
  • Experience with CrowdStrike, TenableSC, Splunk.

Responsibilities

  • Create, track, monitor and investigate security events/incidents through closure.
  • Monitor, maintain and administer policies within EDR and SIEM tools (CrowdStrike, Splunk).
  • Lead remediation of incidents and responses from live threats.
  • Perform incident response analysis based on requirements.
  • Develop reports during and after incidents to mitigate and recover operations.

Skills

Incident response
Vulnerability analysis
SIEM tools
EDR tools
Threat hunting
Security reporting
Network analysis

Education

Bachelor's degree

Tools

CrowdStrike
TenableSC
Splunk
Nessus
Remedy
Wireshark

Job description

Be Challenged and Make a Difference

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.

Description of Task to be Performed:

Responsibilities
  • Create, track, monitor and investigate security related events/incidents through closure.
  • Monitor, maintain and administer policies and rules within EDR and SIEM tools (e.g., Crowdstrike, Splunk).
  • Participate in or lead the remediation of incidents and responses that are generated from live threats against the enterprise.
  • Perform incident response analysis based on investigation requirements.
  • Support and develop reports during and after incidents, which include all actions taken to properly mitigate, recover and return operations to normal operations.
  • Assist in developing and implementing defensive cyber best practice tactics, techniques, and procedures.
  • Assist in conducting vulnerability scans using Tenable SC and Nessus Manager. Manage the applications and conduct vulnerability analysis.
  • Maintain Incident Ticketing tracking system and related tickets within Remedy.
  • Monitor and take action within multiple tools providing security functions such as vulnerability management (e.g., Nessus), configuration management (e.g., Tenable Security Center, IBM BigFix, SCCM, McAfee ePO), endpoint protection (e.g., antivirus, ATP), intrusion detection software and hardware.
  • Perform Splunk queries to examine and query log data from the Enterprise Logging as a Service system.
  • Interacting with GRC tool (e.g., CSAM) to perform daily/weekly vulnerability analysis.
  • Creating and compiling weekly security metrics into dashboards and charts.
  • Flexible with other security related tasks as needed by the customer.
  • This position is on-site in Washington, DC.
Qualifications
  • Bachelor's degree in a related field or equivalent demonstrated experience and knowledge.
  • 4 years’ experience as a Security Administrator.
  • Hands‑on experience conducting incident response activities and vulnerability analysis of various systems, applications, security tools, databases, and networks logs.
  • Performing vulnerability scans with tools such as Tenable.
  • Experience with Crowdstrike, TenableSC, Splunk (experience with comparable tools may be considered).
  • Experience with NIST SP 800‑61 rev2 Computer Security Incident Handling Guide.
  • Excellent oral and written communication skills.
  • Familiarity with multi‑tiered network applications, common ports and protocols used in those communications, the Common Vulnerability System (CVS) and the exploitation mechanisms of common vulnerability types (e.g., buffer overflows, cross‑site‑scripting, SQL injection).
  • Ability to perform online research and comprehend attack signatures while comparing them to network traffic to perform proper analysis of detections.
  • Ability to use common tools such as Wireshark to examine network traffic.
  • Ability to obtain and maintain a Top Secret clearance. Qualified candidates must already have an adjudicated Secret Clearance or higher to be considered for this role.
  • Certifications: Security+ required.
  • Self‑Starter – ability to quickly become competent with new security‑related tools and processes.
  • Ability to conduct Deep Dive analysis to determine root cause assessment of various network scanning agents’ scanning or communication failures.
  • Ability to coordinate remediation strategies with agency’s department technical staff through completion.
  • Familiarity with the various use cases and alignment of data from each tool to various security disciplines in configuration management, vulnerability management, risk management and incident management.
  • Familiarity with encryption technologies used in commercial operating systems, including Public Key Infrastructures, symmetric and asymmetric cryptography, certificate trust stores and the use of key escrow for discovery and legal purpose.
  • Understanding of the role of interactive training such as phishing exercises for assessment of organizational abilities.
  • Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources.
  • Familiarity with information security terminology and being able to develop or select technical training in the discipline of information security geared to an organization.
  • Familiarity with data management and reporting of training data and statistics using common tools such as Microsoft Excel and Word.
Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long‑term and short‑term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
Equal Opportunity Statement

AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Anavationllc • Washington

Hybrid
USD 110,000 - 150,000
Medical insurance
Dental insurance
Disability insurance
+5
Sr. Systems Security Engineer
Sr. Systems Security Engineer

Anavationllc • Washington

On-site
USD 130,000 - 180,000
Medical insurance
Dental insurance
Disability insurance
+5
Cyber Capability Developer
Cyber Capability Developer

AnaVation LLC • Chantilly (VA)

On-site
USD 100,000 - 140,000
Generous medical insurance cost sharing
100% company paid dental insurance
401k plan with generous match
+1
Security Infrastructure & Exposure Engineer
Security Infrastructure & Exposure Engineer

AnaVation LLC • Reston (VA)

On-site
USD 140,000 - 190,000
Generous medical insurance
Dental insurance
Vision insurance
+4
Sr. Security Specialist
Sr. Security Specialist

Nava • Washington

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
Security Infrastructure & Exposure Engineer
Security Infrastructure & Exposure Engineer

AnaVation, LLC • Reston (VA)

On-site
USD 120,000 - 180,000
Medical insurance (employee & depend.
Dental insurance (company paid)
Disability insurance (company paid)
+4
Cyber Vulnerability Analyst
Cyber Vulnerability Analyst

Nava • Reston (VA), Northern (KY)

Hybrid
USD 100,000 - 140,000
Medical insurance sharing
Dental insurance fully paid
Disability insurance fully paid
+6
Cyber Security Officer, Senior
Cyber Security Officer, Senior

AnaVation, LLC • Reston (VA)

On-site
USD 125,000 - 180,000
Medical insurance
Dental insurance
Disability insurance
+5
Cyber Security Officer, Senior
Cyber Security Officer, Senior

Anavationllc • Reston (VA)

On-site
USD 140,000 - 190,000
Generous medical insurance
Dental, vision, life insurance
401k with match
+2
Cyber Security Officer, Senior
Cyber Security Officer, Senior

AnaVation LLC • Reston (VA)

On-site
USD 150,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+3