Incident Response & Threat Detection Analyst

Esmcorp

Columbus (OH)

On-site

USD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Enterprise Solutions and Management (ESM) is seeking a Cybersecurity Incident Response & Threat Detection Analyst to support an enterprise-level program within a federal environment. The role involves monitoring SIEM and cybersecurity tools around the clock to detect, analyze, and respond to threats and unauthorized activity across the network.

The ideal candidate has experience with multiple security tools (firewall, IDS/IPS, DLP), is adept at threat intelligence, OSINT, and script development

Qualifications

  • Five (5) years relevant experience.
  • Two (2) years performing root cause analysis of cybersecurity events and incidents.
  • Must maintain CSSP Analyst certification by having one of the listed certs.

Responsibilities

  • Participates in 24x7x365 monitoring of SIEM and cybersecurity tools to detect, analyze, and respond to threats and unauthorized activity across the enterprise network.
  • Reviews security events, logs, and network traffic to identify trends, APTs, and indicators of compromise.
  • Uses threat intelligence and OSINT to stay aware of emerging threats and inform defensive actions.
  • Provides technical analysis and sustainment support for cybersecurity tools and applications.
  • Assists with implementing defense-in-depth signatures and perimeter controls to mitigate network threats.

Skills

SIEM monitoring
Threat detection & incident response
Threat intelligence
Scripting (Python/PowerShell)
Defense-in-depth controls

Education

CSSP Analyst certification (CEH/CFR/GCIA/GCISP)

Tools

Firewall
IDS/IPS
Host-based antivirus
Data Loss Prevention
Vulnerability Management
Forensics

Job description

Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cybersecurity Incident Response & Threat Detection Analyst to support an enterprise-level program within a federal environment.

Job Description and Responsibilities

Participates in 24x7x365 monitoring of SIEM and cybersecurity tools to detect, analyze, and respond to threats and unauthorized activity across the enterprise network. Reviews security events, logs, and network traffic to identify trends, advanced persistent threats (APTs), and other indicators of compromise. Uses threat intelligence and open-source intelligence (OSINT) to maintain awareness of emerging threats and inform defensive actions. Provides technical analysis and sustainment support for cybersecurity tools and applications and assists with implementing defense-in-depth signatures and perimeter controls to mitigate network threats.

Required Knowledge, Skills and Abilities (KSA)
  • Knowledge of SIEM, cybersecurity monitoring tools, network traffic, and security event analysis.
  • Ability to detect, analyze, and respond to cyber threats, including APTs, indicators of compromise, and unauthorized activity.
  • Ability to apply threat intelligence, cybersecurity tools, and defense-in-depth controls to identify and mitigate network threats.
  • Knowledge of at least two types of security tools: Firewall, IDS/IPS, Host based antivirus, Data loss prevention, Vulnerability Management, Forensics, Malware Analysis, Device Hardening.
  • Ability to build scripts and tools to enhance threat detection and incident response capabilities.
  • Preferably in SPL, Python, PowerShell.
Desired KSA
  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations.
  • Candidate must communicate effectively with team members, team lead, management, and government customers.
  • Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision.
Minimum Training, Education, and Certifications
  • Five (5) years relevant experience
  • Two (2) years performing root cause analysis of cybersecurity events and incidents.
  • Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP).
Minimum Clearance
  • Top Secret
Physical Requirements
  • Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Regularly required to stoop, kneel, bend, crouch and lift up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
  • Physical demands associated with this position include extensive walking (including stairs) throughout offices and between buildings. May require use of public transportation, personal or Government vehicle to drive to local and/or remote office locations.
Additional Requirements
  • Other duties as assigned

ESM provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry, disability, genetic information, veteran status, gender identification or any other characteristic protected by state, federal or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Esmcorp • Columbus (OH)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

Esmcorp • Virginia Beach (VA)

On-site
USD 90,000 - 140,000
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Esmcorp • Columbus (OH)

On-site
USD 110,000 - 150,000
SIEM Content Developer
SIEM Content Developer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
Cyber Threat Detection & Incident Response Analyst
Cyber Threat Detection & Incident Response Analyst

Esmcorp • Columbus (OH)

On-site
USD 90,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

Enterprise Solutions & Management • Virginia Beach (VA)

On-site
USD 90,000 - 125,000
Operational Technology Threat Intelligence Analyst
Operational Technology Threat Intelligence Analyst

Esmcorp • Columbus (OH)

On-site
USD 90,000 - 120,000
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

electro soft • Columbus (OH)

On-site
USD 130,000 - 140,000
Sr Security Analyst
Sr Security Analyst

ECS • Shiloh (IL)

On-site
USD 80,000 - 110,000
Software Developer
Software Developer

Enterprise Solutions & Management • Virginia Beach (VA)

On-site
USD 110,000 - 170,000