Senior Cyber Incident Analyst

ECS

Arlington (VA)

On-site

USD 170,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS seeks a Senior Cyber Incident Analyst to join our Arlington team, coordinating incident response and threat intelligence for government partners. You will design playbooks, guide mitigation strategies, and deliver clear reports to executives and stakeholders.

The role emphasizes MITRE ATT&CK alignment, risk analysis, and cross-team collaboration to strengthen threat-hunting, incident management, and risk mitigation across federal civilian, state, and local communities.

Qualifications

  • US Citizenship with the ability to obtain and maintain DHS (Suitability) EOD/Public Trust.
  • Active Top Secret Clearance and SCI eligible.
  • On-site 3-5 days per week in Arlington, VA.
  • 10+ years of experience in threat intelligence, cyber security, incident response, or similar role.
  • Ability to analyze and produce reports on active cyber threats (phishing, malware, ransomware).
  • Familiarity with MITRE ATT&CK for incident management and cyber threat intelligence mapping.
  • Strong fundamentals in computer/network concepts; OS and architecture.
  • Ability to develop, document, and maintain SOPs.
  • Excellent written and oral communication skills; capable of producing threat reports.
  • Familiarity with AI/ML concepts for process improvements.
  • Proficiency with Confluence for documentation.

Responsibilities

  • Create written guidance to assist JCDC partners with solutions for active threats.
  • Maintain and develop SOPs to streamline workflows.
  • Analyze and provide recommendations for process improvements.
  • Perform analysis on active cyber incidents and vulnerabilities to guide mitigation.
  • Conduct threat intelligence research to identify and apply risk mitigation strategies.
  • Translate strategic products into actionable formats for diverse stakeholders.
  • Provide tailored vulnerability mitigation recommendations to drive rapid adoption.

Skills

Threat intelligence
Incident response
MITRE ATT&CK
SOP development
Written and oral communication
Analytical research

Education

CTIA
CEH
GREM
GCIH
GCFA

Tools

Confluence
SharePoint

Job description

Senior Cyber Incident Analyst

Everforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington, VA office.

ECS is seeking talented professionals to join our successful and growing team supporting the Cybersecurity and Infrastructure Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC). The JCDC is CISA’s flagship initiative for uniting government, industry, and international partners to proactively defend against cyber threats. Our ECS team is at the center of providing support to JCDC as they continue to plan, share, and respond to cyber threats in real time to support the greater cyber community, and we are looking to grow our team supporting this critical mission.

We are seeking a highly skilled and experienced Sr. Cyber Incident Analyst to join our team.

The successful candidate will foster collaboration and communication within a team of incident coordinators/analysts, develop and implement playbooks/mitigation strategies supporting cyber threats and incident management, have expert-level communications skills that enable stakeholder and customer actions and decision enablement. This role requires a strong understanding of cybersecurity principles, threat intelligence, and risk management.

The ideal candidate will provide incident management support for coordination with stakeholders and executives/government leaders, provide technical guidance for root cause analysis, risk and mitigation strategies and documentation of post-incident analysis/reporting. Familiarity with knowledge management tools such as Confluence or SharePoint to document workflows and communication methods. Including alignment with industry frameworks such as MITRE ATT&CK for incident management and cyber threat intelligence mapping, CVE and DHS/CISA KEV tracking. They will also collaborate with other teams to satisfy customer requirements and develop and implement technical solutions to advance Threat Hunting, Incident Management, and Risk Mitigation capabilities within FCEB, SLTT and Partner communities.

Responsibilities
  • Create written guidance and recommendations to assist JCDC partners with solutions for active and ongoing cyber threats.
  • Maintain and develop SOPs for current processes to streamline workflows.
  • Analyze, develop and provide recommendations for process improvements to the customer.
  • Perform analysis on active cyber incidents, events and vulnerabilities to provide guidance and targeted recommendations for mitigation efforts.
  • Conduct threat intelligence research and analysis to stay up-to-date on emerging technologies, threats and trends. Then apply this knowledge to develop efficient cyber risk mitigation strategies.
  • Oversee the translation of strategic products into clear, practical formats that are tailored to the specific needs and operational constraints of different stakeholder groups, including large and small jurisdictions and critical infrastructure (CI) partners.
  • Provide tailored vulnerability mitigation recommendations and contextualized examples to stakeholders to address implementation challenges and encourage rapid adoption.

Salary Range: $170,000 - $180,000

General Description Of Benefits
Required Skills
  • US Citizenship with the ability to obtain and maintain DHS (Suitability) EOD/ Public Trust
  • Active Top Secret Clearance and SCI eligible
  • On-site 3-5 days per week in Arlington, VA
  • 10+ Years of previous experience in a threat intelligence, cyber security, incident response, or similar role
  • Ability to expertly analyze and produce reports on active cyber threats, including but not limited to, phishing, malware, and ransomware attacks.
  • Proven understanding of cybersecurity frameworks such as MITRE ATT&CK
  • Proven understanding of computer and network fundamentals
  • Strong understanding of computer architecture, operating systems, vulnerabilities, encryption, or other areas of expertise
  • Ability to perform in-depth research tasks and produce written technical summaries to include insights and predictions based on an analytical process
  • Expert level experience with developing, documenting, and maintaining Standard Operating Procedures.
  • Excellent written and oral communication skills
  • Ability to develop cyber threat reporting products that address risks and mitigation strategies using both OSINT and COTS solutions.
  • Familiarity with AI/ML concepts and applications that support Workflow and Incident Management process improvements.
  • Proficiency with Confluence for creating, organizing, maintaining, and collaborating on technical and operational documentation.
Desired Skills
  • Ability to mentor and foster Junior-Mid level Cyber Analysts
  • Familiarity with the .gov Cyber Mission space and legal constraints applicable to civilian Government Agencies (e.g., FISMA)
  • Familiarity with federal reporting mandates and secure-by-design principles
  • Ability to interpret complex cybersecurity topics and effectively communicate or present information to various groups of stakeholders (Executives, SOC, etc.)
  • Field-related certifications such as (CTIA, CEH, GREM, GCIH, GCFA)
  • Experience with tools in both Linux and Windows environments

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Cyber Ops Delivery Lead
Cyber Ops Delivery Lead

ECS • Arlington (VA)

Hybrid
USD 160,000 - 190,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

ECS • Washington

Hybrid
USD 155,000 - 165,000
SOC Tier 2 Analyst
SOC Tier 2 Analyst

ECS • Portland (OR)

On-site
USD 90,000 - 120,000
SOC Tier 1 Analyst
SOC Tier 1 Analyst

ECS • Portland (OR)

On-site
USD 65,000 - 90,000
Cyber Assessment & Authorization / Technical Writer
Cyber Assessment & Authorization / Technical Writer

ECS • Falls Church (VA)

On-site
USD 130,000 - 150,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Sr. Mission Integration Strategist
Sr. Mission Integration Strategist

ECS • Arlington (VA)

On-site
USD 200,000 - 250,000
Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000