Senior Incident Response Analyst

tetraddigitalintegrityllc

Arlington (VA)

Hybrid

USD 120,000 - 135,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tetrad Digital Integrity (TDI) seeks a Senior Incident Response Analyst to join our SOC and help monitor, detect, investigate, and respond to cyber threats in a large-scale government program. The role requires onsite 2 days weekly for Arlington, VA residents, while others may work fully remotely.

You will lead IR activities, analyze events, and develop IOCs and playbooks, leveraging MITRE ATT&CK. Strong scripting and Windows/Linux expertise are essential for automation and containment.

Qualifications

  • Bachelor's degree in CS, Engineering, IT, Cybersecurity, or related field.
  • 12–15 years of relevant incident response experience.
  • Hands-on incident detection/response, malware analysis, or computer forensics.
  • Expertise with Windows and Linux OS, enterprise networking, and security infrastructure.
  • Experience investigating incidents, root-cause analysis, attacker TTPs; MITRE ATT&CK and Cyber Kill Chain.
  • Proficiency in Python, PowerShell, Bash for automation.

Responsibilities

  • Lead and coordinate incident response across the full lifecycle.
  • Analyze events, logs, network traffic, and telemetry to determine scope and impact.
  • Identify TTPs and develop IOCs to improve detection.
  • Develop and maintain incident response playbooks and SOPs.
  • Configure and optimize SIEM, EDR, IDS/IPS and monitoring tools.
  • Create detection content, rules, and automation scripts.
  • Document investigations and produce incident reports and after-action documentation.
  • Establish and track SOC KPIs for continuous improvement.

Skills

Incident response
SOC
Python
PowerShell
Bash
MITRE ATT&CK
Windows
Linux
Networking
Scripting

Education

Bachelor's degree in CS/Engineering/IT/Cybersecurity

Tools

SIEM
EDR
IDS/IPS
Firewalls
Proxies
VPNs
Load balancers

Job description

Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!

TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will help monitor, detect, investigate, and respond to cybersecurity threats affecting a large‑scale enterprise environment while supporting coordinated incident response across multiple organizations.

This role requires two onsite days per week for employees residing within 50 miles of Arlington, VA. Employees residing outside the 50-mile radius are eligible to work fully remote.

Responsibilities
  • Lead and coordinate cyber incident response activities across the full Incident Response lifecycle, including investigation, containment, eradication, and recovery.
  • Analyze security events, logs, network traffic, endpoint telemetry, and forensic artifacts to determine the scope, root cause, and impact of cyber incidents.
  • Identify adversary tactics, techniques, and procedures (TTPs) and develop indicators of compromise (IOCs) to improve threat detection and response.
  • Develop, maintain, and enhance Incident Response processes, playbooks, workflows, and standard operating procedures (SOPs).
  • Configure, tune, and optimize security technologies, including SIEM, EDR, IDS/IPS, and related monitoring tools, to improve detection accuracy and reduce false positives.
  • Create and maintain detection content, including correlation rules, use cases, signatures, alerts, and automation scripts to strengthen SOC monitoring capabilities.
  • Document investigations, response activities, and findings within case management systems, producing clear incident reports and after‑action documentation.
  • Establish and track SOC performance metrics and key performance indicators (KPIs) to measure operational effectiveness and support continuous improvement.
Qualifications
  • Ability to obtain Public Trust clearance and successfully complete the EOD process.
  • Candidates must possess at least one of the following certifications: GIAC: GCIH, GCIA, GCFA, GCFE, GREM, or GPEN, CISSP, OSCP, OSCE, or OSWP.
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field and 12-15 years of relevant experience.
  • Must have technical hands‑on experience in the areas of incident detection and response, malware analysis, or computer forensics.
  • Expertise with Windows and Linux operating systems, enterprise networking, common protocols, and security infrastructure (firewalls, proxies, VPNs, load balancers).
  • Demonstrated experience investigating cyber incidents, performing root cause analysis, identifying attacker TTPs, and leveraging frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Proficiency in Python, PowerShell, Bash, or similar scripting languages to support security automation and incident response.
Preferred Qualifications
  • Experience in cyber government, and/or federal law enforcement FISMA systems.
Pay Range

The anticipated salary range for this position is $120,000 - $135,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.

TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.

"TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws."

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead — Remote (Govt Program)
Senior Incident Response Lead — Remote (Govt Program)

tetraddigitalintegrityllc • Arlington (VA)

Hybrid
USD 120,000 - 135,000
Information Assurance Lead
Information Assurance Lead

tetraddigitalintegrityllc • Washington

On-site
USD 160,000 - 180,000
Information Assurance Lead
Information Assurance Lead

Tetrad Digital Integrity LLC • Washington

On-site
USD 160,000 - 180,000
Information Assurance Lead
Information Assurance Lead

Tetrad-Digital-Integrity-LL • Washington

On-site
USD 160,000 - 180,000
Cybersecurity Awareness Training Coordinator
Cybersecurity Awareness Training Coordinator

Tetrad Digital Integrity LLC • Washington

Hybrid
USD 75,000 - 80,000
Cybersecurity Awareness Training Coordinator
Cybersecurity Awareness Training Coordinator

Tetrad-Digital-Integrity-LL • Washington

Hybrid
USD 75,000 - 80,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Leidos Inc • Arlington (VA)

On-site
USD 131,000 - 238,000
Competitive compensation
Health and wellness programs
Paid leave
+1
Network Administrator, 3rd Shift
Network Administrator, 3rd Shift

tetraddigitalintegrityllc • Arlington (VA)

On-site
USD 80,000 - 84,000
Lead Software Engineer, Data & DevSecOps
Lead Software Engineer, Data & DevSecOps

tetraddigitalintegrityllc • Arlington (VA)

On-site
USD 130,000 - 145,000
Data Analyst
Data Analyst

Tetrad Digital Integrity LLC • Washington

On-site
USD 130,000 - 145,000