Senior Incident Response Analyst - Tier 2 (Hybrid)

cFocus Software Incorporated

Washington (District of Columbia)

Hybrid

USD 110,000 - 135,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role is Hybrid with onsite in Washington, DC, and requires a Public Trust clearance.

You will perform in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates should have 3+ years IR experience, strong scripting in Python/PowerShell, and knowledge of Velociraptor, Splunk ES and Microsoft Sentinel.

Qualifications

  • Active Public Trust clearance required.
  • BS in Computer Science, IT, or related field.
  • 3+ years in an incident response role.
  • 2+ years scripting with Python and PowerShell for decoding obfuscated payloads.
  • 2 years in live triage, log correlation, and detection rule refinement with Velociraptor, Splunk ES and Sentinel.
  • 1 year in federal incident handling guidelines per NIST CSWP-29 and SP-800-61.
  • Active SANS GCIH or GCIA certification.

Skills

Active Public Trust clearance
IR experience
Python & PowerShell scripting
Live triage & log correlation
NIST incident handling familiarity

Education

BS in Computer Science/IT/related

Tools

Python
PowerShell
Velociraptor
Splunk ES
Microsoft Sentinel

Job description

cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role is Hybrid with onsite in Washington, DC, and requires a Public Trust clearance.

You will perform in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates should have 3+ years IR experience, strong scripting in Python/PowerShell, and knowledge of Velociraptor, Splunk ES and Microsoft Sentinel.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Incident Response Analyst
AOUSC - Incident Response Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 135,000
Hybrid Tier 2 Incident Response Analyst | SOC & Mentorship
Hybrid Tier 2 Incident Response Analyst | SOC & Mentorship

Tyto Athene, LLC • Washington

Hybrid
USD 85,000 - 120,000
Hybrid Insider Threat Analyst - Public Trust Clearance
Hybrid Insider Threat Analyst - Public Trust Clearance

cFocus Software Incorporated • Washington

Hybrid
USD 80,000 - 100,000
Incident Responder Shift Lead - Tier 2
Incident Responder Shift Lead - Tier 2

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 158,000
Tier 2 Cyber Incident Response (Shift Lead)
Tier 2 Cyber Incident Response (Shift Lead)

AGR, LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Cybersecurity Triage Analyst – Hybrid, Public Trust
Cybersecurity Triage Analyst – Hybrid, Public Trust

cFocus Software Incorporated • Washington

Hybrid
USD 70,000 - 100,000
Threat Detection Engineer - Hybrid (Public Trust)
Threat Detection Engineer - Hybrid (Public Trust)

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 140,000
AOUSC - Insider Threat Analyst
AOUSC - Insider Threat Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 80,000 - 100,000
Senior Incident Response Analyst (Tier 3) – On‑Site Quantico
Senior Incident Response Analyst (Tier 3) – On‑Site Quantico

RMC - Resource Management Concepts Inc. • Quantico (VA)

On-site
USD 135,000 - 150,000
Relocation assistance
Paid vacation and holidays
Healthcare plans
+1
Incident Responder Shift Lead - Tier 2
Incident Responder Shift Lead - Tier 2

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 158,000