Senior Tier 2 CIRT Shift Lead

Twenty8 Technology, LLC

Beltsville (MD)

On-site

USD 130,000 - 170,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Twenty8 Technology, LLC in Beltsville, MD is seeking a Tier 2 Cyber Incident Response Team Shift Lead to join the Federal Strategic Cyber Mission program. The role involves leading Tier 2 responses, coordinating with government leadership, and ensuring remediation actions are properly executed in a 24/7 environment.

Requirements include a Bachelor’s degree with 9+ years of experience (or higher degrees with fewer years), active Secret clearance, and certifications such as CISSP, CEH, or CCNP

Qualifications

  • Bachelor’s degree and 9+ years of relevant experience (or advanced degrees with fewer years).
  • Must possess one or more listed security certifications (see below) and maintain certifications.
  • Demonstrated incident response lifecycle experience across multiple environments.
  • Experience with SOAR platforms and automated workflows.
  • Experience with SIEM platforms (Splunk, Sentinel, Elastic, QRadar).
  • Experience with EDR solutions and malware analysis.
  • Knowledge of cloud security monitoring and incident response.
  • Ability to analyze threat intel and adversary TTPs.
  • Familiarity with MITRE ATT&CK and D3FEND.

Responsibilities

  • Detect, classify, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of Tier 1 alerts in a 24x7x365 environment.
  • Analyze logs from multiple sources to identify threats and containment steps.
  • Characterize network traffic to identify anomalous activity.
  • Conduct forensic analysis of hosts, network, and email content.
  • Analyze malware and generate IOCs for threat mitigation.
  • Collaborate with DoS/DISA/ CISA and other CIRTs for coordination.
  • Monitor SOAR platforms and coordinate remediation actions.
  • Coordinate and report incident information to CISA and leadership.

Skills

Incident response
SOAR
SIEM
Threat intelligence
TTPs knowledge

Education

Bachelor’s degree +9 years
Master’s degree +7 years
PhD +4 years
Alternative: +4 years experience

Tools

Splunk
Microsoft Sentinel
Elastic
QRadar
EDR solutions (Defender for Endpoint, Elastic XDR, CrowdStrike)
ServiceNow SOAR
Python
PowerShell
BASH scripting
Azure
KAPE
Volatility
Autopsy
AxiomMagnetForensics
Zimmermann-Tools

Job description

Twenty8 Technology, LLC in Beltsville, MD is seeking a Tier 2 Cyber Incident Response Team Shift Lead to join the Federal Strategic Cyber Mission program. The role involves leading Tier 2 responses, coordinating with government leadership, and ensuring remediation actions are properly executed in a 24/7 environment.

Requirements include a Bachelor’s degree with 9+ years of experience (or higher degrees with fewer years), active Secret clearance, and certifications such as CISSP, CEH, or CCNP

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

24/7 Cyber Incident Response Lead (Tier 2)
24/7 Cyber Incident Response Lead (Tier 2)

AGR LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Cyber Incident Response: Tier 2 Shift Lead
Cyber Incident Response: Tier 2 Shift Lead

AGR, LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Tier 2 Cyber Incident Response (Shift Lead)
Tier 2 Cyber Incident Response (Shift Lead)

AGR, LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Tier 2 Cyber Incident Responder (Shift Lead)
Tier 2 Cyber Incident Responder (Shift Lead)

Twenty8 Technology, LLC • Beltsville (MD)

On-site
USD 130,000 - 170,000
Tier 2 Cyber Incident Lead – Secret Clearance (Onsite)
Tier 2 Cyber Incident Lead – Secret Clearance (Onsite)

Veterans Enterprise Technology Solutions Inc • Beltsville (MD)

On-site
USD 100,000 - 124,000
ON-SITE WORK ONLY
Night Shift: CIRT Tier 2 Analyst — Active Secret
Night Shift: CIRT Tier 2 Analyst — Active Secret

Peraton • Beltsville (MD)

On-site
USD 66,000 - 106,000
Cyber Incident Response Analyst – Tier 1 (24/7 Triage)
Cyber Incident Response Analyst – Tier 1 (24/7 Triage)

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Onsite Tier 2 Cyber Shift Lead - Beltsville
Onsite Tier 2 Cyber Shift Lead - Beltsville

SkyePoint Decisions • Vansville (MD)

On-site
USD 100,000 - 124,000
Certification incentives
PTO
Floating federal holidays
+2
Tier 2 Cybersecurity Shift Lead – Day Onsite, Beltsville
Tier 2 Cybersecurity Shift Lead – Day Onsite, Beltsville

SkyePoint Decisions • Laurel (MS)

On-site
USD 100,000 - 124,000
Certification incentive program
PTO
Floating federal holidays
+2
Tier 2 Cyber Incident Response Lead
Tier 2 Cyber Incident Response Lead

Peraton • Beltsville (MD)

On-site
USD 104,000 - 166,000