Tier 2 Cyber Incident Response Analyst & Lead

Leidos

Ashburn (VA)

On-site

USD 87,000 - 157,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking a Tier 2 Cyber Incident Response Analyst to join the CBP Security Operations Center (SOC). The role focuses on cyber incident analysis, containment, remediation, and root cause analysis to protect DHS CBP networks and information systems.

The candidate will lead incident response activities, mentor junior staff, and work with stakeholders to implement remediation plans, leveraging MITRE ATT&CK techniques and open-source threat intel.

Qualifications

  • Bachelor’s degree (or equivalent) in a science or engineering field, IT, or Cybersecurity related field.
  • A minimum of 4 years of experience in the areas of cyber incident response, remediation, malware analysis, or computer forensics.
  • Advanced knowledge of the Incident Response Lifecycle and applicability to various types of incidents and situations.
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses.
  • Experience creating new processes, playbooks, and SOPs for new tools and workflows. Prior relevant experience should be in the areas of incident detection and response, malware analysis, or computer forensics.
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.
  • Experience running cyber incident investigations with emphasis on attention to detail, adept communication skills, and adherence to defined escalation paths.

Responsibilities

  • Shift schedule: 7am-7pm, Sunday-Tuesday, every other Wednesday.
  • Utilize EDR tools, log analysis (firewall, proxy, IDS, Windows & Linux) and network forensics to investigate activity.
  • Conduct in-depth analysis on hosts and networks, forensic analysis, log analysis, and triage in support of incident response.
  • Recognize attacker and APT activity, and indicators of compromise to improve monitoring and response.
  • Apply cyber incident response knowledge to proactive threat hunting and MITRE ATT&CK mapping.
  • Develop security content, scripts, tools, or methods to enhance investigations.
  • Lead incident response activities and mentor junior SOC staff.
  • Coordinate remediation plans with stakeholders and communicate findings clearly.
  • Stay up-to-date with open-source intelligence and current cyber threats.

Skills

Incident response
Malware analysis
Forensics
Log analysis
Threat hunting
Python scripting
PowerShell scripting
Communication skills

Education

Bachelor’s degree or equivalent in science/engineering/IT/Cybersecurity

Tools

EDR tools
Network forensics
Packet capture
Firewall log analysis

Job description

Leidos is seeking a Tier 2 Cyber Incident Response Analyst to join the CBP Security Operations Center (SOC). The role focuses on cyber incident analysis, containment, remediation, and root cause analysis to protect DHS CBP networks and information systems.

The candidate will lead incident response activities, mentor junior staff, and work with stakeholders to implement remediation plans, leveraging MITRE ATT&CK techniques and open-source threat intel.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Tier 2 Cyber Incident Responder & Analyst
Senior Tier 2 Cyber Incident Responder & Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 87,000 - 157,000
Tier 2 SOC Analyst: Cyber Defense & Incident Response
Tier 2 SOC Analyst: Cyber Defense & Incident Response

Leidos Inc • Alexandria (VA)

On-site
USD 87,000 - 157,000
Senior Incident Response Lead – SOC & Cyber Defense
Senior Incident Response Lead – SOC & Cyber Defense

Leidos Inc • Washington

On-site
USD 108,000 - 195,000
Senior Cyber Incident Response Analyst (Remote)
Senior Cyber Incident Response Analyst (Remote)

Leidos • United States

On-site
USD 150,000 - 190,000
Senior Incident Response Lead | SOC & Cyber Defense
Senior Incident Response Lead | SOC & Cyber Defense

Via Logic LLC • Washington

On-site
USD 108,000 - 195,000
Senior Incident Response Lead — Cyber Defense SOC
Senior Incident Response Lead — Cyber Defense SOC

Via Logic LLC • Ashburn (VA)

On-site
USD 108,000 - 195,000
Remote Tier 2 SOC Analyst - Advanced Cyber Defense
Remote Tier 2 SOC Analyst - Advanced Cyber Defense

Koitecc Solutions • Alexandria (VA)

On-site
USD 87,000 - 157,000
Cyber Defense SOC Analyst – Incident Response Lead (TS/SCI)
Cyber Defense SOC Analyst – Incident Response Lead (TS/SCI)

Leidos Inc • Fort Belvoir (VA)

On-site
USD 87,000 - 157,000
Remote Incident Response Analyst – Cyber Defense
Remote Incident Response Analyst – Cyber Defense

Leidos Inc • Alexandria (VA)

On-site
USD 87,000 - 157,000
Senior Tier 2 SOC Analyst - 24/7 Cyber Defense
Senior Tier 2 SOC Analyst - 24/7 Cyber Defense

Leidos • Seaside (OR)

On-site
USD 87,000 - 157,000