Tier 2 Cyber Incident Response (Shift Lead)

AGR, LLC

Beltsville (MD)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ICS (a REDHAWK company) seeks an experienced Tier 2 Cyber Incident Response Team Shift Lead in Beltsville, MD to join the Federal Strategic Cyber Mission program. You will lead Tier 2 shift operations, review tickets for accuracy, and coordinate with CIRT Watch Officers and government leadership on remediation actions.

Responsibilities include advanced log analysis across multiple sources, malware analysis, IOC generation, and collaboration with DoS and CISA.

Qualifications

  • Bachelor’s degree or higher with relevant incident response experience.
  • Experience across the incident response lifecycle and 24x7 operations.
  • Active security clearance or ability to obtain one (Secret or higher).
  • Experience with SOAR platforms and automated response workflows.

Responsibilities

  • Detect, classify, process, and report cyber security events and incidents.
  • Perform in-depth analysis of Tier 1 triage and requests.
  • Analyze logs from hosts, EDR, firewalls, IDS, and servers to contain threats.
  • Characterize network traffic to identify anomalies and threats.
  • Collaborate with DoS/CISA and other CIRTs on incidents and remediation.
  • Monitor SOAR platform, tickets, and SOP workflows.

Skills

Incident response
SOAR platforms
SIEM operations
EDR tools
Threat hunting
CISA coordination

Education

Bachelor’s degree
Master’s degree

Tools

Splunk
Microsoft Sentinel
Elastic
QRadar
ServiceNow SOAR

Job description

Job Description

Location: Beltsville, Maryland.

Clearance: Secret

ICS (a REDHAWK company) is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join the Federal Strategic Cyber Mission program.

In this role, you will:
  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
Additionally, as a Tier 2 Shift Lead you will:
  • Review all Tier 2 shift tickets for accuracy and completeness
  • Coordinate with CIRT Watch Officers and government leadership on remediation actions
  • Provide technical and procedural improvement recommendations to CIRT leadership
  • Assist with Tier 2 candidate technical interviews as required
  • Ensure coordinated remediation actions are operating properly
Minimum Qualifications
  • Bachelor’s degree and minimum of 9 years of relevant experience; or, Master’s degree with minimum of 7 years; or PhD with 4 years. In lieu of a degree, 4 years of additional experience may be considered.
  • Must possess, or obtain prior to start date, at least one of the following certifications. Continued certification is required as a condition of employment:
  • CASP+ CE; CCNA Cyber Ops; CCNA-Security; CCNP Security; CEH; CFR; CHFI; CISA;CISSP (or Associate); CISSP-ISSAP; CISSP-ISSEP; CySA+; GCED; GCFA; GCIH; SCYBER
  • Demonstrated experience across the incident response lifecycle.
  • Experience with SOAR platforms and automated response workflows (e.g., ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, Elastic, QRadar).
  • Experience with Endpoint Detection and Response (EDR) solutions (e.g., Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating indicators of compromise (IOCs) and tracking advanced persistent threat (APT) actors.
  • Ability to analyze cyber threat intelligence and understand adversary tactics, techniques, and procedures (TTPs).
  • Knowledge of malware analysis techniques.
  • Familiarity with MITRE ATT&CK and D3FEND frameworks.
  • Active Secret security clearance required at start.
Preferred Qualifications:
  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Experience using Microsoft Azure access and identity management.
  • Proficiency in Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience using digital forensics collection and analysis tools (e.g. Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience using ServiceNow SOAR for ticketing and automated response.
  • Experience using Python, PowerShell and BASH scripting languages.
  • Proficiency in cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Tier 2 Cyber Incident Responder (Shift Lead)
Tier 2 Cyber Incident Responder (Shift Lead)

Twenty8 Technology, LLC • Beltsville (MD)

On-site
USD 130,000 - 170,000
Tier 2 Shift Lead- Secret Clearance
Tier 2 Shift Lead- Secret Clearance

Veterans Enterprise Technology Solutions Inc • Beltsville (MD)

On-site
USD 100,000 - 124,000
ON-SITE WORK ONLY
Cyber Incident Response: Tier 2 Shift Lead
Cyber Incident Response: Tier 2 Shift Lead

AGR, LLC • Beltsville (MD)

On-site
USD 120,000 - 180,000
Incident Responder Shift Lead - Tier 2
Incident Responder Shift Lead - Tier 2

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 158,000
Incident Responder Shift Lead - Tier 2
Incident Responder Shift Lead - Tier 2

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 158,000
Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MD
Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MD

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
CIRT Tier 1 Analyst / Active Secret
CIRT Tier 1 Analyst / Active Secret

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Cyber Defense Analyst Suitland, MD Top Secret/SCI R-00190180
Cyber Defense Analyst Suitland, MD Top Secret/SCI R-00190180

ESR Healthcare • Suitland (MD)

On-site
USD 120,000 - 160,000
Referral bonus $2,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Tier 2 Cybersecurity Engineer
Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC • Houston (TX)

On-site
USD 110,000 - 150,000
Health insurance
Retirement plan
Disability insurance
+5