Tier 2 Incident Response Analyst

Quantum Sky

Washington (District of Columbia)

Hybrid

USD 110,000 - 120,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision benefits
401(k) match
Paid Time Off
Parental leave

Job summary

Quantum Sky is seeking a Tier 2 Incident Response Analyst to support a law enforcement customer in Washington, DC. You will monitor security tools, triage alerts, and investigate threats as part of the SOC team.

The role offers opportunities to learn, cross-train, and attend external training while working on enterprise network monitoring and phishing threat investigations. The position requires six years in cybersecurity with IR/SOC experience, a Bachelor’s degree, and certifications like

Qualifications

  • Minimum of six (6) years of cybersecurity experience with at least three (4) years in a SOC watch floor analyst or IR role.
  • Bachelor’s Degree or higher in Cybersecurity or related is required.
  • CISSP or CEH certification; additional experience, formal training, certifications, and/or education may be substitutable at the client's discretion.
  • Experience with SIEM (Sumo Logic/Splunk) preferred.
  • Knowledge of attacker tools, techniques and procedures (TTP).
  • Experience with major cloud service provider offerings.
  • Knowledge of malware.
  • Knowledge of Windows and Unix operating systems.
  • Knowledge of common phishing techniques and how to investigate them.
  • Proficiency in technical writing.
  • Able to convey information clearly through speaking, email, and presentations.
  • Comfortable in customer facing environments.
  • Ability to maintain a positive customer service mentality.
  • Clearance: TS/SCI

Responsibilities

  • Utilize security tools to analyze, investigate, and triage security alerts.
  • Monitor customers' environments, including cloud and SaaS for evidence of adversarial activity.
  • Perform in-depth analysis and investigation of high-priority cybersecurity incidents.
  • Use advanced tools for root cause, scope, and impact analysis.
  • Collaborate with threat hunting and threat intelligence teams.
  • Contribute to SOC tool detection content and alerting signatures.
  • Document triage findings and intake reports in the Incident Management System (IMS).
  • Learn new investigative techniques and research emerging threats.
  • Help shape SOC processes and procedures.
  • Provide guidance to Tier 1 SOC Analysts to enhance skills.

Skills

Cybersecurity experience
SOC/IR experience
Technical writing
Customer facing
Communication skills
Phishing investigation
Windows/Unix knowledge
Zero trust principles
Cloud service offerings
Malware knowledge
CISSP/CEH certifications
SIEM experience (Sumo Logic/Splunk)

Education

Bachelor's Degree or higher in Cybersecurity or related

Tools

Sumo Logic
Splunk

Job description

Description

Quantum Sky is searching for a Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington, DC. Our IR analysts form the backbone of our cybersecurity services. You will play a critical role in securing our customers by monitoring our tools, triaging alerts, and investigating potential cyber threats. As a SOC team member, you will also serve as the initial point of contact for cybersecurity incidents, ensuring prompt and effective responses.We provide a supportive environment for you to learn from senior SOC team members, cross-train for other positions, and attend external training. We want to see you grow and improve your cybersecurity skills. Join us and delve into the complexities of monitoring enterprise networks, learn basic incident response techniques, and how to effectively investigate phishing threats against our clients.

Responsibilities:

  • Utilize security tools to analyze, investigate, and triage security alerts
  • Monitor our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize advanced tools, such as host based digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Participate in the development, implementation, and tuning of the SOC tools detection content and alerting signatures.
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research into emerging threats and vulnerabilities to aid their prevention and mitigation
  • Help shape the evolution of processes and procedures of the SOC
  • Provide guidance and mentorship to Tier 1 SOC Analysts to enhance their skills and capabilities
Qualifications

Required:

  • Minimum of six (6) years of cybersecurity experience with at least three (4) years in a SOC watch floor analyst or IR role
  • Bachelor’s Degree or higher in Cybersecurity or related is required
  • CISSP or CEH certification; additional experience, formal training, certifications, and/or education may be substitutable at the client's discretion
  • Experience in some of the following tools and technologies :i.e. SIEM experience required with Sumo Logic/Splunk preferred.
  • Knowledge of common attacker tools, techniques and procedures (TTP)
  • Experience with major cloud service provider offerings
  • Knowledge of malware
  • Knowledge of enterprise architecture including zero trust principles
  • Knowledge of Windows and Unix operating systems
  • Knowledge of common phishing techniques and how to investigate them
  • Proficiency in technical writing
  • Able to accurately and succinctly convey information through speaking, email, and presentations
  • Comfortable in customer facing environments
  • Ability to maintain a positive customer service mentality

Desired:

  • Previous SOC or incident response experience
  • Working knowledge of regex and scripting languages
  • Any SOC analyst relevant certifications such as those from GIAC or CompTIA
  • The initiative to ask for assistance and offer fresh ideas to improve the SOC’s performance

Clearance:

  • TS/SCI Clearance required

Shift:

  • Day shift (6am-2:30pm), and/or swing shift (2:00pm-10:30pm)

Location:

  • This hybrid role is expected to be on the client site at least 2 days per week.
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $110,000-$120,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Intelligence Technical Lead
Cyber Threat Intelligence Technical Lead

Quantum Sky • Homeland Park (MD)

On-site
USD 150,000 - 200,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Systems Administrator II
Systems Administrator II

Quantum Sky • San Angelo (TX)

On-site
USD 50,000 - 60,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Systems Administrator III
Systems Administrator III

Quantum Sky • San Angelo (TX)

On-site
USD 60,000 - 70,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Supply Chain Risk Management Analyst
Supply Chain Risk Management Analyst

Quantum Sky • Washington

On-site
USD 140,000 - 160,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cloud Security Engineer
Cloud Security Engineer

Quantum Sky • Washington

On-site
USD 140,000 - 150,000
Health/Dental/Vision
Senior SIEM Engineer - Splunk
Senior SIEM Engineer - Splunk

Quantum Sky • Washington

On-site
USD 145,000 - 155,000
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000
Cloud Security Engineer (AWS & GCP)
Cloud Security Engineer (AWS & GCP)

Quantum Sky • United States

Remote
USD 115,000 - 140,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Senior Audit Lead
Senior Audit Lead

Quantum Sky • Washington

Hybrid
USD 150,000 - 170,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Platform Network Administrator
Platform Network Administrator

Quantum Sky • McLean (VA)

On-site
USD 190,000 - 205,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4