Tier 3 Incident Response Lead

Quantum Sky

Washington (District of Columbia)

Hybrid

USD 170,000 - 180,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid Time Off
Parental leave

Job summary

Quantum Sky is seeking a Tier 3 Incident Response Lead to conduct in-depth analyses and respond to cyber threats for clients. You will coordinate incident response, lead cross-functional teams, and mentor junior SOC staff from the Washington, DC area.

The role requires strong experience in incident response, SIEM/EDR, and forensics with certifications such as CISSP/CEH preferred. Hybrid work with on-site client support in Washington, DC is expected.

Qualifications

  • Bachelor’s degree or equivalent in a relevant field.
  • 8+ years of cyber security experience.
  • 3+ years of incident response experience.
  • 3+ years of SIEM experience.
  • 2+ years of EDR experience.
  • Experience with open-source forensic tools.
  • Proficient in Python scripting & regex.

Responsibilities

  • Lead cross-functional teams to analyze and investigate high-priority cybersecurity incidents.
  • Analyze, investigate, and triage security alerts using security tools.
  • Coordinate monitoring of customer environments (cloud and SaaS) for adversarial activity.
  • Use forensics and malware analysis to identify root causes, scope, and impact.
  • Mentor Tier 1/2 SOC analysts to enhance skills.
  • Develop or tune detection rules and collaborate with engineering to implement them.
  • Document triage findings and intake reports in IMS.

Skills

Incident response
SIEM
EDR
Python
Regular expressions
Open-source tools
Mentoring

Education

Bachelor’s degree
CISSP Certification
CEH Certification

Tools

CISSP

Job description

Description

Quantum Sky is searching for aTier 3 Incident Response Lead. You will play a critical role in conducting in-depth analyses and responding to incidents from cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for other analysts, helping guide them through more complex and high-priority incidents.

Responsibilities:

  • Lead cross-functional teams to perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize security tools to analyze, investigate, and triage security alerts
  • Coordinate the monitoring of our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Utilize advanced tools, such as digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Serve as the primary incident point of contact with law enforcement, third-party vendors, and other external parties
  • Conduct post-incident analysis and lessons learned to identify improvement opportunities
  • Develop or tune detection rules or signatures to improve the effectiveness of security monitoring and collaborate with engineering teams to implement them
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research on emerging threats and vulnerabilities to aid their prevention and mitigation
  • Assist in developing and implementing initiatives that will enhance the SOC’s performance (e.g., SOPs, playbooks, capability deployments)
  • Escalate SOC performance issues or risks to management
  • Provide guidance and mentorship to Tier 1 and Tier 2 SOC Analysts to enhance their skills and capabilities
Qualifications

Required:

  • Bachelor’s Degree or an equivalent combination of formal education and experience in relevant field.
  • 8 or more years of cyber security experience.
  • 8 or more years of experience in investigating network and endpoint architecture
  • CISSP and CEH certifications or equivalent.
  • 3 or more years of incident response experience.
  • 3 or more years of SIEM experience.
  • 2 or more years of Endpoint Detection Response (EDR) experience.
  • Demonstrated competency in opensource industry standard forensic tools and suites
  • Experience with operational security, including security operations center (SOC), incident response, malware analysis, or IDS and IPS analyses
  • Understanding of scripting languages such as Python and regular expressions

Desired:

  • CISSP - Certified Information Systems Security Professional
  • GCFA - GIAC Certified Forensic Analyst
  • GCFE - GIAC Certified Forensic Examiner
  • GREM - GIAC Reverse Engineering Malware

Location:

  • This is hybrid position with requirements to report to the client site in Washington, DC for incident support as needed
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $170,000-$180,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst (Tier 2)
SOC Analyst (Tier 2)

Quantum Sky • Washington

On-site
USD 125,000 - 135,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000
Cyber Security Analyst Level II
Cyber Security Analyst Level II

Quantum Sky • Warner Robins (GA)

On-site
USD 75,000 - 85,000
Senior Audit Lead
Senior Audit Lead

Quantum Sky • Washington

Hybrid
USD 150,000 - 170,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
ISSM / Security Automation Engineer
ISSM / Security Automation Engineer

Tyto Athene, LLC • Northern (KY)

Hybrid
USD 175,000 - 190,000
Health/Dental/Vision
401(k) match
Paid Time Off
Cloud Security Engineer
Cloud Security Engineer

Quantum Sky • Washington

Hybrid
USD 140,000 - 150,000
Health/Dental/Vision
Senior Information Security Analyst
Senior Information Security Analyst

Quantum Sky • Oceanside (CA)

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cybersecurity Analyst - Journeyman
Cybersecurity Analyst - Journeyman

Quantum Sky • Colorado Springs (CO)

On-site
USD 80,000 - 95,000
Health/Dental/Vision
401(k) match
Flexible Time Off
+2
Engagement Manager
Engagement Manager

Quantum Sky • United States

Remote
USD 110,000 - 130,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Senior Quantum Algorithm Developer
Senior Quantum Algorithm Developer

Quantum Sky • Reston (VA)

On-site
USD 190,000 - 230,000