- Assess cybersecurity incidents to investigate, validate, respond, and recover the environment, and perform additional activities such as root cause analysis and resilience recommendations. Serve as the primary escalation point for the SOC in the event of an incident.
- Communicate and coordinate with internal and external teams during incidents and breaches.
- Implement, and document IR processes, procedures, playbooks, and guidelines.
- Participate in breach and attack simulation and purple teaming exercises to stress test the incident response plans and playbooks.
- Analyze emerging threats to improve and maintain the detection and response capabilities of the organization.
- Apply knowledge of monitoring, analyzing, detecting, and responding to cyber events to develop clever, efficient methods and technology to detect all types of threat.
- Document specifications, playbooks, and detections - not as an afterthought, but through the whole process.
- Work with developers to build security automation workflows, enrichments, and mitigations.
- Evaluate policies and procedures and recommend updates to management as appropriate.
- Bachelor's degree or equivalent practical experience in incident response, computer science, cybersecurity, information technology, software engineering, information systems, or computer engineering.
- Programming and scripting languages, preferably Python and PowerShell.
- Dedicated monitoring and analysis of cyber security events.
- Excellent written and oral communication skills.
- Self-motivated and able to work in an independent manner.
- Preference given for CCE, CCFE, CEH, CPT, CREA, GCFE, GCFA, GCIH, GCIA GIAC, Splunk Core, OSCP, SANS Security 500 Series or other industry standard equivalent but not required.
- Public Trust
- Must be US Citizen
-
Incident Response Analyst
3 weeks ago
OneZero Solutions Washington, United StatesJob Description · Job DescriptionWe are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technic ...
-
Cyber Incident Response Analyst
3 weeks ago
cFocus Software Incorporated Washington, United StatesJob Description · Job DescriptioncFocus Software seeks a Cyber Incident Response Analyst (Senior) to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship and the ability to obtain a Publi ...
-
Cyber Incident Response Analyst
3 weeks ago
cFocus Software Incorporated Washington, United StatesJob Description · Job DescriptioncFocus Software seeks a Cyber Incident Response Analyst (Mid-Level) to join our program supporting to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship ...
-
Incident Response Analyst
1 month ago
Computer World Services (CWS)Corporation Washington, United States OTHER· Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reporte ...
-
Incident Response Analyst
1 month ago
Computer World Services (CWS)Corporation Washington, United States OTHER· Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported ...
-
Incident Response Analyst
4 weeks ago
Computer World Services (CWS)Corporation Washington, United States OTHER· Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported ...
-
Cyber Incident Response Analyst
6 days ago
Peraton Arlington, United States Full timeResponsibilities · Peraton is currently hiring a Cyber Incident Response Analyst for its' Federal Strategic Cyber sector. · Location: On-site, Arlington, VA · In this role, you will have the following duties:Identify, log, categorize, perform initial triage, assign to other team ...
-
Detection and Response Analyst
1 month ago
Rapid7 Arlington, United States Full timeDetection & Response Analyst · We are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As a Detection & Response Analyst, you will utilize Rapid7's advanced tools to investigate and triage security events and work side- ...
-
OMW Consulting San Francisco, United States PermanentCyber Incident Response Analyst Washington, DC - On site TS Clearance - SCI eligible $140k-$150k I am partnered with a leading Cyber security consultancy who is looking to hire a Cyber Incident Response Analyst to be based on site in DC for a federal customer. To be considered fo ...
-
Tier 2 Cyber Incident Response Analyst
6 days ago
Critical Solutions Washington, United StatesJob Description · Job DescriptionTier 2 Cyber Incident Response Analyst - Shift 1 (M-F 6AM - 2:30PM ET) - (w/ active TS)Washington, DC · Full-time · Clearance Required: Top Secret w/ SCI eligibility · Shift 1: Monday - Friday 6am - 2:30pm EST · JOB DESCRIPTION · Critical Solution ...
-
Base One Technologies San Francisco, United States PermanentOur DC Metro based client is looking for Senior Incident Response Analyst . If you are qualified for this position, please email your updated resume in word format to Primary Responsibilities · • In-depth knowledge of each phase of the Incident Response life cycle · • Expertise o ...
-
Incident Response Analyst
3 weeks ago
Super Systems Inc Arlington, United StatesHybrid · - 2x a week onsite (Tuesday and Thursdays) Sometimes there may not be an onsite need. · **Role Description**: · - Support the development of staff schedules and staffing forecasts for approval · - Ensure shift members follow the appropriate incident escalation and report ...
-
Ozs13068 Incident Response Analyst
5 days ago
Dhara Consulting Group Washington, United StatesToday · - Top Secret/SCI · - Unspecified · - Unspecified · - Washington, DC** (ON-SITE/OFFICE)** · **Position Title**: Incident Response Analyst · **Location**: Hybrid. One day a week onsite: Washington DC - St. Elizebeth's Campus - Coast Guard HQ · **Clearance**: TS/SCI · **Prog ...
-
Cyber Incident Response Analyst
3 weeks ago
cFocus Software Incorporated Washington, United StatescFocus Software seeks a Cyber Incident Response Analyst (Mid-Level) to join our program supporting to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship and the ability to obtain a Publ ...
-
Responsible AI Operations Research Analyst
3 weeks ago
Booz Allen Hamilton Washington, United StatesResponsible AI Operations Research AnalystThe Opportunity: · Do you love solving problems? Are you passionate about making Responsible AI more practical and actionable? · On our Responsible AI team, you'll work to bring AI Ethics research and Governance to life as a Responsible A ...
-
Incident Response Analyst with OT/ICS/SCADA
4 days ago
Peraton Arlington, United States Full timeResponsibilities · Peraton is currently seeking an experienced Incident Response Analyst with OT/ICS/SCADA experience for its' Federal Strategic Cyber program in Arlington, VA. · Location: On-site role in Arlington, VA. Ideal candidate needs to be amenable to travel, approximate ...
-
Critical Solutions Washington, United States Part timeJob Description · Job DescriptionTier 2 Cyber Incident Response Analyst - (w/ active TS) - PART TIME Weekend NightsWashington, DC · Part-time, On-site · Clearance Required:Top Secret · Shift Schedule: Weekend Nights, 10 pm - 10 am EST · JOB DESCRIPTION · Critical Solutions is see ...
-
Incident Response Analyst with OT/ICS/SCADA
2 weeks ago
Peraton Arlington, United StatesResponsibilities · Peraton is currently seeking an experienced Incident Response Analyst with OT/ICS/SCADA experience for its' Federal Strategic Cyber program in Arlington, VA. · Location: On-site role in Arlington, VA. Ideal candidate needs to be amenable to travel, approximate ...
-
Tier 3 Incident Response Analyst
1 week ago
MindPoint Group Washington, United StatesText code IRT3 to to apply · Since 2009, MindPoint Group has been the cybersecurity firm of choice for the most security-conscious US federal agencies and commercial enterprises. · We're proud to be one of Inc. 5000's fastest-growing companies in the country. With several 'Best P ...
-
Digital Forensic Incident Response Analyst
3 weeks ago
Booz Allen Hamilton Washington, United StatesJob Number: R0186940 · Digital Forensic Incident Response AnalystKey Role:Collect, analyze, and present digital evidence in support of computer investigations. Apply basic principles, theories, and concepts and limited industry knowledge. Solve routine problems of limited scope a ...
Incident Response Analyst - Washington, United States - Computer World Services (CWS)Corporation
![Default job background](https://contents.bebee.com/public/img/bg-user-ex-1.jpg)
Description
Job DescriptionThe mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported and collected; performing applied research and essential long-term research; developing tools for risk measurement and monitoring; performing other related services; making the results of the activities of the OFR available to financial regulatory agencies; and assisting such member agencies in determining the types of formats of data authorized to be collected by such member agencies.
The Incident Response Analyst is an on-call role providing day-to-day incident response across the OFRAE and JADE networks.
This includes investigating alerts from the SOC, third party notifications, and other security tools; working with Enterprise System owners to remediate immediate threats and incidents; knowledge capture and investigation tracking documentation to maintain knowledge on the team; monitor and notify of security tool outages and issues; participate in process enhancements through after-action reports, tabletop exercises, and peer consulting as needed.
The role is to advise and build automations and playbooks to further grow the response capability of the team.
This is a junior role that requires a basic understanding of incident response and security practices.As part of a growing team this role will have the ability to leverage and work with new capabilities as they are deployed including deception infrastructure, continuous penetration testing, data loss prevention (DLP), and machine learning capabilities.
The analyst should have basic experience in ticketing workflow, understanding of Endpoint Detection and Response (EDR) and endpoint data investigations, security investigation, and other security tool alerting workflow and pivoting.
This role is expected to contribute to maturing the overall IR and security capability.Key Tasks and Responsibilities
This is a remote/work from home role.
Computer World Services is an affirmative action and equal employment opportunity employer.
Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations.
Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations.
If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Aaron McClellan in Human Resources at 314.###.
#### or