Jobs
>
Washington, D.C.

    Tier 2 Cyber Incident Response Analyst - Washington, United States - Critical Solutions

    Default job background
    Description

    Job Description

    Job DescriptionTier 2 Cyber Incident Response Analyst - Shift 1 (M-F 6AM - 2:30PM ET) - (w/ active TS)

    Washington, DC

    Full-time

    Clearance Required: Top Secret w/ SCI eligibility

    Shift 1: Monday - Friday 6am - 2:30pm EST

    JOB DESCRIPTION
    Critical Solutions is seeking a Tier 2 Cyber Incident Response Analyst to support threat monitoring, detection, event analysis, and incident reporting. The Security Operations Center is a 24/7 environment. You will be responsible for monitoring enterprise networks and systems, detecting events, and reporting on any and all threats that are directed against those systems regardless of their classification level or type.

    Typically, the client's sensor grid acquires millions of events per day and events are analyzed and categorized in accordance with the Cyber Security Incident Response Plan. The Incident Response Analyst will provide the client with a fully comprehensive array of analytical activities in support of external threat monitoring, detection, event analysis, and incident reporting efforts including presentation reviews, internal and external threat reporting, analysis of inbound and outbound public internet traffic, suspicious e-mail messages, administering access request to specific public sites, communicating and coordinating the characterization of events and the response.

    PRIMARY ROLES AND RESPONSIBILITIES:

    • Provides support for complex computer network exploitation and defense techniques to include deterring, identifying, and investigating computer and network intrusions; providing incident response and remediation support;
    • Performing comprehensive computer surveillance/monitoring, identifying vulnerabilities; developing secure network designs and protection strategies, and audits of information security infrastructure.
    • Provides technical support for continuous monitoring, computer exploitation and reconnaissance; target mapping and profiling; and, network decoy and deception operations in support of computer intrusion defense operations.
    • Provides technical support for forensics services to include evidence seizure, computer forensic analysis, and data recovery, in support of computer crime investigation.
    • Researches and maintains proficiency in open and closed source computer exploitation tools, attack techniques, procedures, and trends.
    • Performs research into emerging threat sources and develops threat profiles.
    • Provides technical support for a comprehensive risk management program identifying mission-critical processes and systems; current and projected threats; and system vulnerabilities.

    BASIC QUALIFICATIONS:

    • Active Top Secret with SCI eligibility required*
    • Be able to commute onsite and support Shift 1, Monday through Friday 6 AM - 2:30 PM EST
    • Minimum of four (4) years of general work experience and three (3) years of relevant experience in functional responsibility
    • Bachelor's Degree, or an equivalent combination of formal education, experience
    • Experience in the following tools and technologies:
      • BRO IDS
      • Splunk SIEM
      • RSA Netwitness
      • FireEye
      • Sourcefire (Snort)
      • CrowdStrike EDR
      • Fidelis XPS
    • Strong analytical and organizational skills
    • Strong verbal and written communication skills
    • Experience with MS Word and other MS Office Applications

    PREFERRED QUALIFICATIONS:

    • Experience with securing various environments preferred
    • Experience working a SOC and doing incident response is preferred
    • Experience and education preferred in eCPPT, OSCP, GCFW, GCIH, other relevant IT security certifications, or advanced vendor certifications such as Splunk Certified Architect or SourceFire Certified Administrator; Security+, GSEC, or other relevant IT security product certifications such as Tenable Certified Nessus Auditor, or SnortCP; CISSP, CISM, or ISO 27001

    SHIFT:

    • This role will be Monday through Friday from 6 AM to 2:30 PM EST.

    LOCATION:

    • This is a hybrid role with expectations of being on the client site a few days a week.
    • Must be willing and able to commute to Washington, DC

    ADDITIONAL INFORMATION:

    CLEARANCE REQUIREMENT: Must possess an active DoD Top Secret Clearance . In addition, selected candidate must undergo background investigation (BI) and finger printing by the federal agency and successfully pass the preceding to qualify for the position. US CITIZENSHIP IS REQUIRED


    CRITICAL SOLUTIONS PAY AND BENEFITS:

    Salary range $75,000 - $95,000. The salary range for this position represent the typical salary range for this job level and this does not guarantee a specific salary. Compensation is based upon multiple factors such as responsibilities of the job, education, experience, knowledge, skills, certifications, and other requirements.

    BENEFIT SNAPSHOT: 100% premium coverage for Medical, Dental, Vision, and Life Insurance, Supplemental Insurance, 401K matching, Flexible Time Off (PTO/Holidays), Higher Education/Training Reimbursement, and more.

    Job Posted by ApplicantPro


  • OneZero Solutions Washington, United States

    We are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technically proficient and technically c ...


  • Computer World Services (CWS)Corporation Washington DC, United States

    · Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data report ...


  • OneZero Solutions Washington, United States

    Job Description · Job DescriptionWe are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technic ...


  • RedTrace Technologies Inc Washington, United States

    Job Description · Job DescriptionSECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY · ***POSITION REQUIRES US CITIZENSHIP*** · Company Overview: As a Cybersecurity, Information Technology, and Management Consulting firm focused on assisting our commercial and U.S. Intellige ...


  • cFocus Software Incorporated Washington, United States

    Job Description · Job DescriptioncFocus Software seeks a Cyber Incident Response Analyst (Senior) to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship and the ability to obtain a Publi ...


  • cFocus Software Incorporated Washington, United States

    Job Description · Job DescriptioncFocus Software seeks a Cyber Incident Response Analyst (Mid-Level) to join our program supporting to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship ...


  • Booz Allen Hamilton Washington, United States Full time

    Job Number: R0186940 · Digital Forensic Incident Response AnalystKey Role: · Collect, analyze, and present digital evidence in support of computer investigations. Apply basic principles, theories, and concepts and limited industry knowledge. Solve routine problems of limited scop ...


  • Peraton Arlington, United States Full time

    Responsibilities · Peraton is currently hiring a Cyber Incident Response Analyst for its' Federal Strategic Cyber sector. · Location: On-site, Arlington, VA · In this role, you will have the following duties:Identify, log, categorize, perform initial triage, assign to other team ...


  • MindPoint Group Washington, United States

    MindPoint Group is seeking a Security Operations Center (SOC) Analyst that will collaborate with members of the SOC team to improve procedures for the SOC to enhance coordination and incident response operations. You must be willing to work in a 24x7x365 SOC environment demonstra ...


  • Computer World Services (CWS)Corporation Washington, United States OTHER

    · Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported ...


  • Computer World Services (CWS)Corporation Washington, United States OTHER

    · Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported ...


  • Computer World Services (CWS)Corporation Washington, United States OTHER

    · Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reported ...


  • MindPoint Group Washington, United States

    MindPoint Group is seeking a Tier 2 Incident Response Analyst to support threat monitoring, detection, event analysis, and incident reporting. The Security Operations Center is a 24/7 environment. You will be responsible for monitoring enterprise networks and systems, detecting e ...


  • Sikich LLP Washington, United States

    **Description**: · **Incident Response Analyst (II)** · **What to expect when you join the Sikich family** · Team members at Sikich have a lot in common while also being part of a rich and diverse group of contributors, creating a distinct and thriving culture. Chief among our co ...


  • Computer World Services (CWS)Corporation Washington, United States OTHER

    · Job Description · The mission of the OFR is to support the Financial Stability Oversight Council (FSOC) in promoting financial stability by: collecting data on behalf of FSOC; providing such data to FSOC and member agencies; standardizing the types and formats of data reporte ...


  • Gridiron IT Washington, United States

    **Role Description**: · - Support the development of staff schedules and staffing forecasts for approval · - Ensure shift members follow the appropriate incident escalation and reporting procedures · - Ingest, triage, prioritize, assign, track, document, and manage incidents and ...


  • Rapid7 Arlington, United States Full time

    Detection & Response Analyst · We are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As a Detection & Response Analyst, you will utilize Rapid7's advanced tools to investigate and triage security events and work side- ...


  • XOR Security Arlington, United States

    Job Title: Incident Response Analyst · Location: 1110 N. Glebe Rd. Arlington, Virginia 22201 · Clearance Level: Top Secret · SUMMARY: · XOR Security, An Agile Defense Company is currently seeking an Incident Response Analyst with advanced skillsets in Digital Forensic & Incid ...


  • Super Systems Inc Arlington, United States

    Hybrid · - 2x a week onsite (Tuesday and Thursdays) Sometimes there may not be an onsite need. · **Role Description**: · - Support the development of staff schedules and staffing forecasts for approval · - Ensure shift members follow the appropriate incident escalation and report ...


  • Peraton Arlington, United States Full time

    Responsibilities · Peraton is currently seeking an experienced Incident Response Analyst with OT/ICS/SCADA experience for its' Federal Strategic Cyber program in Arlington, VA. · Location: On-site role in Arlington, VA. Ideal candidate needs to be amenable to travel, approximate ...