Cyber Incident Response Analyst SME
$131,300–$237,350 year
On-site · Alexandria, Virginia, United States
Job Summary
The Cyber Incident Response Analyst SME role involves monitoring, detecting, analyzing, mitigating, and responding to cyber threats across the enterprise. Key responsibilities include leading incident detection and response activities, coordinating efforts through the enterprise incident tracking system, providing expert investigative support for complex security incidents, and ensuring timely containment and reporting of incidents. Candidates should possess at least 12 years of cybersecurity incident response experience, strong knowledge of cybersecurity standards and frameworks, and proficiency with various cybersecurity tools and SIEM systems. A Bachelor's degree and a Top Secret with SCI eligibility security clearance are required.
Required Qualifications
- Top Secret with SCI eligibility security clearance
- Bachelor degree or higher from an accredited college or university OR Offerings listed in DoD 8140 Training Repository OR GCFA or GCIA
- Minimum of 12 years of experience in cybersecurity incident response
- Strong knowledge of cybersecurity frameworks and standards (e.g., NIST, ISO)
- Proficiency in using cybersecurity tools and technologies for monitoring and incident response
- Experience with network security monitoring, intrusion detection systems, and security information and event management (SIEM) tools
- Excellent analytical and problem-solving skills
- Strong communication and coordination skills to work effectively with various teams
Desired Qualifications
- Active TS/SCI
- Master's degree in Cybersecurity or a related field
- Certifications such as CISSP, CISM, CEH, or GIAC
- Experience with cloud security and familiarity with AWS GovCloud/NIPRNet, SC2S AWS Secret Region Cloud for SIPRNet, and C2S AWS Cloud for JWICS environments
- Knowledge of automation tools and techniques, including AI chatbots and Robotic Process Automation (RPA)
- Experience in designing and implementing disaster recovery and continuity of operations plans
- Familiarity with customer relationship management and use case intake processes
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.