Senior Incident Response Analyst
HybridArlington, Virginia, United States
Job Summary
Lead and coordinate cyber incident response activities across the full lifecycle, including investigation, containment, eradication, and recovery. Analyze security events, logs, network traffic, and forensic artifacts to determine incident scope, root cause, and impact. Identify adversary tactics, techniques, and procedures (TTPs) to develop indicators of compromise and enhance threat detection. Develop, maintain, and enhance incident response processes, playbooks, workflows, and standard operating procedures. Configure, tune, and optimize security technologies, including SIEM, EDR, IDS/IPS, and monitoring tools to improve detection accuracy. Create detection content, including correlation rules, use cases, signatures, alerts, and automation scripts to strengthen SOC capabilities. Document investigations, response activities, and findings within case management systems, producing clear incident reports and after-action documentation. Establish and track SOC performance metrics and key performance indicators to measure operational effectiveness and support continuous improvement. This role supports a mission-critical government program within a hybrid environment in the Arlington, VA area.
Required Qualifications
- Ability to obtain Public Trust clearance and successfully complete the EOD process
- Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field
- 12–15 years of relevant experience
- At least one of the following certifications: GIAC: GCIH, GCIA, GCFA, GCFE, GREM, or GPEN, CISSP, OSCP, OSCE, or OSWP
- Technical hands-on experience in the areas of incident detection and response, malware analysis, or computer forensics
- Expertise with Windows and Linux operating systems, enterprise networking, common protocols, and security infrastructure (firewalls, proxies, VPNs, load balancers)
- Demonstrated experience investigating cyber incidents, performing root cause analysis, identifying attacker TTPs, and leveraging frameworks such as MITRE ATT&CK and the Cyber Kill Chain
- Proficiency in Python, PowerShell, Bash, or similar scripting languages to support security automation and incident response
- US citizenship or lawful permanent resident of the United States
Desired Qualifications
- Experience in cyber government, and/or federal law enforcement FISMA systems
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.