TDI logo
TDIPosted 1 month ago

Senior Incident Response Analyst

HybridArlington, Virginia, United States

Full TimeSenior LevelBachelors DegreeSmallCybersecurity

Job Summary

Lead and coordinate cyber incident response activities across the full lifecycle, including investigation, containment, eradication, and recovery. Analyze security events, logs, network traffic, and forensic artifacts to determine incident scope, root cause, and impact. Identify adversary tactics, techniques, and procedures (TTPs) to develop indicators of compromise and enhance threat detection. Develop, maintain, and enhance incident response processes, playbooks, workflows, and standard operating procedures. Configure, tune, and optimize security technologies, including SIEM, EDR, IDS/IPS, and monitoring tools to improve detection accuracy. Create detection content, including correlation rules, use cases, signatures, alerts, and automation scripts to strengthen SOC capabilities. Document investigations, response activities, and findings within case management systems, producing clear incident reports and after-action documentation. Establish and track SOC performance metrics and key performance indicators to measure operational effectiveness and support continuous improvement. This role supports a mission-critical government program within a hybrid environment in the Arlington, VA area.

Required Qualifications

  • Ability to obtain Public Trust clearance and successfully complete the EOD process
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field
  • 12–15 years of relevant experience
  • At least one of the following certifications: GIAC: GCIH, GCIA, GCFA, GCFE, GREM, or GPEN, CISSP, OSCP, OSCE, or OSWP
  • Technical hands-on experience in the areas of incident detection and response, malware analysis, or computer forensics
  • Expertise with Windows and Linux operating systems, enterprise networking, common protocols, and security infrastructure (firewalls, proxies, VPNs, load balancers)
  • Demonstrated experience investigating cyber incidents, performing root cause analysis, identifying attacker TTPs, and leveraging frameworks such as MITRE ATT&CK and the Cyber Kill Chain
  • Proficiency in Python, PowerShell, Bash, or similar scripting languages to support security automation and incident response
  • US citizenship or lawful permanent resident of the United States

Desired Qualifications

  • Experience in cyber government, and/or federal law enforcement FISMA systems

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce