Tier II Incident Response Analyst
$85,000–$110,000 year
RemoteUnited States
Job Summary
Analyze malicious code, packet captures, and artifacts while recognizing suspicious activity to determine incident root cause and scope. Drive implementation of new tools, frameworks, and automation to improve SOC operations and process efficiencies. Mentor analysts and instill industry best practices in incident response, case management, and knowledge sharing. Propose automated alerts for emerging threats and develop strategies to fill logging gaps. Develop and present status updates to the Federal Team, establishing trust with customer stakeholders. Requires US citizenship, a bachelor's degree, and 5+ years of incident response experience, with CISSP and SANS GCIH/GCIA certifications required upon start. Located in Frederick, MD, this role supports a government contract with a salary range of $85,000 - $110,000.
Required Qualifications
- US Citizenship
- Bachelor's degree in computer science, Engineering, Information Technology, Cybersecurity, or related field
- 4 years of experience in incident detection and response, malware analysis, or cyber forensics
- Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques, and procedures (TTPs)
- Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework
- Expertise of Operating Systems (Windows/Linux) operations and artifacts
- In-depth knowledge of each phase of the Incident Response life cycle
- 5+ years of intrusion detection and/or incident handling experience
- Strong experience with Splunk, FireEye, Microsoft MDE (or similar tool)
- Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise
- Mature understanding of industry accepted standards for incident response actions and best practices related to SOC operations
- Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings
- Strong analytical and troubleshooting skills
- CISSP and SANS GCIH or GCIA required upon start
Desired Qualifications
- Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities
- Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization including prior experience performing large-scale incident response
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.