drjobs Senior Incident Response Analyst

Senior Incident Response Analyst

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Arlington County, VA - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

We connect our employees with some of the best opportunities around.

Time and again our employees tell us that the most important thing we offer is respect. Federal Staffing Solutions puts people to work in all types of jobs. When you work with us you build a relationship with a team of employment professionals in your community who have in turn built professional relationships with the businesses that are hiring.

We are looking for a Senior Incident Response Analyst to work in Arlington VA supporting our client.

Clearance: US Citizen

Salary: $111000

Requirements:

  • Bachelors degree in Computer Science Engineering Information Technology Cyber Security or related field and 1215 years of related experience. Additional years of experience and/or cyber certifications may be considered in lieu of degree.
  • Indepth knowledge of each phase of the Incident Response life cycle
  • Expertise of Operating Systems (Windows/Linux) operations and artifacts
  • Expertise of Enterprise Network Architectures to include routing/switching common protocols (DHCP DNS HTTP etc) and devices (Firewalls Proxies Load Balancers VPN etc)
  • Ability to recognize suspicious activity/events common attacker TTPs and perform logical analysis and research to determine root cause and scope of Incidents
  • Expertise with Cyber Kill Chain and have utilized the ATT&CK Framework
  • Have scripting experience with Python PowerShell and/or Bash
  • Ability to independently prioritize and complete multiple tasks with little to no supervision
  • Flexible and adaptable selfstarter with strong relationshipbuilding skills
  • Strong problemsolving abilities with an analytic and qualitative eye for reasoning
  • Strong verbal and written communication skills
  • Ability to communicate with all levels of audiences (subordinates peers & leadership)
  • Candidates will have at least one of the following certifications: SANS GIAC: GCIH GCIA GCFA GPEN GCFE GREM CISSP OSCP OSCE OSWP

Preferred Qualifications:

  • Experience in cyber government and/or federal law enforcement FISMA systems.


Essential Requirements: US Citizenship is required.

Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation. While performing the duties of this job the employee will regularly sit walk stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally movement that requires twisting at the neck and/or trunk more than the average person squatting/ stooping/kneeling reaching above the head and forward motion will be required. The employee will continuously be required to repeat the same hand arm or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close distance depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist waist to shoulder or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress.


Job Duties:

  • Coordinate investigation and response efforts throughout the Incident Response lifecycle
  • Correlate and and analyze events and data to determine scope of Cyber Incidents
  • Acquire and analyze endpoint and network artifacts volatile memory malicious files/binaries and scripts
  • Recognize attacker tactics techniques and procedures as potential indicators of compromise (IOCs) that can be used to improve monitoring analysis and Incident Response.
  • Develop document and maintain Incident Response process procedures workflows and playbooks
  • Tune and maintain security tools (EDR IDS SIEM etc) to reduce false positives and improve SOC detection capabilities
  • Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports
  • Create metrics and determine Key Performance Indicators to drive maturity of SOC operations
  • Develop security content such as scripts signatures and alerts

Equal Opportunity Employer

Requirements: Bachelors degree in Computer Science, Engineering, Information Technology, Cyber Security, or related field and 12-15 years of related experience. Additional years of experience and/or cyber certifications may be considered in lieu of degree. In-depth knowledge of each phase of the Incident Response life cycle Expertise of Operating Systems (Windows/Linux) operations and artifacts Expertise of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc) Ability to recognize suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents Expertise with Cyber Kill Chain and have utilized the ATT&CK Framework Have scripting experience with Python, PowerShell, and/or Bash Ability to independently prioritize and complete multiple tasks with little to no supervision Flexible and adaptable self-starter with strong relationship-building skills Strong problem-solving abilities with an analytic and qualitative eye for reasoning Strong verbal and written communication skills Ability to communicate with all levels of audiences (subordinates, peers & leadership) Candidates will have at least one of the following certifications: SANS GIAC: GCIH, GCIA, GCFA, GPEN GCFE, GREM CISSP OSCP, OSCE, OSWP Preferred Qualifications: Experience in cyber government, and/or federal law enforcement FISMA systems. Essential Requirements: US Citizenship is required.

Employment Type

Full Time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.