Incident Response Analyst

12 minutes ago
Contract
Senior
Cybersecurity
Skyepoint Decisions

Skyepoint Decisions

Skyepoint Decisions specializes in providing comprehensive IT solutions for the federal government, focusing on cybersecurity architecture, critical infrastructure operations, and applications development and maintenance to support a secure and mobile ...

Internet Software & Services
51-250
Founded 2009

Description

  • Participate in 24x7 incident response operations, escalation activities, and emergency response procedures.
  • Monitor and analyze security events from SIEM, IDS/IPS, EDR, cloud security, and network monitoring platforms.
  • Investigate suspected cybersecurity incidents to determine scope, impact, severity, and root cause.
  • Perform incident triage, containment, eradication, recovery, and post-incident analysis activities.
  • Correlate logs, alerts, threat intelligence, and forensic evidence to identify malicious activity.
  • Coordinate incident response activities with stakeholders, system owners, cybersecurity teams, and government leadership.
  • Escalate incidents according to government-approved procedures and response playbooks.
  • Document findings, investigative activities, and remediation recommendations in formal incident reports.
  • Develop and maintain indicators of compromise, detection logic, response procedures, workflows, and playbooks.
  • Conduct forensic analysis, support cybersecurity exercises and tabletop simulations, and participate in lessons learned reviews.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related discipline.
  • Minimum 5 years of experience in cybersecurity, incident response, SOC operations, threat detection, or cyber defense.
  • Experience supporting Federal Government cybersecurity programs.
  • Knowledge of the incident response lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and lessons learned.
  • Experience using SIEM platforms such as Splunk.
  • Experience with vulnerability management and security assessment tools.
  • Experience investigating malicious activity, suspicious behaviors, and security events.
  • Strong understanding of Windows and Linux operating systems, network protocols and architecture, security monitoring technologies, EDR, IDS/IPS, and cloud security concepts.
  • Experience developing incident reports and executive summaries.
  • Excellent verbal and written communication skills.
  • Ability to support on-call and incident response activities as required.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.
  • One or more preferred certifications: GCIH, ECIH, Security+, CEH, CySA+, GCFA, CISSP, or OSCP.
  • Experience supporting HHS or other Federal civilian agencies (preferred).
  • Knowledge of NIST SP 800-61 and FISMA compliance requirements (preferred).
  • Experience with FireEye, Palo Alto, Tenable, Qualys, Rapid7, Splunk, and EDR platforms (preferred).
  • Experience conducting malware analysis, threat hunting, or digital forensics (preferred).
  • Experience developing cybersecurity metrics and dashboard reporting (preferred).

Benefits

  • Salary range of $110,000 to $130,000.
  • Certification incentive program.
  • PTO.
  • Floating federal holiday options.
  • Medical insurance options, including HMO and High Deductible plans with HSA and FSA options.
  • Dental, vision, short-term disability, long-term disability, and life insurance coverage.
  • 401(k) with company match.
  • Flexible work environment, including fully remote work.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

27 minutes ago

Client Due Dilligence Analyst (DDQ)

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a DDQ Analyst to support its global sales process by managing client due diligence questionnaires and related compliance workflows for an enterprise SaaS platform.

Cybersecurity
23 hours, 27 minutes ago

Resilience Operations Lead

Commvault is hiring a Resilience Operations (ResOps) Lead to help run and scale its enterprise resilience program across cyber resilience, recovery readiness, critical service resilience, testing, and governance.

Cybersecurity
23 hours, 57 minutes ago

Security Associate - 2nd Shift

Carvana 10K-50K Automotive

Carvana is hiring a Safe and Secure Associate to support gate operations, facility security, and inventory control at its Inspection Center and logistics site.

JIRA
1 day, 22 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers