Cyber Incident Response Analyst
Tasks
- Analyze malware behavior
- Build incident timelines and reconstruction
- Communicate with leadership and affected agencies
- Conduct host based forensics
- Conduct post-incident reviews and lessons learned
- Coordinate incident response actions and documentation
- Correlate host network and intelligence data
- Maintain 247 readiness via on call rotation
- Map adversary TTPs to MITRE ATT&CK
- Perform incident response triage and containment
- Perform memory disk and file system analysis
- Produce incident reports and executive summaries
- Recommend detection improvements hardening and mitigation
- Serve as Incident Commander during cybersecurity events
- Update playbooks and procedures
- Validate alerts from SIEM IDS IPS EDR and monitoring tools
Perks/Benefits
Skills/Tech-stack
Case management | Corelight | CrowdStrike | Cyware CSAP | Detection Systems | Digital forensics | EDR | Google SecOps | Google Threat Intelligence | Gravwell | Host-based Forensics | Incident Response | Intrusion Detection | Intrusion Prevention | Intrusion Prevention Systems | Intrusion detection systems | Linux forensics | Log Analysis | Malware analysis | Memory Forensics | Microsoft Sentinel | Mitre Attack | NetWitness | Network Monitoring | Packet Analysis | Prevention systems | Recorded Future | SIEM | SentinelOne | Threat Intelligence | Threat hunting | Threat modeling | VirusTotal | Windows forensics
Education
N/A
Related jobs
-
Team Lead, Security Operations Center (SOC) - 2nd Shift USD 121K-152KCyber Security | Detection engineering | EDR | Evidence Based Investigation | Incident Response401(k) plan matching | Bereavement leave | Employee assistance program | Employee discount program | Health and wellbeing benefitsSenior-level Full TimeRemote - Nationwide, United States R4h ago
-
Target Digital Network Analyst USD 115K-205KAdversary Tactics Techniques and Procedures | Adversary tactics | Anomaly Detection | Computer Network Exploitation | Computer networkTravel for cyber tabletop exercisesMid-level Full TimeLinthicum, MD4h ago
-
Automated Enrichment Workflows | Automated enrichment | Correlation rules | Data Normalization | Detection engineeringHybrid work | Occasional after-hours supportMid-level ContractAustin, United States6h ago
-
TARGET DIGITAL NETWORK ANALYST - Network Exploitation - 5+ yrs of Experience - TS/SCI w/Poly clearance is required - IW A USD 203K-209KCommercial Intrusion Detection Tools | Cryptanalysis | Detection tools | Digital forensics | Executable File Analysis401k retirement plan | ADandD insurance | Dental insurance | Federal Holidays | Floating holidaysMid-level Full TimeLinthicum Heights, United States7h ago
-
Senior Cyber Security Analyst USD 137K-244K800-53A | ACAS | Continuous Monitoring | Control Assessment | Control ImplementationSenior-level Full TimeUSA-VA-Virginia Beach7h ago
-
Cloud Security | Cybersecurity | Data Architecture | Hybrid Data | Hybrid Data ArchitectureOnsite work 5 days per weekSenior-level Full TimeLas Vegas, Nevada, United States7h ago
-
Manager - AI SOC USD 134K-265KApplication Programming | Application Programming Interface | Automation | Automation and response | Case managementMid-level Full TimeChicago, Illinois, United States8h ago
-
Automation | Correlation rules | Event Correlation | Event collector | Event managementSenior-level Full TimeArlington/Rosslyn, Virginia, United States8h ago
-
Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance) USD 102K-188KAlerting | Correlation searches | Dashboard Development | Data Modeling | Log ParsingSenior-level Full TimeArlington/Rosslyn, Virginia, United States8h ago
-
Access Control | Access Control Lists | Alert analysis | Coverage Validation | Detection Coverage ValidationOnsite work | Travel opportunitiesMid-level Full TimeArlington/Rosslyn, Virginia, United States8h ago
-
Event Analyst II, Third Party Risk Management USD 55K-95KCyber Compliance | Cybersecurity | Data Analysis | Executive reporting | FFIEC401k matching | Dental insurance | Employee assistance program | Employee discounts | Employee stock purchase planEntry-level Full Time601 S. Tryon Street, NC R8h ago
-
Enforcement Detection Analyst, YouTube, Trust and Safety USD 132K-190KCause analysis | Data Analysis | Data labeling | Incident Response | Language ModelsMid-level Full TimeSan Bruno, CA, USA9h ago
-
AI Security Analyst | Camden Corporate Office USD 128K-237KAI/ML | Access Control | Application Firewall | Automation | AzureDisaster recovery exercise support | Off-hours support | Periodic travelSenior-level Full TimeHouston, TX, United States15h ago
-
Senior Corporate Security Engineer USD 180K-240KAPI Integration | AWS | Access Control | Access Management | AtlassianSenior-level Full TimeRemote, United States R18h ago
-
Product Security Engineer USD 208K-312KAPI Security | Access Control | Advanced Security | Authentication & Authorization | Bug BountyMid-level Full TimeRemote - United States R18h ago
-
Security Engineer, Cloud USD 208K-312KAWS | AWS IAM | AWS Security | Access Management | CI/CDEvent support | Flexible time off | Healthcare | Mentorship | Remote workSenior-level Full TimeRemote - United States R18h ago
-
AI Security Operations Engineer USD 136K-204KAI Governance | AI Security | AWS | Agentic AI | AutomationHealth benefits | Paid Holidays | Paid leaves | Paid vacation | Retirement contribution 401k planSenior-level Full TimeUS - Gaithersburg - MD, United …20h ago
-
VP Security Guardian, Product Security USD 120K-202KAI Security | Access Management | Agentic AI | Agentic AI security | Application Security401k match | Dental insurance | Employee assistance program | Employee networks | Flexible work/life supportExecutive-level Full TimeQuincy, Massachusetts, United States20h ago
-
Engineer IV, Cybersecurity USD 180K-205KAWS | Access Management | Artificial Intelligence | Azure | DevSecOps401k match | Dental insurance | Disability insurance | Life insurance | Medical insuranceSenior-level Full TimeMD - Gaither Rd., Rockville Corp …20h ago
-
Temporary Senior Associate, Cyber Engineering USD 56K-84KAPIs | AWS | Azure | Containers | Incident ResponseFlexible scheduleSenior-level Full Time TemporaryUSA-NC-Virtual, United States R20h ago
-
Security Engineer and Firewall SME USD 77K-176KAWS Network | AWS Network Firewall | Alerting | Ansible | App-IDDependent care | Hybrid work option | Paid leave | Professional development | Remote work optionSenior-level Full TimeUndisclosed Location - USA, DC, Washington, …20h ago
-
Staff Product Security Engineer USD 169K-224KAI Security | Access Control | CI/CD | Cause analysis | Data FlowsFlexible-hybrid work | On site requirement 60 percent | Work from home optionSenior-level Full TimeMenlo Park, CA21h ago
-
Cyber Security Analyst (On-Site) USD 94K-103KAntivirus | Awareness Training | Cause analysis | Detection and prevention | Encryption401k matching | Certification programs | Employee assistance program | Employer-paid life insurance | Family medical dental vision coverageMid-level Full TimeSnoqualmie, WA, US22h ago
-
AI Security | AWS | Application Security | Application Testing | Architecture Review401k match | Counseling membership | Flexible time off | Life insurance | Long-term disabilitySenior-level Full Time-REMOTE, USA- R23h ago
-
Security Operations Engineer USD 150K-193K800-53 | AWS | Azure | CI/CD | Cause analysis401k with employer match | Federal holidays off | Flexible PTO | Flexible spending account | Health, dental, vision insuranceSenior-level Full TimePatrick SFB, FL or Arlington, VA1d ago