Lead Incident Response Analyst

4 weeks ago


Washington, United States Tyto Athene, LLC Full time

Tyto Athene is searching for a Incident Response Analyst to support weekend shift activities. We believe our Security Operations Center (SOC) analysts form the backbone of our cybersecurity services. Take your career to the next level and join us as a Tier 2 SOC Analyst. You will play a critical role in conducting in-depth analyses and responding to incidents of potential cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for junior analysts, helping guide them through more complex and high-priority incidents.


One of the most critical tasks for our Tier 2 SOC Analysts is learning. We provide a supportive environment for you to learn from senior SOC team members, cross-train with other positions, and attend external training.



Responsibilities:

  • Utilize security tools to analyze, investigate, and triage security alerts
  • Monitor our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize advanced tools, such as host based digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Participate in the development, implementation, and tuning of the SOC tools detection content and alerting signatures.
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research into emerging threats and vulnerabilities to aid their prevention and mitigation
  • Help shape the evolution of processes and procedures of the SOC
  • Provide guidance and mentorship to Tier 1 SOC Analysts to enhance their skills and capabilities



Required:

  • Minimum of six (6) years of cybersecurity experience with at least three (3) years in a SOC watch floor analyst or IR role
  • Bachelor’s Degree or higher in Cybersecurity or related is preferred
  • CISSP or CEH certification; additional experience, formal training, certifications, and/or education may be substitutable at the client's discretion
  • Experience in some of the following tools and technologies:i.e. SIEM experience required with Sumo Logic/Splunk preferred.
  • Knowledge of common attacker tools, techniques and procedures (TTP)
  • Experience with major cloud service provider offerings
  • Knowledge of malware
  • Knowledge of enterprise architecture including zero trust principles
  • Knowledge of Windows and Unix operating systems
  • Knowledge of common phishing techniques and how to investigate them
  • Proficiency in technical writing
  • Able to accurately and succinctly convey information through speaking, email, and presentations
  • Comfortable in customer facing environments
  • Ability to maintain a positive customer service mentality



Desired:

  • Previous SOC or incident response experience
  • Working knowledge of regex and scripting languages
  • Any SOC analyst relevant certifications such as those from GIAC or CompTIA
  • The initiative to ask for assistance and offer fresh ideas to improve the SOC’s performance



Shift: Tier 2 weekdays (M-F), 2nd shift (currently 2 pm-10 pm). Minimum 2 days on-site at DOJ.



Clearance: TS/SCI required



Location: This hybrid role is expected to be on the client site at least 2 days per week.



  • Washington, United States Axxum Technologies Full time

    Job DescriptionJob DescriptionIncident Response Analyst Responsibilities:Provide effective front-line support leveraging service desk ticketing system, telephone, and email communicationsSupport the service desk shift lead in operational activities Interact with the government Program Manager for the service desk regarding operational issuesEnsure timely...


  • Washington, Washington, D.C., United States OneZero Solutions Full time

    Job DescriptionTier 2 Deputy IR LeadAs a key member of our Incident Response team, you will utilize state-of-the-art technologies to perform hunt and investigative activity, examining endpoint and network-based data. Your expertise in malware analysis, host and network forensics, log analysis, and triage will help improve incident response and...


  • Washington, Washington, D.C., United States Leidos Holding Full time

    Leidos is a Fortune 500 innovation company addressing national security and health challenges.Job DescriptionWe are seeking a Senior Cybersecurity Analyst with strong incident response background to join our DISA GSM-O program at the Pentagon.This role will work core hours with some flexibility and requires an active TS/SCI security clearance prior to...


  • Washington, United States Ankura Full time

    Cybersecurity Analyst Job DescriptionWe are looking for an experienced Cybersecurity Analyst to join our Cybersecurity Practice at Ankura. As a key member of our team, you will contribute to addressing critical information security challenges faced by our clients.About the Role:This position involves participating in security incident investigations,...


  • Washington, United States Palo Alto Networks Full time

    About the RolePalo Alto Networks is seeking an experienced Cybersecurity Incident Response Lead to join our team. In this role, you will be responsible for leading high-profile incident response engagements, providing expert-level digital forensics and incident response services to clients, and developing and executing strategy for the Unit 42 Digital...


  • Washington, Washington, D.C., United States Edgewater Federal Solutions, Inc. Full time

    Job Overview:The position of Senior Incident Response Analyst at Edgewater Federal Solutions, Inc. is a critical role that requires advanced incident response expertise to support the maximization of cyber fusion throughout the client's SOC.


  • Washington, United States Tyto Athene, LLC Full time

    Incident Response SpecialistAs an Incident Response Specialist at Tyto Athene, LLC, you will be responsible for conducting in-depth analyses and responding to incidents of potential cyber threats facing our clients. You will serve as the escalation point for junior analysts, helping guide them through more complex and high-priority incidents.We provide a...


  • Washington, Washington, D.C., United States ManTech International Corporation Full time

    Cybersecurity and Infrastructure ExpertiseAt ManTech International Corporation, we are seeking a seasoned Network/Infrastructure Analyst Lead to join our team. As a critical member of our Cybersecurity and Infrastructure group, you will play a key role in protecting national security while working on cutting-edge projects that drive innovation.With a...


  • Washington, United States Tyto Athene, LLC Full time

    Here at Tyto Athene, we believe our Incident Response Analyst analysts form the backbone of our cybersecurity services. Take your career to the next level and join us as a Tier 2 Incident Response Analyst. You will play a critical role in conducting in-depth analyses and responding to incidents of potential cyber threats facing our clients. In addition to...


  • Washington, United States Tyto Athene, LLC Full time

    Here at Tyto Athene, we believe our Incident Response Analyst analysts form the backbone of our cybersecurity services. Take your career to the next level and join us as a Tier 2 Incident Response Analyst. You will play a critical role in conducting in-depth analyses and responding to incidents of potential cyber threats facing our clients. In addition to...


  • Washington, United States Insight Global Full time

    Job Description An employer is looking for an Incident Response Analysts to sit in Alexandria, VA! In this role, you will utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks and endpoints. You will perform junior- to intermediate-level reviews of massive log files, pivot between data sets, and...


  • Washington, United States cFocus Software Incorporated Full time

    Job DescriptionJob DescriptioncFocus Software seeks a Cyber Incident Response Analyst (Senior) to join our program supporting US Courts in Washington, DC. This position has remote capabilities. This position requires an active Public Trust clearance and must meet 8570 requirements.Required Qualifications include:5 years of experience analyzing forensic...


  • Washington, United States MindPoint Group Full time

    Incident Response Analyst - Night Shift (Tier 2) **Department:** SOC **Location:** Washington, DC Here at MindPoint Group, we believe our Incident Response Analyst analysts form the backbone of our cybersecurity services. Take your career to the next level and join us as a **Tier 2 Incident Response Analyst** . You will play a critical role in conducting...


  • Washington, United States Palo Alto Networks Full time

    About the RoleWe are looking for a highly skilled Digital Forensics and Incident Response Manager to join our team at Palo Alto Networks. In this role, you will be responsible for managing, leading, and motivating consultants at all levels, overseeing other director, senior, and mid-level analyst/consultant teams, and providing strategic guidance and...


  • Washington, United States Crisis24 Full time

    About the Role:The Senior GSOC Analyst directs the activities within the day-to-day operations of the Headquarters Command Center (HQCC) and monitors performance for quality assurance. Using the Incident Command System, the Senior GSOC Analyst serves as the incident commander and directs the HQCC's response to incidents, until they are resolved or major...


  • Washington, United States Leidos Full time

    Responsibilities:The Security Operations Manager will be responsible for ensuring the timeliness and quality of reporting produced by the security operations staff to stakeholders. This includes:Instilling and reinforcing industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC...


  • Washington, United States GovStaff Full time

    GovStaff is seeking a Top Secret cleared Tier II Incident Response Analyst. Shift 1, M-F, 6am to 2:30pm. Hybrid role with expectations of working onsite most days of the week. Site location is in the NoMa area of Washington, DC, 20002 at 2CON Square. Excellent company sponsored benefits program, and an opportunity to establish stability and grow your cyber...


  • Washington, Washington, D.C., United States General Dynamics Full time

    Job Description: We are seeking an experienced IT Incident Response Manager to join our team in Washington DC. This is a full-time position that offers the opportunity to work on challenging projects and develop your skills in technical support and incident management.In this role, you will be responsible for leading the response to critical incidents,...


  • Washington, United States MindPoint Group Full time

    **Job Summary:**We are seeking a highly experienced Security Operations Center Manager to join our team at MindPoint Group. The successful candidate will have a strong background in information security and extensive experience in managing a Security Operations Center (SOC).Main Responsibilities:Lead the Security Operations Center (SOC) and ensure the...


  • Washington, Washington, D.C., United States TekSynap Full time

    OverviewTekSynap is a high-tech company providing comprehensive services to the Unite States Senate in Washington DC.We are seeking an experienced Help Desk Incident Manager to oversee and manage the resolution of IT incidents. The ideal candidate will have a strong background in IT support, incident management, and coordinating teams to respond to critical...