Senior Incident Response Analyst with Security Clearance

4 weeks ago


Ashburn, United States Base One Technologies Full time
Our Ashburn VA based client is looking for multiple Senior Incident Response Analyst. If you are qualified for this position, please email your updated resume in word format to
Required Education/Experience
A bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS 4 years of experience in incident detection and response, malware analysis, or cyber forensics. Primary Responsibilities
• In-depth knowledge of each phase of the Incident Response life cycle
• Expertise of Operating Systems (Windows/Linux) operations and artifacts
• Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)
• Ability to recognize suspicious activity/events, common attacker TTPs, perform logical analysis and research to determine root cause and scope of Incidents
• Drive implementation and improvement of new tools, capabilities, frameworks, and methodologies
• Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC operations
• Promote and drive implementation of automation and process efficiencies
• Familiarity with Cyber Kill Chain and ATT&CK Framework and how to leverage in Security Operations
• Provide guidance and mentorship to improve analyst skill sets and ensure delivery of high-quality analysis and work products
• Establish trust and business relationships with customer and other relevant stakeholders Basic Qualifications
• All Senior Incident Response Analyst candidates shall have a minimum of a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS 4 years of experience in incident detection and response, malware analysis, or cyber forensics.
• Must have TS/SCI. In addition to specific security clearance requirements, all Department of Homeland Security SOC employees are required to obtain an Entry on Duty (EOD) clearance to support this program. • 4+ years of supervising and/or managing teams
• 5+ years of intrusion detection and/or incident handling experience
• CISSP and SANS GCIH or GCIA required upon start
• Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise
• Significant experience supervising and leading employees of various labor categories and technical skill levels in efforts similar in size and scope to a mature Security Operation
• Mature understanding of industry accepted standards for incident response actions and best practices related to SOC operations;
• Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings.
• Strong analytical and troubleshooting skills. Preferred Qualifications
• Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
• Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization including prior experience performing large-scale incident response.
• Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
• Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework.
• Familiarity with Cloud concepts and experience performing monitoring and responding to threats in Cloud environments
• Must Have One of the Following J3 Certifications
• CISSP and SANS GCIH or GCIA required upon start Clearance Level Required: Top Secret/SCI
Travel: No
Scheduled Weekly Hours:40

  • Ashburn, United States Agile Defense Full time

    Agile Defense We are in the business of innovation through information technology and cybersecurity, delivered exceptionally. View company page Agile Defense provides leading-edge Digital Transformation solutions to support and advance our customers' mission. We deliver innovative and high-quality services to our customers worldwide through an empowered and...


  • Ashburn, United States Leidos Full time

    **Description** Our Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the government Enterprise. We have primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet...


  • Ashburn, United States Base One Technologies Full time

    Threat Hunt Analyst MidPrimary Responsibilities• Create Threat Models to better understand the Agency's IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and maintain SOPs, playbooks, work instructions• Utilize Threat Intelligence and Threat Models to create threat hypotheses• Plan and scope Threat Hunt Missions to...


  • Ashburn, United States Anonymous Employer Full time

    Primary ResponsibilitiesThe ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:• Create Threat Models to better understand the Agency IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and...


  • Ashburn, United States Base One Technologies Full time

    Primary Responsibilities• Identify gaps in malicious activity detection capabilities• Create new signatures / rules to improve detection of malicious activity• Test and tune existing signatures / rules to ensure low rate of false positives• Assist in playbook development for alert triage and Incident Response• Define and implement alert and threat...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesPerform research on current threats and vulnerabilities. Will be responsible for authoring security advisories. Manage enterprise vulnerability compliance and will conduct vulnerability assessments of IT systems. This position location is Ashburn, Virginia Basic QualificationsNEW REQUIREMENT as of 6/27/2022: In addition to uploading...


  • Ashburn, United States Base One Technologies Full time

    Required Education/ExperienceBS degree in Science, Technology, Engineering, Math or related field and 8 years of prior relevant experience with a focus on cyber security or Masters with 6 years of prior relevant experience. Should have 5 years of experience serving as a digital media Primary Responsibilities• Identify gaps in malicious activity detection...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Detection Engineer. If you are qualified for this position. Please email me your updated resume in word format to Work location: Ashburn VA Detection EngineerPrimary Responsibilities• Identify gaps in malicious activity detection capabilities• Create new signatures / rules to improve detection of malicious...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesNight Shift Back -Shift schedule: 7pm-7am, Thur-Sat, every other Wednesday.• Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to examine endpoint...


  • Ashburn, United States Gray Tier LLC Full time

    Primary Responsibilities: The ideal Cyber Threat Hunter is someone who is process driven, curious, and enjoys identifying patterns and anomalies in data that are not immediately obvious. The Cyber Threat Hunter will:• Create Threat Models to better understand the CBP IT Enterprise, identify defensive gaps, and prioritize mitigations• Author, update, and...


  • Ashburn, United States Anonymous Employer Full time

    Primary Responsibilities • Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies. • Perform web app pentests • Perform vulnerability risk assessment • Perform physical pentests and social engineering • Perform cyber incident response as needed for programs Basic Qualifications Bachelors'...


  • Ashburn, United States Anonymous Employer Full time

    Primary Responsibilities• Perform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies.• Perform web app pentests• Perform vulnerability risk assessment• Perform physical pentests and social engineering• Perform cyber incident response as needed for programs Basic QualificationsBachelors’...


  • Ashburn, United States Base One Technologies Full time

    Primary ResponsibilitiesPerform internal and external pentest against systems to determine vulnerabilities and offer mitigation strategies.Perform web app pentestsPerform vulnerability risk assessmentPerform physical pentests and social engineeringPerform cyber incident response as needed for programs Basic QualificationsBachelors’ degree from an...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Tier 2 IR Night Shift Front. This position requires an active DHS Public Trust Clearance. If you are interested in this opening, please forward a copy of your updated resume in word format to Must Have One of the Following J3 Certifications GCIH – Incident Handler GCFA – Forensic Analyst GCFE – Forensic...


  • Ashburn, United States Anonymous Employer Full time

    Our Arlington VA based client is looking for Cyber Vulnerability Assessment Analyst. If you are qualified for this position, please email your updated resume in word format to Required Education/ExperienceBachelors’ degree from an accredited college in a related discipline, or equivalent experience/combined education, with 2-4 years of professional...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Tier 2 IR Night Shift Front. This position requires an active Secret and DHS Public Trust Clearance. If you are interested in this opening, please forward a copy of your updated resume in word format to Must Have One of the Following J3 CertificationsGCIH – Incident HandlerGCFA – Forensic AnalystGCFE –...


  • Ashburn, United States Base One Technologies Full time

    Tier 2 IR Night ShiftNight Shift FrontShift schedule: 7pm-7am, Sun-Tues, every other Wednesday.Primary Responsibilities• Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Systems Engineer. If you are qualified for this position, please email your updated resume in word format to Primary ResponsibilitiesPerform research on current threats and vulnerabilities. Will be responsible for authoring security advisories. Manage enterprise vulnerability compliance and will conduct...


  • Ashburn, United States Base One Technologies Full time

    Work location: Ashburn VA222 - Senior Security Engineer Must Have One of the Following J3 Certifications Sr. Security Engineer:CompTIA Advanced Security Practitioner (CASP)GCIH – Incident HandlerGCWN – Windows Security AdministratorGISF – Security FundamentalsGISP – Security ProfessionalGSSP – Secure Software ProgrammerGICSP –Cyber Security...


  • Ashburn, United States Base One Technologies Full time

    Our Ashburn VA based client is looking for a Splunk Engineer. If you are interested in this opening. Please forward a copy of your updated resume in word format to Work location: Ashburn VA222 - Senior Security Engineer (CBP) Must Have One of the Following J3 Certifications Sr. Security Engineer:CompTIA Advanced Security Practitioner (CASP)GCIH – Incident...