Incident Response Analyst

1 week, 1 day ago
Contract
Senior
Cybersecurity
Skyepoint Decisions

Skyepoint Decisions

Skyepoint Decisions specializes in providing comprehensive IT solutions for the federal government, focusing on cybersecurity architecture, critical infrastructure operations, and applications development and maintenance to support a secure and mobile ...

Internet Software & Services
51-250
Founded 2009

Description

  • Participate in 24x7 incident response operations, escalation activities, and emergency response procedures.
  • Monitor and analyze security events from SIEM, IDS/IPS, EDR, cloud security, and network monitoring platforms.
  • Investigate suspected cybersecurity incidents to determine scope, impact, severity, and root cause.
  • Perform incident triage, containment, eradication, recovery, and post-incident analysis activities.
  • Correlate logs, alerts, threat intelligence, and forensic evidence to identify malicious activity.
  • Coordinate incident response activities with stakeholders, system owners, cybersecurity teams, and government leadership.
  • Escalate incidents according to government-approved procedures and response playbooks.
  • Document findings, investigative activities, and remediation recommendations in formal incident reports.
  • Develop and maintain indicators of compromise, detection logic, response procedures, workflows, and playbooks.
  • Conduct forensic analysis, support cybersecurity exercises and tabletop simulations, and participate in lessons learned reviews.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related discipline.
  • Minimum 5 years of experience in cybersecurity, incident response, SOC operations, threat detection, or cyber defense.
  • Experience supporting Federal Government cybersecurity programs.
  • Knowledge of the incident response lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and lessons learned.
  • Experience using SIEM platforms such as Splunk.
  • Experience with vulnerability management and security assessment tools.
  • Experience investigating malicious activity, suspicious behaviors, and security events.
  • Strong understanding of Windows and Linux operating systems, network protocols and architecture, security monitoring technologies, EDR, IDS/IPS, and cloud security concepts.
  • Experience developing incident reports and executive summaries.
  • Excellent verbal and written communication skills.
  • Ability to support on-call and incident response activities as required.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.
  • One or more preferred certifications: GCIH, ECIH, Security+, CEH, CySA+, GCFA, CISSP, or OSCP.
  • Experience supporting HHS or other Federal civilian agencies (preferred).
  • Knowledge of NIST SP 800-61 and FISMA compliance requirements (preferred).
  • Experience with FireEye, Palo Alto, Tenable, Qualys, Rapid7, Splunk, and EDR platforms (preferred).
  • Experience conducting malware analysis, threat hunting, or digital forensics (preferred).
  • Experience developing cybersecurity metrics and dashboard reporting (preferred).

Benefits

  • Salary range of $110,000 to $130,000.
  • Certification incentive program.
  • PTO.
  • Floating federal holiday options.
  • Medical insurance options, including HMO and High Deductible plans with HSA and FSA options.
  • Dental, vision, short-term disability, long-term disability, and life insurance coverage.
  • 401(k) with company match.
  • Flexible work environment, including fully remote work.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

1 week, 1 day ago

Cyber Detection and Response Analyst, Asia Pacific

Control Risks 1K-5K Professional Services

Cyber Detection and Response Analyst at a global security team, supporting 24/7 threat detection, investigation, and response across a client environment.

AWS Azure CrowdStrike Cybersecurity GCP SIEM Splunk
2 weeks, 5 days ago

Fractional Cyber Security Analyst (Advisor Network)

Arootah 11-50 Professional Services

Arootah is seeking an experienced Cybersecurity Analyst to join its advisor network and support hedge fund and family office clients on project-based cybersecurity engagements.

Active Directory Azure Cybersecurity Encryption Network Security Penetration Testing SQL Windows Server
3 weeks, 1 day ago

Surveillance Officer

Prevail Partners 11-50 Professional Services

Prevail Partners is seeking experienced Surveillance Officers to support an Ultra High Net Worth client through discreet protective surveillance operations within a specialist security programme.

4 weeks, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers