Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Incident Response Analyst II

Merit 321

Tier 2 Cybersecurity Incident Response Analyst

The Tier 2 Cybersecurity Incident Response Analyst provides advanced incident response support for NIH enterprise and cloud environments. This role responds to hotline-reported incidents and performs investigation, containment, and recovery activities in accordance with NIH policies, HHS requirements, NIST standards, and Client CISA guidance.

Key Responsibilities

  • Respond to and manage incidents reported through the NIH cybersecurity hotline
  • Log, categorize, investigate, and escalate incidents per NIH procedures
  • Perform Tier 2/3 incident response across on-premises and cloud environments (Azure, AWS, GCP)
  • Conduct forensic analysis, threat hunting, and log correlation
  • Coordinate response activities with NIH stakeholders and service providers
  • Develop executive summaries for significant incidents and third-party events
  • Develop and maintain incident response playbooks, SOPs, and KB documentation
  • Support annual updates to the NIH Incident Response Plan
  • Contribute to incident response maturity assessments and improvement roadmaps

Required Qualifications

  • At least 3 years of cybersecurity incident response experience
  • Bachelor’s degree in related field
  • Experience supporting federal, NIH, HHS, or healthcare environments
  • Working knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • NIST SP 800-61 Rev. 2
    • NIST SP 800-53 Rev. 5 (IR, AU, SI, CA families)
    • Client CISA guidance
  • Hands-on experience responding to incidents in cloud environments
  • Strong written communication skills, including executive-level reporting

Preferred Qualifications

  • Experience developing or maintaining incident response playbooks

Incident response or security certifications (GCIH, GCIA, CISSP, etc.)

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Incident Response Analyst II in Bethesda, MD vacancy
  •  ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We are seeking an experienced Incident Response... 
    Suggested
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy

    Washington DC
    4 days ago
  • $60 per hour

     ...Description Tyto Athene is searching for a Part-Time Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington, DC. Our IR analysts form the backbone of our cybersecurity services. You will play a critical role in securing our... 
    Suggested
    Part time
    Worldwide
    Shift work
    Night shift
    Weekend work
    Day shift

    Tyto Athene, LLC

    Washington DC
    4 days ago
  •  ...Full-Time Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military...  ...and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and helps deliver... 
    Suggested
    Full time
    Contract work
    Part time
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    4 days ago
  • A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools, triage alerts, and investigate cyber threats. Ideal candidates have six years in cybersecurity, preferably three in SOC... 
    Suggested

    Tyto Athene, LLC

    Washington DC
    3 days ago
  • A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience... 
    Suggested
    Remote job

    Cyber Synergy Consulting Group

    Washington DC
    3 days ago
  • Tyto-Athene is seeking a Part-Time Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor cybersecurity tools, triage alerts, and respond to incidents. Ideal candidates have significant cybersecurity experience and a Bachelor's... 
    Part time

    Tyto-Athene

    Washington DC
    4 days ago
  •  ...Global Solutions in Washington, DC is seeking a Senior Security Operations Analyst to monitor and respond to cybersecurity threats. The candidate will analyze security events, manage incident response, and support the National Indian Gaming Commission's cybersecurity... 

    Terrestris Global Solutions

    Washington DC
    1 day ago
  • $127k - $140k

     ...join Deepwatch’s team of world-class cybersecurity professionals and the brightest...  ...comprehensive detection and automated response to cyber threats together with tailored...  ...Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active... 
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Work from home
    Home office
    Flexible hours

    Deepwatch

    Washington DC
    4 days ago
  • $80k - $92k

     ...Job Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure...  ...SkyePoint Decisions is seeking an experienced Tier 2 Analyst for the Cyber Incident Response Team to support our customer's Federal Strategic Cyber... 
    Contract work
    Local area

    SkyePoint Decisions

    Beltsville, MD
    a month ago
  •  ...SME Incident Response Analyst This Department of War enterprise data and analytics program delivers mission-critical capabilities that enable...  ...Responsibilities Design, implement, and operate Cybersecurity Incident and Spillage processes and procedures.... 

    Navstar

    Alexandria, VA
    3 days ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Arlington, VA
    5 days ago
  • $40 per hour

     ...We are looking for experienced cybersecurity professionals to join our team to help train...  ..., Ireland, Australia, and New Zealand Responsibilities Evaluate AI-generated cybersecurity content...  ...g., penetration testing, red teaming, incident response, detection engineering, DFIR,... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  • $30 - $39 per hour

     ...Overview Job Title: ITSM Incident Response Analyst Location: Remote Type: Independent Contract - Corp to Corp/1099 Start Date: ASAP Pay Rate: $30-39/hr (Independent Contract) Contract Length: throughAugust 31 Responsibilities Serve as a... 
    Contract work
    For contractors
    Work experience placement
    Local area
    Immediate start
    Remote work

    Cayuse Holdings

    Washington DC
    3 days ago
  • Ernst & Young Oman is looking for a Cyber Triage and Forensics (CTF) Incident Analyst to be a senior member of the technical team handling security incidents. Responsibilities include performing digital forensic analysis, responding to security incidents, and developing... 
    Flexible hours

    Ernst & Young Oman

    Washington DC
    4 days ago
  •  ...seeking a Security Operations Center (SOC) Analyst to support 24x7 security monitoring, alert triage, and incident response activities. This role involves validating alerts...  ...should have a bachelor's degree in Cybersecurity, at least four years of SOC experience, and... 
    Remote job

    Ardent

    Washington DC
    4 days ago
  • $130.36k - $221.6k

     ...Description BAE Systems is seeking a Data Analyst to join our team and provide support...  ...by Q3/Q4 of 2026. The Data Analyst responsibilities include, but are not limited to: *...  ...& Skills * Bachelor's Degree in IT, Cybersecurity, Computer Science, Information Systems... 
    Full time
    Contract work
    Local area

    BAE Systems PLC

    Washington DC
    3 days ago
  •  ...Business Analyst II Location: Rockville, MD Duration: 3 months, Onsite Day-to-day Responsibilities: Architect, develop, and implement AWS infrastructure (VPCs, subnets...  ...high system reliability and rapid incident response. Stay current with evolving... 

    Ark Solutions

    Rockville, MD
    5 days ago
  • $120k - $145k

     ...Corporation is looking for an experienced Information Security Analyst (SME) to join their team in Washington, DC. The ideal...  ...Degree and over 4 years of experience in security analysis and incident response. Responsibilities include maintaining threat awareness, developing... 

    Cape Fox Corporation

    Washington DC
    3 days ago
  • $71k - $119k

     ...Application Development, Cybersecurity, Virtualization, Cloud...  ...seeking a ServiceNow Analyst to join our team at...  ...platform. You will be responsible for requirements...  ...support role. IAT Level II Certification equivalent...  ...modules such as Incident, Problem, Change, CMDB... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Remote work
    Relocation package

    Link Solutions, Inc.

    Adelphi, MD
    5 days ago
  •  ...Cybersecurity Operations Specialist This position is contingent upon award of a government...  ...operations, RMF compliance, incident response, and continuous monitoring support....  ...clearance or eligibility IAT Level II certification Experience with RMF, STIGs... 
    Contract work
    For contractors

    T & T Consulting Services, Inc.

    Silver Spring, MD
    3 days ago
  •  ...SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and...  ...with our customer. This role is responsible for conducting vulnerability scanning and...  ...emergency vulnerability scanning in support of incident investigation and response activities... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    14 days ago
  • $95k - $105k

     ...remote from home! What you’ll do: Responsible for supporting the ongoing monitoring efforts...  ...approvals, testing, monitoring, and incident reporting processes. Support third-...  ...risk (e.g., NIST AI RMF, NIST Cybersecurity Framework, SOC/SSAE, ISO/IEC 27001 concepts... 
    Work experience placement
    Remote work
    Work from home

    Carrington

    Washington DC
    5 days ago
  • $82.55k - $149.23k

     ...currently has an opening for a Hunt Analyst supporting the HEITS...  ...Program (ITP) supporting the Cybersecurity and Infrastructure Security...  ...selected candidate will be responsible for the following: Review...  ...enforcement and report the incident to the U.S. Federal Trade... 
    Contract work
    Local area
    Immediate start
    Monday to Friday
    Weekend work

    Leidos

    Arlington, VA
    2 days ago
  •  ...Analyst II (Budget) Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology...  ...reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a... 
    Work at office

    Arlo Solutions

    Alexandria, VA
    5 days ago
  •  ...great place to work. The Role We're looking for a Sourcing Analyst II. The Procurement Sourcing & Contracts Analyst plays a vital...  ...in procurement strategies. Essential Duties and Responsibilities: * Execute tactical activities such as developing and distributing... 
    Full time
    Contract work

    Avalon Bay

    Arlington, VA
    3 days ago
  • $82.5k

     ...purpose as much as progress, G&A is the place for you! FOIA Analyst II Goldschmitt and Associates is searching for a FOIA...  ...up to $82,500, dependent upon experience. Job Duties and Responsibilities: Support required will involve various assistance-related... 
    Temporary work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Goldschmitt and Associates LLC

    Washington DC
    4 days ago
  • $110k - $135k

     ...Working Title Cybersecurity Specialist Payroll Title Analyst Location BCSA DC HQ - Washington, DC 2...  ...operational monitoring. Key Responsibilities: Support analysis of cybersecurity...  ...threats, vulnerabilities, and incidents impacting the U.S. energy... 
    Full time
    Currently hiring
    Local area
    Remote work

    BCS Allegient

    Washington DC
    1 day ago
  •  ...Analyst II Primary Location: Washington DC Clearance: Active Top Secret, TS/SCI Obsidian Solutions Group (OSG) is seeking...  ..., Technical, Training/Facilitation, and Change Management responsibilities. This position also serves as a key resource to clients through... 
    Work at office

    Obsidian Solutions Group

    Washington DC
    5 days ago
  •  ...USGI is seeking an Operational Analyst II to provide support that complements the Government's expertise in accomplishing its mission...  ..., evaluations, recommendations, training, and services. Responsibilities Formulate and apply mathematical modeling and other... 
    Temporary work

    Universal Strategy Group

    Arlington, VA
    2 days ago
  •  ...ECS is seeking a Senior Tier-3 Analyst to work in the National Capital...  ...handling the most complex escalated incidents that cannot be resolved at lower...  ...tiers and directing coordinated response activities across engineering, cybersecurity, data operations, and platform operations... 
    Contract work

    ECS Limited

    Falls Church, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Incident Response Analyst II. Be the first to apply!