Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Incident Response Analyst II

Merit 321

Tier 2 Cybersecurity Incident Response Analyst

The Tier 2 Cybersecurity Incident Response Analyst provides advanced incident response support for NIH enterprise and cloud environments. This role responds to hotline-reported incidents and performs investigation, containment, and recovery activities in accordance with NIH policies, HHS requirements, NIST standards, and Client CISA guidance.

Key Responsibilities:

  • Respond to and manage incidents reported through the NIH cybersecurity hotline
  • Log, categorize, investigate, and escalate incidents per NIH procedures
  • Perform Tier 2/3 incident response across on-premises and cloud environments (Azure, AWS, GCP)
  • Conduct forensic analysis, threat hunting, and log correlation
  • Coordinate response activities with NIH stakeholders and service providers
  • Develop executive summaries for significant incidents and third-party events
  • Develop and maintain incident response playbooks, SOPs, and KB documentation
  • Support annual updates to the NIH Incident Response Plan
  • Contribute to incident response maturity assessments and improvement roadmaps

Required Qualifications:

  • At least 3 years of cybersecurity incident response experience
  • Bachelor’s degree in related field
  • Experience supporting federal, NIH, HHS, or healthcare environments
  • Working knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • NIST SP 800-61 Rev. 2
    • NIST SP 800-53 Rev. 5 (IR, AU, SI, CA families)
    • Client CISA guidance
  • Hands-on experience responding to incidents in cloud environments
  • Strong written communication skills, including executive-level reporting

Preferred Qualifications:

  • Experience developing or maintaining incident response playbooks

Incident response or security certifications (GCIH, GCIA, CISSP, etc.)

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Incident Response Analyst II in Bethesda, MD vacancy
  •  ...detection/prevention and cybersecurity tools administration....  ...holiday workdays. Responsibilities Provide on-site CSSP/...  ...triage of CSSP/IR incidents including implementing...  ...certification. DoD 8570 IAT-II or above professional...  .../INCIDENT RESPONSE ANALYST #J-18808-Ljbffr... 
    Suggested
    Work at office
    Monday to Friday
    Weekend work

    Bespoke Corps LLC

    Arlington, VA
    2 days ago
  • $86.8k - $198k

    Incident Response Analyst, SeniorThe Opportunity:Respond to cybersecurity incidents and proactively prevent the reoccurrence of these incidents. Apply specific functional knowledge to resolve cybersecurity incidents. Analyze or contribute to solutions to a variety of problems... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    2 days ago
  • $135k - $175k

     ...Cybersecurity Professional Hogan Lovells Cadwalader is looking for an experienced cybersecurity professional...  ...technology environment. This position is responsible for leading security investigations, coordinating incident response activities, advancing detection capabilities... 
    Suggested
    Monday to Friday
    Afternoon shift
    Early shift

    Hogan Lovells

    Washington DC
    7 hours ago
  • $94k - $127k

     ...Description Incident Response Analyst Xcelerate Solutions is seeking an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join... 
    Suggested

    VMD Corp

    Alexandria, VA
    4 days ago
  •  ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We are seeking an experienced Incident Response... 
    Suggested
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy Inc

    Washington DC
    4 days ago
  • $120k - $135k

     ...Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust...  ...of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission-critical government... 
    Permanent employment
    Contract work
    Remote work
    2 days per week

    Tetrad Digital Integrity

    Arlington, VA
    4 days ago
  • $100k - $125k

    A cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role involves serving as a subject matter expert in incident response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have over 8... 

    ARGO Cyber Systems

    Arlington, VA
    20 hours ago
  • A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a... 

    Bespoke Corps LLC

    Arlington, VA
    20 hours ago
  • Xcelerate Solutions is seeking an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Location: Alexandria, VA and Seaside, CA. Responsibilities... 

    Xcelerate-Solutions-5

    Alexandria, VA
    2 days ago
  • Xcelerate Solutions seeks an Incident Response Analyst to support CyberPRIMES cybersecurity, privacy, records and information management for DHRA. The role requires an Active Secret clearance and collaboration with government stakeholders across multiple environments.... 

    VMD Corp

    Alexandria, VA
    2 days ago
  • Ops Tech Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You will assess...  ..., identify operational risks and process gaps, support incident-response, and translate complex cyber information into actionable... 

    OPS TECH ALLIANCE LLC

    Mc Lean, VA
    3 days ago
  • $80k - $128k

    Tier 2 Cyber Incident Response Team (CIRT) Analyst job at Peraton. Beltsville, MD. Program Overview Encompasses technical, engineering, data analytics...  .... Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).... 
    Interim role
    Internship
    Work at office
    Local area
    Worldwide
    Afternoon shift

    Peraton

    Beltsville, MD
    1 day ago
  • $99k - $225k

    Incident Response Analyst, Senior The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make...  ...monitoring, detection, investigation, and response to cybersecurity threats across enterprise networks, endpoints, applications... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    3 days ago
  • cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance... 
    Work at office

    cFocus Software Incorporated

    Washington DC
    4 days ago
  • $87.1k - $157.45k

     ...Description Leidos is seeking an experienced Incident Response Analyst to support the Defense Manpower Data Center (DMDC) CyberPRIMES...  ...the contract and will provide a substantialportionof the cybersecurity workforce supporting the Defense Human Resources Activity... 
    Contract work
    Work at office
    Local area
    Immediate start
    Remote work

    Leidos

    Alexandria, VA
    20 hours ago
  • Chenega MIOS in Arlington, VA seeks a Security Operations Center Analyst I to monitor devices, manage incidents, and coordinate recovery across government networks. The role requires DoD IAT Level II certification and a DoD Secret Clearance with potential TS/SCI eligibility... 

    Njvc LLC

    Arlington, VA
    1 day ago
  • Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient...  ...) Cloud experience is a plus Responsibilities Address cybersecurity incidents: identify, isolate, resolve, recover, document,... 
    Remote work
    Visa sponsorship

    Breeze End Technology, LLC

    Alexandria, VA
    2 days ago
  •  ...based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital...  ...many benefits and opportunities we offer. Requirements Analyst II Responsibilities and Duties: Elicit, analyze, document, and validate... 
    For contractors
    Work at office

    Electrosoft

    Arlington, VA
    20 hours ago
  • $70.6k - $83k

     ...Compensation:$70,600.00to $83,000.00 Purpose: The HRMS Analyst II - Time & Attendance serves as a technical expert responsible for the functional administration, optimization...  ..., with escalation protocols for critical incidents Manages UKG accrual processes, including... 
    Work experience placement
    Work at office
    Local area
    Flexible hours

    Avolta AG

    Bethesda, MD
    1 day ago
  • $132.48k - $336.96k

    Responsibilities About the Team The TikTok USDS JV Security Operations...  ...efforts to enterprise-wide incidents, including post-incident root...  ...incidents. As an IR Analyst, you will belong to a team...  ...comprehensive data privacy and cybersecurity program we operate under defined... 
    Temporary work
    Shift work

    TikTok USDS Joint Venture

    Washington DC
    2 days ago
  • $131.3k - $237.35k

    Leidos Inc is seeking a Senior Incident Response Analyst to join their team in Arlington, Virginia. The role involves coordinating incident response efforts, analyzing cyber threats, and developing security protocols for the Department of Homeland Security's CISA Program... 

    Leidos

    Arlington, VA
    4 days ago
  • Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join the Department of State (DOS) Diplomatic Security Cyber Mission program in Beltsville, Maryland. The role operates on an evening shift (1400-2200 EST, Tue-Sat) and focuses on detecting... 
    Worldwide
    Afternoon shift

    Peraton

    Beltsville, MD
    1 day ago
  • Nightwing Group is seeking a Business Analyst to support onsite incident response for U.S. Government agencies experiencing cyber-attacks. The role involves gathering requirements, stakeholder coordination, and ensuring technology integration aligns with operational priorities... 

    Nightwing Group

    Arlington, VA
    1 day ago
  •  ...based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust,...  ...the many benefits and opportunities we offer. Business Analyst II Responsibilities and Duties: Support IT programs and project teams by... 
    For contractors
    Work at office

    Electrosoft

    Arlington, VA
    2 days ago
  • Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency...  ...and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret... 
    Work at office

    Cortek, Inc.

    Washington DC
    20 hours ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Flexible hours

    Leidos

    Arlington, VA
    4 days ago
  • $100k - $129.02k

    Management Analyst II This position requires an active Secret clearance. The Management...  ...without notice. Management Analyst II Responsibilities Include: Provide administrative, operational...  ...Technologies Artificial Intelligence Cybersecurity Foreign Policy Legal Disclaimer:... 
    Full time
    Contract work
    Work at office

    Cherokee Federal

    Washington DC
    1 day ago
  • ## (Cyber) Incident Management Analyst - Weekend Night ShiftApplylocations: Arlington, VAtime type:...  ...provide support for onsite incident response to civilian Government agencies and...  ...incidents within the enterprise- Applying cybersecurity concepts to the detection and... 
    Contract work
    Immediate start
    Shift work
    Night shift
    Weekend work

    Nightwing Group

    Arlington, VA
    1 day ago
  •  ...is a market leading cybersecurity consultancy firm that...  ...seeking a skilled SOC Analyst with an active Secret...  ...security events and incidents to evaluate the effectiveness...  ...Center administrator responsibilities, routine maintenance...  ...CAT I and CAT II items that cannot be... 
    Full time
    Local area
    Flexible hours

    Coalfire

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Incident Response Analyst II. Be the first to apply!