Cyber Incident Response Team Analyst (Tier 2)
AGR LLC
Job Description
Job Description
Location: Beltsville, MD
Work Hours: Evening Shift, 1400 – 2200 EST, TUE-SAT
Program Overview
The DSCM program encompasses cyber security, data analytics, engineering, technical, managerial, operational, logistical and administrative support to aid and advise DOS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats. Those supporting the DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.
About the Role
- Detect, classify, process, track, and report on cyber security events and incidents.
- Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
- Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
- Characterize and analyze network traffic to identify anomalous activity and potential threats.
- Protect against and prevent potential cyber security threats and vulnerabilities.
- Perform forensic analysis of hosts artifacts, network traffic, and email content.
- Analyze malicious scripts and code to mitigate potential threats.
- Conduct malware analysis to generate IOCs to identify and mitigate threats.
- Collaborate with Department of State teams to analyze and respond to events and incidents.
- Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
- Create tickets and initiate workflows as instructed in technical SOPs.
- Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
- Collaborate with other local, national and international CIRTs as directed.
- Submit alert tuning requests.
Qualifications:
- Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
- Must possess one of the following certifications prior to start date:
- A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.
- Demonstrated experience in the Incident Response lifecycle.
- Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
- Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
- Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
- Knowledge of cloud security monitoring and incident response.
- Knowledge of integrating IOCs and Advanced Persistent Threat actors.
- Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
- Knowledge of malware analysis techniques.
- Knowledge of the MITRE ATT&CK and D3FEND frameworks.
- U.S. Citizenship required.
- Active Interim Secret clearance in order to start.
Preferred Qualifications:
- Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
- Knowledge of Microsoft Azure access and identity management.
- Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
- Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
- Experience with using ServiceNow SOAR for ticketing and automated response.
- Knowledge of Python, PowerShell and BASH scripting languages.
- Experience with cloud security monitoring and incident response.
- Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
- Experience with integrating cyber threat intelligence and IOC-based hunting.
- Technical certifications such as: Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
- Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
$90k - $107k
...Decisions is seeking a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program... ...:00 EST, TUES-SAT. Responsibilities: Detect, classify... ...security events and incidents. Perform advanced... ...Department of State teams to analyze and respond...CyberContract workLocal areaRemote workShift work- ...recognized members of the Cyber Elite, we work... ...to the belief that our team members do their best... ...We are seeking a Tier 2 Analyst for a potential opportunity... ...cybersecurity to improve incident detection, analyze threat... ...support detection and response. Support incident...CyberContract work
$131.3k - $237.35k
...our customers’ success. We empower our teams, contribute to our communities, and... ...Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department... ..., mitigating, and responding to cyber threats and adversarial activity on...CyberFlexible hours- ...A global cybersecurity consultancy is seeking an Incident Response Engagement Lead to manage cyber incidents and lead a team of experts. The role involves project management, relationship building, and effective incident response. Ideal candidates should possess strong...CyberFull time
$83.5k - $87.5k
Cayuse Holdings is seeking a Cyber Incident Response Analyst in Washington, DC to enhance the cybersecurity framework. This role involves case management... ...and CompTIA Security+ certification, with between 0-2 years of experience. The Analyst will work in a professional...Cyber- cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance...Work at office
$7.5k
...malware analysis. Two (2) years of demonstrated... ...0 compliance with CSSP Analyst Baseline certification.... ..., Kibana, Advanced Cyber Defense Course, and other... ...of the role's responsibilities, the candidate's educational... ...Department of Defense, with team members located...CyberContract workPart timeWork experience placementImmediate startFlexible hours$83.5k - $87.5k
Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client’s cybersecurity framework... ...(SOPs). Escalate cases to specialized teams (e.g., Threat Hunting, Vulnerability... ...best practices. Additional (2) two years of experience may be substituted...CyberTemporary workWork at officeLocal areaFlexible hoursShift work$65k - $85k
...Consultants (CTC) is seeking Tier 2 Technical Support to... ..., Test Automation, Cyber Security, and... ...Washington, DC Daily Responsibilities: Provide professional... ...used with Microsoft Teams, etc.). Offer consulting... ...experience with Incident, Change, or Knowledge...CyberFull timeContract workFor contractorsWork at officeLocal areaRemote work$7.5k
...Brief Exploitation, network, cyber Job Description RealmOne is... ...opportunity supports a team of Exploitation Analysts, Digital Network Exploitation... ...Network Defense Analysts, responsible for improving, protecting,... ...administration. The Level 2 Exploitation Analyst shall...CyberContract workWork experience placementImmediate startFlexible hours- ...Job Description Job Description Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)... ...across multiple federal cybersecurity teams. The ideal candidate has hands-on experience... .... Required Qualifications ~2–5+ years of experience in cybersecurity...Full timeContract workRemote workMonday to Friday
$60k - $100k
...cybersecurity operations and a bachelor's degree in a related field. The role involves leading incident response efforts, documenting actions, and collaborating with technical teams to enhance security across multiple environments. Competitive salary range from $60,000 to...Cyber- Cayuse is hiring a Cyber Incident Response Analyst in Washington, DC. This role is critical for reinforcing the client’s cybersecurity framework, managing... ...incidents, and collaborate closely with various teams while maintaining high-quality customer service. Candidates...Cyber
$7.5k
...to work with a RESILIENT team at RealmOne? RealmOne... ...supports a team of Target Analyst Reporters, Collection Managers... ...reporting vehicles, in response to mission requirements.... ...Analyst Reporter Level 2 shall possess the... ...mission (e.g. collection, cyber and intelligence analysis...CyberContract workWork experience placementImmediate startFlexible hours- ...exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United... ...demand than ever. We’re building a team to meet this challenge. We’re quick... ...’ve built a team of intelligence analysts, technical specialists, software developers...CyberFull timeImmediate startFlexible hours
- ...Job Description Provides Tier 2 desktop support (telephone, deskside... ..., resolves, and reports on incidents and requests using ServiceNow.... ...Escalates incident to the appropriate team when the incident cannot be... ..., with the focus on Cloud, Cyber, Enterprise IT, Systems...CyberWork at officeRemote work
$130k - $135k
...Hands‑on experience performing responsibilities aligned to incident response, security... ...engineering, threat hunting, or cyber threat intelligence. Must... ...a weekend schedule. ( 2 nd Shift WEEKEND schedule,... ...collaboration, and respect for all team members, ensuring that WWT...CyberFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift$60k - $180k
...Delivery & Analytics, Cyber Security, Cloud... ...a Business Analyst to work onsite in... ...clearance is required. Responsibilities Analyze business... .... Support Tier 1 and Tier 2 operational services... ...and maintain incident management, escalation... ..., operational teams, and technical resources...CyberFull timeContract workFor subcontractor- ...Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda,... ...(IOCs). Support Cyber Threat Intelligence (CTI) activities... ...across technical teams. Commitment to continuous... ..., state, or local law. #M-2 #LI-CK1 Ref: #856-Baltimore...CyberLocal area
$140k - $175k
...to apply for the SOC Analyst - Top Secret Clearance... ...Zachary Piper Solutions 2 days ago Be among the... ...assessments, improving incident response protocols, and ensuring... ...knowledge and fulfill team deliverables. Support... ...Holidays Keywords: Cyber Analyst, SOC Analyst, Security...CyberFull timeContract work- Job Overview A law firm seeks a Cyber Incident Response Associate Attorney in Washington, DC. This role involves managing cybersecurity incidents... ...skills. Ability to work in a fast‑paced environment. Team player. Education JD from an accredited law school. Certifications...CyberFlexible hours
$160k - $190k
...be valued and empowered, then we invite you to apply to our Cyber Incident Response Associate Attorney position in our Washington, D.C. Office.... ...and Westlaw) Ability to work in a fast‑paced environment Team player Salary Range $160,000 - $190,000 USD Benefits Wilson...CyberFull timeWork at officeFlexible hours$160k - $190k
...Washington, D.C. - Flexible hybrid working arrangement. Key Responsibilities Incident response for cybersecurity and data privacy incidents... ...and Westlaw) Ability to work in a fast‑paced environment Team player Salary & Benefits Salary Range: $160,000 USD - $190...CyberFull timeFlexible hours$160k - $190k
...a flexible, hybrid working arrangement. The Position Key Responsibilities Incident response for cybersecurity and data privacy incidents Analysis... ...and Westlaw) Ability to work in a fast-paced environment Team player Wilson Elser offers a competitive salary and...CyberFull timeFlexible hours- ...Support Specialist – Level 2 Port Cyber is seeking to grow its technical team to keep pace with its... ...Services group will be responsible for ensuring all client... ...are: Tier 1 and 2 Issue Resolution... ...to and resolve client incidents via remote and on-site...CyberWork at officeLocal areaRemote workRelocation
- ...Job Description Job Description Incident Response Expert IV (Cyber Eviction Analysts) Location: Washington Dc Metro Area (On-Site) Citizenship: US only... ...and critical infrastructure owners nationwide. Our teams deliver rapid incident response, advanced forensics,...CyberLocal areaImmediate start
$140k - $160k
...in 2000, is a leading cyber operations, intelligence... ...Operational Language Analyst - Turkish, level 2with... ...SCI w/ Poly to join our team working in Annapolis Junction... ...SIGINT Operations. RESPONSIBILITIES Recovering essential... ...Associate’s degree or 2 additional yrs of work...CyberFull timeContract workWork experience placement$59.15k - $106.93k
...a large Engineering team entrusted with evolving... ...this role will be responsible for the design,... ...Respond to network incidents, troubleshoot network... ...Information Systems, Cyber Security, or a related field. 2-4 years combined experience... ..., topologies (3‑tier, SD‑Access)....CyberWork at office- ...Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency... ...and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret...Work at office
$100k - $120k
...position: Sr. Cybersecurity Incident Response Specialist Location – Washington... ...Member of the SOC team which provides 24 hours per day... ...triaging, and responding to cyber incidents across enterprise networks... ..., mentor junior analysts, and collaborate with cross-functional...CyberFull timeContract workWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Incident Response Team Analyst (Tier 2). Be the first to apply!






