Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Response Team Analyst (Tier 2)

AGR LLC

Job Description

Job Description

Location: Beltsville, MD

Work Hours: Evening Shift, 1400 – 2200 EST, TUE-SAT

Program Overview

The DSCM program encompasses cyber security, data analytics, engineering, technical, managerial, operational, logistical and administrative support to aid and advise DOS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats. Those supporting the DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.

About the Role

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

Qualifications:

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date:
    • A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.
  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.

Preferred Qualifications:

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.

Vacancy posted 29 days ago
Similar jobs that could be interesting for youBased on the Cyber Incident Response Team Analyst (Tier 2) in Beltsville, MD vacancy
  • $90k - $107k

     ...Decisions is seeking a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program...  ...:00 EST, TUES-SAT. Responsibilities: Detect, classify...  ...security events and incidents. Perform advanced...  ...Department of State teams to analyze and respond... 
    Cyber
    Contract work
    Local area
    Remote work
    Shift work

    SkyePoint Decisions

    Beltsville, MD
    9 days ago
  •  ...recognized members of the Cyber Elite, we work...  ...to the belief that our team members do their best...  ...We are seeking a  Tier 2 Analyst for a potential opportunity...  ...cybersecurity to improve incident detection, analyze threat...  ...support detection and response. Support incident... 
    Cyber
    Contract work

    ShorePoint

    Washington DC
    2 days ago
  • $131.3k - $237.35k

     ...our customers’ success. We empower our teams, contribute to our communities, and...  ...Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department...  ..., mitigating, and responding to cyber threats and adversarial activity on... 
    Cyber
    Flexible hours

    Leidos

    Bethesda, MD
    3 days ago
  •  ...A global cybersecurity consultancy is seeking an Incident Response Engagement Lead to manage cyber incidents and lead a team of experts. The role involves project management, relationship building, and effective incident response. Ideal candidates should possess strong... 
    Cyber
    Full time

    S-RM Intelligence and Risk Consulting

    Washington DC
    6 hours ago
  • $83.5k - $87.5k

    Cayuse Holdings is seeking a Cyber Incident Response Analyst in Washington, DC to enhance the cybersecurity framework. This role involves case management...  ...and CompTIA Security+ certification, with between 0-2 years of experience. The Analyst will work in a professional... 
    Cyber

    Cayuse Holdings

    Washington DC
    4 days ago
  • cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance... 
    Work at office

    cFocus Software Incorporated

    Washington DC
    4 days ago
  • $7.5k

     ...malware analysis. Two (2) years of demonstrated...  ...0 compliance with CSSP Analyst Baseline certification....  ..., Kibana, Advanced Cyber Defense Course, and other...  ...of the role's responsibilities, the candidate's educational...  ...Department of Defense, with team members located... 
    Cyber
    Contract work
    Part time
    Work experience placement
    Immediate start
    Flexible hours

    RealmOne

    Columbia, MD
    6 hours ago
  • $83.5k - $87.5k

    Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client’s cybersecurity framework...  ...(SOPs). Escalate cases to specialized teams (e.g., Threat Hunting, Vulnerability...  ...best practices. Additional (2) two years of experience may be substituted... 
    Cyber
    Temporary work
    Work at office
    Local area
    Flexible hours
    Shift work

    Cayuse Holdings

    Washington DC
    2 days ago
  • $65k - $85k

     ...Consultants (CTC) is seeking Tier 2 Technical Support to...  ..., Test Automation, Cyber Security, and...  ...Washington, DC Daily Responsibilities:   Provide professional...  ...used with Microsoft Teams, etc.). Offer consulting...  ...experience with Incident, Change, or Knowledge... 
    Cyber
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    CTC

    Washington DC
    8 days ago
  • $7.5k

     ...Brief Exploitation, network, cyber Job Description RealmOne is...  ...opportunity supports a team of Exploitation Analysts, Digital Network Exploitation...  ...Network Defense Analysts, responsible for improving, protecting,...  ...administration. The Level 2 Exploitation Analyst shall... 
    Cyber
    Contract work
    Work experience placement
    Immediate start
    Flexible hours

    RealmOne

    Columbia, MD
    1 day ago
  •  ...Job Description Job Description Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)...  ...across multiple federal cybersecurity teams. The ideal candidate has hands-on experience...  .... Required Qualifications ~2–5+ years of experience in cybersecurity... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy Consulting Group

    Washington DC
    19 days ago
  • $60k - $100k

     ...cybersecurity operations and a bachelor's degree in a related field. The role involves leading incident response efforts, documenting actions, and collaborating with technical teams to enhance security across multiple environments. Competitive salary range from $60,000 to... 
    Cyber

    MAXIMUS

    Washington DC
    2 days ago
  • Cayuse is hiring a Cyber Incident Response Analyst in Washington, DC. This role is critical for reinforcing the client’s cybersecurity framework, managing...  ...incidents, and collaborate closely with various teams while maintaining high-quality customer service. Candidates... 
    Cyber

    UNAVAILABLE

    Washington DC
    3 days ago
  • $7.5k

     ...to work with a RESILIENT team at RealmOne? RealmOne...  ...supports a team of Target Analyst Reporters, Collection Managers...  ...reporting vehicles, in response to mission requirements....  ...Analyst Reporter Level 2 shall possess the...  ...mission (e.g. collection, cyber and intelligence analysis... 
    Cyber
    Contract work
    Work experience placement
    Immediate start
    Flexible hours

    RealmOne

    Columbia, MD
    4 days ago
  •  ...exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United...  ...demand than ever. We’re building a team to meet this challenge. We’re quick...  ...’ve built a team of intelligence analysts, technical specialists, software developers... 
    Cyber
    Full time
    Immediate start
    Flexible hours

    S-RM Intelligence and Risk Consulting

    Washington DC
    6 hours ago
  •  ...Job Description Provides Tier 2 desktop support (telephone, deskside...  ..., resolves, and reports on incidents and requests using ServiceNow....  ...Escalates incident to the appropriate team when the incident cannot be...  ..., with the focus on Cloud, Cyber, Enterprise IT, Systems... 
    Cyber
    Work at office
    Remote work

    AAC

    Washington DC
    24 days ago
  • $130k - $135k

     ...Hands‑on experience performing responsibilities aligned to incident response, security...  ...engineering, threat hunting, or cyber threat intelligence. Must...  ...a weekend schedule. ( 2 nd Shift WEEKEND schedule,...  ...collaboration, and respect for all team members, ensuring that WWT... 
    Cyber
    Full time
    Remote work
    Flexible hours
    Shift work
    Weekend work
    Afternoon shift

    World Wide Technology

    Adelphi, MD
    3 days ago
  • $60k - $180k

     ...Delivery & Analytics, Cyber Security, Cloud...  ...a Business Analyst to work onsite in...  ...clearance is required. Responsibilities Analyze business...  .... Support Tier 1 and Tier 2 operational services...  ...and maintain incident management, escalation...  ..., operational teams, and technical resources... 
    Cyber
    Full time
    Contract work
    For subcontractor

    M9 Solutions

    Bethesda, MD
    4 days ago
  •  ...Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda,...  ...(IOCs). Support Cyber Threat Intelligence (CTI) activities...  ...across technical teams. Commitment to continuous...  ..., state, or local law. #M-2 #LI-CK1 Ref: #856-Baltimore... 
    Cyber
    Local area

    System One

    Bethesda, MD
    7 days ago
  • $140k - $175k

     ...to apply for the SOC Analyst - Top Secret Clearance...  ...Zachary Piper Solutions 2 days ago Be among the...  ...assessments, improving incident response protocols, and ensuring...  ...knowledge and fulfill team deliverables. Support...  ...Holidays Keywords: Cyber Analyst, SOC Analyst, Security... 
    Cyber
    Full time
    Contract work

    Zachary Piper Solutions

    Washington DC
    6 hours ago
  • Job Overview A law firm seeks a Cyber Incident Response Associate Attorney in Washington, DC. This role involves managing cybersecurity incidents...  ...skills. Ability to work in a fast‑paced environment. Team player. Education JD from an accredited law school. Certifications... 
    Cyber
    Flexible hours

    BCG Attorney Search

    Washington DC
    4 days ago
  • $160k - $190k

     ...be valued and empowered, then we invite you to apply to our Cyber Incident Response Associate Attorney position in our Washington, D.C. Office....  ...and Westlaw) Ability to work in a fast‑paced environment Team player Salary Range $160,000 - $190,000 USD Benefits Wilson... 
    Cyber
    Full time
    Work at office
    Flexible hours

    Wilson Elser Moskowitz Edelman & Dicker LLP

    Washington DC
    4 days ago
  • $160k - $190k

     ...Washington, D.C. - Flexible hybrid working arrangement. Key Responsibilities Incident response for cybersecurity and data privacy incidents...  ...and Westlaw) Ability to work in a fast‑paced environment Team player Salary & Benefits Salary Range: $160,000 USD - $190... 
    Cyber
    Full time
    Flexible hours

    Wilson Elser

    Washington DC
    1 day ago
  • $160k - $190k

     ...a flexible, hybrid working arrangement. The Position Key Responsibilities Incident response for cybersecurity and data privacy incidents Analysis...  ...and Westlaw) Ability to work in a fast-paced environment Team player Wilson Elser offers a competitive salary and... 
    Cyber
    Full time
    Flexible hours

    Wilson Elser - Attorneys

    Washington DC
    3 days ago
  •  ...Support Specialist – Level 2 Port Cyber is seeking to grow its technical team to keep pace with its...  ...Services group will be responsible for ensuring all client...  ...are:   Tier 1 and 2 Issue Resolution...  ...to and resolve client incidents via remote and on-site... 
    Cyber
    Work at office
    Local area
    Remote work
    Relocation

    Port Cyber Corporation

    Kensington, MD
    27 days ago
  •  ...Job Description Job Description Incident Response Expert IV (Cyber Eviction Analysts) Location: Washington Dc Metro Area (On-Site) Citizenship: US only...  ...and critical infrastructure owners nationwide. Our teams deliver rapid incident response, advanced forensics,... 
    Cyber
    Local area
    Immediate start

    Argo Cyber Systems

    Washington DC
    29 days ago
  • $140k - $160k

     ...in 2000, is a leading cyber operations, intelligence...  ...Operational Language Analyst - Turkish, level 2with...  ...SCI w/ Poly to join our team working in Annapolis Junction...  ...SIGINT Operations. RESPONSIBILITIES Recovering essential...  ...Associate’s degree or 2 additional yrs of work... 
    Cyber
    Full time
    Contract work
    Work experience placement

    Acclaim Technical Services

    Annapolis Junction, MD
    11 days ago
  • $59.15k - $106.93k

     ...a large Engineering team entrusted with evolving...  ...this role will be responsible for the design,...  ...Respond to network incidents, troubleshoot network...  ...Information Systems, Cyber Security, or a related field. 2-4 years combined experience...  ..., topologies (3‑tier, SD‑Access).... 
    Cyber
    Work at office

    Leidos Inc

    Greenbelt, MD
    1 day ago
  •  ...Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency...  ...and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret... 
    Work at office

    CORTEK Inc

    Washington DC
    4 days ago
  • $100k - $120k

     ...position: Sr. Cybersecurity Incident Response Specialist Location – Washington...  ...Member of the SOC team which provides 24 hours per day...  ...triaging, and responding to cyber incidents across enterprise networks...  ..., mentor junior analysts, and collaborate with cross-functional... 
    Cyber
    Full time
    Contract work
    Work at office
    Local area

    BERING STRAITS PROFESSIONAL SERVICES LLC

    Washington DC
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Response Team Analyst (Tier 2). Be the first to apply!