Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Tier 2 Cyber Incident Responder (Shift Lead)

AGR LLC

Job Description

Job Description

Location: Beltsville, Maryland.

Clearance: Secret

ICS (a REDHAWK company) is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join the Federal Strategic Cyber Mission program.

Location: Beltsville, MD; On-site

Work Hours: Day Shift, 06:00– 14:00 EST (6:00 - 2:00 PM, EST), Tuesday - Saturday

In this role, you will:

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

Additionally, as a Tier 2 Shift Lead you will:

  • Review all Tier 2 shift tickets for accuracy and completeness
  • Coordinate with CIRT Watch Officers and government leadership on remediation actions
  • Provide technical and procedural improvement recommendations to CIRT leadership
  • Assist with Tier 2 candidate technical interviews as required
  • Ensure coordinated remediation actions are operating properly

Minimum Qualifications

  • Bachelor’s degree and minimum of 9 years of relevant experience; or, Master’s degree with minimum of 7 years; or PhD with 4 years. In lieu of a degree, 4 years of additional experience may be considered.
  • Must possess, or obtain prior to start date, at least one of the following certifications. Continued certification is required as a condition of employment:
    • CASP+ CE; CCNA Cyber Ops; CCNA-Security; CCNP Security; CEH; CFR; CHFI; CISA;CISSP (or Associate); CISSP-ISSAP; CISSP-ISSEP; CySA+; GCED; GCFA; GCIH; SCYBER

  • Demonstrated experience across the incident response lifecycle.
  • Experience with SOAR platforms and automated response workflows (e.g., ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, Elastic, QRadar).
  • Experience with Endpoint Detection and Response (EDR) solutions (e.g., Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating indicators of compromise (IOCs) and tracking advanced persistent threat (APT) actors.
  • Ability to analyze cyber threat intelligence and understand adversary tactics, techniques, and procedures (TTPs).
  • Knowledge of malware analysis techniques.
  • Familiarity with MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Secret security clearance required at start.

Preferred Qualifications:

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Experience using Microsoft Azure access and identity management.
  • Proficiency in Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience using digital forensics collection and analysis tools (e.g. Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience using ServiceNow SOAR for ticketing and automated response.
  • Experience using Python, PowerShell and BASH scripting languages.
  • Proficiency in cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
Vacancy posted 9 days ago
Similar jobs that could be interesting for youBased on the Tier 2 Cyber Incident Responder (Shift Lead) in Beltsville, MD vacancy
  • ICS (a REDHAWK company) seeks an experienced Tier 2 Cyber Incident Response Team Shift Lead in Beltsville, MD to join the Federal Strategic Cyber Mission program. You will lead Tier 2 shift operations, review tickets for accuracy, and coordinate with CIRT Watch Officers... 
    Shift work
    Cyber

    AGR, LLC

    Beltsville, MD
    2 days ago
  • Twenty8 Technology, LLC in Beltsville, MD is seeking a Tier 2 Cyber Incident Response Team Shift Lead to join the Federal Strategic Cyber Mission program. The role involves leading Tier 2 responses, coordinating with government leadership, and ensuring remediation actions... 
    Shift work
    Cyber

    Twenty8 Technology, LLC

    Beltsville, MD
    4 days ago
  • SkyePoint Decisions seeks a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program. The role is...  ...-site in Beltsville, MD, with mid-shift hours (22:00-6:00 EST) five days a week. You will detect and respond to cyber events, analyze logs, perform... 
    Shift work
    Cyber

    SkyePoint Decisions

    Laurel, MD
    4 days ago
  • $90k - $107k

    SkyePoint Decisions is a leading Cybersecurity...  ...is seeking a CIRT Tier 2 Analyst to...  ...Diplomatic Security Cyber Mission (DSCM) program...  .... Work Hours:Mid Shift, 22:00- 6:00 EST,...  ...security events and incidents. Perform advanced...  ...teams to analyze and respond to events and... 
    Shift work
    Cyber
    Contract work
    Local area
    Remote work

    SkyePoint Decisions

    Laurel, MD
    4 days ago
  •  ...Operations / Desktop Engineer (Tier 2.5) Location:...  ...Schedule: 1:30pm - 10:00pm Shift.  The shift hours may...  ...health checks, and respond to operational issues....  ..., maintenance support, incident response, and coordination...  ...Engineering, Cloud Solutions, Cyber Security, and IT... 
    Shift work
    Cyber
    Full time
    Work at office
    Flexible hours

    ActioNet, Inc.

    Washington DC
    5 days ago
  • $80k - $128k

     ...experienced CIRT Tier 1 Analyst to...  ...Federal Strategic Cyber Mission program....  ...4:00 (6:00 AM - 2:00 PM) / TUE-SAT...  ...security events and incidents. Perform triage...  ...to analyze and respond to events and...  ...activities.Conduct shift change briefs....  ...As the world’s leading mission capability... 
    Shift work
    Cyber
    Contract work
    Local area

    Peraton Corporation

    Beltsville, MD
    2 days ago
  • $80k - $128k

     ...an experienced CIRT Tier 1 Analyst to join...  ...Federal Strategic Cyber Mission program. Location...  ...events and incidents. Perform triage of...  ...needed to analyze and respond to events and incidents...  .... Conduct shift change briefs. Qualifications...  ...and at least 2 years of... 
    Shift work
    Cyber
    Contract work
    Local area

    Peraton

    Beltsville, MD
    2 days ago
  •  ...Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder...  ...improvement to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,... 
    Cyber
    Contract work
    Flexible hours

    Evolver

    Washington DC
    2 days ago
  • Lead advanced investigations involving ransomware, APTs, zero-day...  .... Perform full lifecycle incident response including detection,...  ...leadership and mentoring to Tier 1 and Tier 2 analysts. Support management...  ...MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 80... 
    Cyber
    Work at office

    OneMain Financial

    Washington DC
    3 days ago
  •  ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and...  ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat Dashboard... 
    Cyber
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    1 day ago
  • $120k - $145k

     ...currently seeking a Incident Response (IR)...  ...team comprised of IR Tier-1, IR Tier-2, and Forensics specialists...  ...Operations Task Lead. Responsibilities...  ...team of around 20 cyber security...  ...after action reports, shift change and daily...  ...support to identify and respond to potentially... 
    Shift work
    Cyber
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  • $80k - $128k

    Peraton is looking for an experienced CIRT Tier 1 Analyst to join its Federal Strategic Cyber Mission program in Beltsville, MD. The role involves tracking cybersecurity events, managing incidents, and coordinating with various teams. Candidates should have a Bachelor's... 
    Cyber
    Full time

    Peraton

    Beltsville, MD
    2 days ago
  • $86.6k - $181.8k

    Job Title: Team Lead- Network Operations - Tier 2Job Category: Information TechnologyTime Type: Full timeMinimum...  ...:As a Team Lead of our Tier 2 Network Operations technicians, you'...  ...network components to research errors, incidents, problems and to perform incident analysis... 
    Contract work
    Work experience placement
    Remote work
    Flexible hours

    CACI International

    Washington DC
    2 days ago
  •  ...offload non-human work, shift people up, and...  ...Security Platform. As a Tier 3 Security Analyst...  ...data to support incident investigation as...  ..., evaluating risk Lead and mentor junior analysts...  ...the 7AI Agents responded to and understand...  ...years of experience in cyber security operations... 
    Shift work
    Cyber

    Seven AI

    Washington DC
    5 days ago
  • Imagineeer is seeking a NOC Tier 2 Technician to provide advanced technical support and troubleshooting for escalated network and system incidents within a 7x24 environment. You will act as a subject matter expert, resolving complex issues and mentoring Tier 1 staff. Responsibilities... 
    Night shift

    Imagineeer, LLC

    Washington DC
    1 day ago
  • $102.5k - $188.9k

    Our Deloitte Cyber team understands the unique challenges...  ...identify, analyze, and respond to exploitation activity...  ...activity, investigating incidents, assessing...  ...relationships Ability to lead projects or workstreams...  ...Top-Secret Clearance ~2+ years of experience within... 
    Cyber
    Work at office

    Deloitte LLP

    Maryland, MD
    6 days ago
  • $140k - $150k

     ...DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office /...  ...challenges facing the enterprise. This is a Tier 3 position, meaning you are the last...  ...reportingDeep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model... 
    Cyber
    Work at office
    Remote work

    ECS Federal

    Washington DC
    3 days ago
  •  ...Incident Response Lead At Leidos, we deliver innovative solutions through the efforts of our diverse...  ...to join our team on a highly visible cyber security single-award IDIQ vehicle...  ...monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial... 
    Cyber

    Leidos

    Washington DC
    1 day ago
  • $92k - $153k

    Job Family:IT Cyber SecurityTravel Required:Up to 10%Clearance...  ...Investigate potential security incidents using SIEM, endpoint,...  ...the ability to prioritize and respond to alerts in a fast-paced environment...  ....Have prior experience leading SOC shifts and mentoring jr. analysts.... 
    Shift work
    Cyber
    Full time
    Work experience placement
    Flexible hours

    Guidehouse

    Washington DC
    2 days ago
  • Edgewater Federal Solutions seeks a Tier II Incident Response Analyst to support a government contract. US citizenship is required for this role, with on-site work in Bethesda, MD. You will investigate incidents, analyze malware, and drive improvements to toolsets and... 
    Cyber
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  • $80k - $128k

    Responsibilities Peraton is seeking a Cyber IT Specialist - 1st Shift Lead to become part of our Federal Strategic Cyber Group. Location: Beltsville...  .... Diagnose and resolve customer-reported system incidents, problems, and events, keeping users informed of incident... 
    Shift work
    Cyber
    Contract work
    Day shift

    Peraton

    Beltsville, MD
    3 days ago
  •  ...Mandatory: ~ Must be capable of providing Tier 2 support for USAidam systems, resolving...  .../local District IT cannot resolve, leading operation of the USAidam Helpdesk, managing...  .../deprovisioning; privileged access; incident/ticket management; SLA management; user training... 
    Full time
    Work experience placement
    Local area

    Wits Solutions Inc

    Washington DC
    3 days ago
  • Peraton is seeking a Cyber IT Specialist for 2nd shift in Beltsville, MD. The role requires IT operations experience, ServiceNow and monitoring tool familiarity, and the ability to coordinate incident response while ensuring data integrity. Candidates must be US citizens... 
    Shift work
    Cyber
    Afternoon shift

    Peraton

    Beltsville, MD
    4 days ago
  • $85k - $110k

     ...Federal Solutions is currently seeking a Tier II Incident Response Analyst to provide support to...  ...process efficiencies. Familiarity with Cyber Kill Chain and ATT&CK Framework and how...  ...experience performing monitoring and responding to threats in Cloud environments. 5+ years... 
    Cyber
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  • $66k - $106k

     ...Peraton is seeking a 1st Shift - Data Center IT...  ...become part of Peraton’s leading cyber and technology security...  ...shift, from 6:00 AM - 2:00 PM, EST. What you’...  ...service request in-boxes and respond within 30 minutes of...  ...resolve customer-reported incidents, problems, and events,... 
    Shift work
    Cyber
    Contract work
    For contractors
    Day shift

    Peraton

    Beltsville, MD
    1 day ago
  • $100k - $120k

     ...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 
    Cyber

    Bering Straits Native Corporation

    Washington DC
    3 days ago
  •  ...Description Job Description Provides Tier 2 desktop support (telephone, deskside, remote...  ..., tracks, resolves, and reports on incidents and requests using ServiceNow. Has advanced...  ...infrastructure, with the focus on Cloud, Cyber, Enterprise IT, Systems Engineering and United... 
    Cyber
    Work at office
    Remote work

    AAC

    Washington DC
    20 days ago
  • $30 - $45 per hour

     ...design, build, operate, and maintain cyber-physical solutions for the nation's...  ...or federally owned facility). Shift Availability: ~1st shift- 6:00am-2:30pm, Monday-Friday ~2nd shift-1...  ...deficiencies, and other unusual occurrences. Respond to emergency situations and perform... 
    Shift work
    Cyber
    Apprenticeship
    Relocation
    Monday to Friday
    Night shift
    Day shift
    Afternoon shift

    M.C. Dean

    Washington DC
    2 days ago
  •  ...applications development, infrastructure, Cyber security, and enterprise content/data...  ...DescriptionJob Description:There will be one Shift Lead in each shift. A Lead is the subject...  ...Task Lead is the single point of final incident reporting review and escalation. The Task... 
    Shift work
    Cyber
    For contractors
    Work experience placement

    Comtech

    Washington DC
    20 hours ago
  •  ...Job Description IT Service Desk Team Lead (Tier 2/3) – Active TS/SCI Required Location...  ...peripherals. Maintain accurate ticket, incident, inventory, and operational...  ...Previous experience as a team lead, shift lead, technical lead, senior technician,... 
    Shift work
    Full time
    Immediate start

    Tenacity Solutions LLC

    Washington DC
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Tier 2 Cyber Incident Responder (Shift Lead). Be the first to apply!