Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Detection Analyst

6AM City, LLC

Description Tyto Athene is searching for an Incident Detection Analyst to support our customer in Washington, DC. Responsibilities Accurately review, annotate, and resolve security incidents tasked by the Intrusion Detection Team, Watch Officer, SOC management or other SOC teams 24 hours a day, 7 days a week, which is subject to change based on AOUSC needs. Conduct Incident Triage to prioritize newly identified security incidents for follow‑on action. Identify all relevant data sources for initial collection to determine prioritization and resource application based on the criticality of the incident and conduct immediate actions to evaluate and contain threats as necessary in accordance with the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), Incident Response Operations Guide, and any other published SOC operations guides and manuals. Please see SLA SOC3. Perform deep dive analysis (manual and automated) of malicious links and files. Ensure efficient configuration and content tuning of shared SOC security tools to eliminate or significantly reduce false alert events. Provide Executive Summary in accordance to IDT Operations Guide. Provide 5W briefing slides for each event for leadership briefing. Provide on‑demand time/trend/event based metric reports for SOC management. Provide clear and actionable event notifications to customers. Notifications to customers will be clear and provide sufficient detail for a mid‑level system or network administrator to understand what has occurred and what needs to take place to remediate the event. Coordinate and provide direct support to local incident responders at the circuit, local court unit and program office levels. Provide notifications, guidance and end‑to‑end incident response support to local incident responders to ensure that the appropriate actions are properly taken to detect, contain, eradicate and recover from identified security incidents. Coordinate with various other SOC teams to leverage the appropriate resources to enable local incident responders. Participate in course of action (COA) development and execution as necessary. Document all communications and actions taken in response to assigned incidents in the SOC ticketing system. Ensure tickets are properly updated in a timely manner and all artifacts are included. Escalate any concerns or requests through the Contractor management as necessary. Directly support the Judiciary Special Tactics and Active Response (JSTAR) team and provide incident response support for critical security incidents as they arise. Perform appropriate event escalation for events, notifications, and non‑responsiveness from customers. Contractors shall track all notifications in the SOC ticketing system and escalate tickets to Watch Officers or SOC management in cases where the customer is non‑responsive or requires clarification that is outside the scope of normal operations. Contractors will be familiar with the JSOCIRP escalation and reporting procedures. Continuously review and update the Incident Handlers (IH) Guide and provide recommendations for annual updates for the JSOCIRP. All SOPs and Op Guides are federal government property. Contract staff provide recommendations in draft form for federal management review, approval and adoption. Incident Responders must be able to perform the tasks and meet the skills, knowledge and abilities as described in NIST Special Publication 800‑181 National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework for the role of Cyber Defense Incident Responder. Qualifications Required 6 years of security intrusion detection examination experience involving a range of security technologies that produce logging data; to include wide area networks, host and Network IPS/IDS/HIPs traffic event review, server web log analysis, raw data logs. Ability to communicate clearly both orally and in writing. Working experience with Splunk SIEM. At least three years of experience working at a senior level, performing analytics examination of logs and console events and creating advanced queries methods in Splunk or advanced Grep skills, firewall ACL review, examining Snort based IDS events, Pcaps, web server log review, in SIEM environments. Education/Certifications Bachelor's degree in information systems, Computer Science or related field is preferred. Splunk Fundamentals I & II certification. Clearance Public Trust Hours of Operation/Shift Monday‑Friday 3PM EST – 11:30PM EST Compensation Compensation is unique to each candidate and relative to the skills and experience they bring to the position. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above‑stated range. Benefits Health/Dental/Vision 401(k) match Paid Time Off STD/LTD/Life Insurance Referral Bonuses Professional development reimbursement Parental leave Equal Opportunity Statement Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any characteristic protected by applicable law. #J-18808-Ljbffr 6AM City, LLC

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Incident Detection Analyst in Washington DC vacancy
  •  .... Government customer to provide onsite incident response to civilian agencies and critical...  .... Apply cybersecurity concepts to detection and defense of intrusions into IT networks...  ...compromise (IOCs), and escalating to specialized analysts as needed. Required Skills U.S.... 
    Suggested
    Shift work
    Night shift
    Weekend work

    hackajob

    Arlington, VA
    3 days ago
  •  ...Global Solutions in Washington, DC is seeking a Senior Security Operations Analyst to monitor and respond to cybersecurity threats. The candidate will analyze security events, manage incident response, and support the National Indian Gaming Commission's cybersecurity... 
    Suggested

    Terrestris Global Solutions

    Washington DC
    5 days ago
  •  .... Government customer to provide onsite incident response to civilian government agencies...  ...incidents. Apply cybersecurity concepts to detect and defend intrusions into small and...  ...compromise (IOCs) and escalation to specialized analysts. Required Skills U.S. citizenship.... 
    Suggested
    Contract work
    Immediate start
    Shift work

    Limelight Health

    Arlington, VA
    3 days ago
  •  ...customer to provide support for onsite incident response to civilian Government agencies...  ...Applying cybersecurity concepts to the detection and defense of intrusions into small, and...  ...Compromise (IOCs), escalating to specialized analysts Required Skills: - Must have an active... 
    Suggested
    Contract work
    Immediate start
    Shift work

    Nightwing

    Arlington, VA
    3 days ago
  • Tyto Athene, LLC seeks an Incident Detection Analyst in Washington, DC, to review and resolve security incidents 24/7. Responsibilities include conducting incident triage, deep dive analysis, and providing clear notifications to local incident responders. The ideal candidate... 
    Suggested
    Local area

    6AM City, LLC

    Washington DC
    4 days ago
  • $131.3k - $237.35k

     ...and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland...  ...is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial... 
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Arlington, VA
    8 hours ago
  • $131.3k - $237.35k

     ...customers through scale and repeatability. This role is a Senior Incident Response Analyst supporting the DHS CISA Program within the Department of...  ..., SIEM, etc.) to reduce false positives and improve SOC detection capabilities Document Investigation and Incident Response... 
    Flexible hours

    Leidos

    Arlington, VA
    3 days ago
  • $128.1k - $239.6k

     ...Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk,...  ...enterprise security.   In an Active Defense Analyst, we are looking for someone who has...  ...threat intelligence, intrusion analysis, incident response, malware analysis, security and... 
    Summer holiday
    Local area
    Remote work
    Flexible hours
    Night shift
    Weekend work

    EY

    Washington DC
    3 days ago
  •  ...Full-Time Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military...  ...operations. Familiarity with security logging, threat detection, response coordination, and post-incident reporting.... 
    Full time
    Contract work
    Part time
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    3 days ago
  • Manager, Detection and Response Services Are you passionate about growing and supporting teams of threat analysts? How about leading the charge against adversaries across a dynamic and...  ...real-time threat detection and incident response for our customers. This role... 
    Local area
    Shift work

    Divvy Cloud Corp.

    Arlington, VA
    4 days ago
  • $120k - $145k

     ...Corporation is looking for an experienced Information Security Analyst (SME) to join their team in Washington, DC. The ideal candidate...  ...Degree and over 4 years of experience in security analysis and incident response. Responsibilities include maintaining threat awareness... 

    Cape Fox Corporation

    Washington DC
    2 days ago
  • $128k - $160k

    A leading law firm is seeking an Information Security Analyst III in Washington, DC. This role is crucial for monitoring security threats, analyzing incidents, and advising on security controls to protect the organization's IT infrastructure. Candidates should possess... 

    Dechert LLP

    Washington DC
    3 days ago
  • Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military Community and Family Policy...  ...operations. Familiarity with security logging, threat detection, response coordination, and post-incident reporting.... 
    Contract work
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    5 days ago
  • $73.6k - $130.3k

     ...training and more. Join us to drive positive, lasting change that moves missions and the government forward! The Business Operations Incident Analyst (Revenue Cycle) serves as a key problem solver and investigator for issues impacting business and financial operations within... 
    Live in
    Work at office
    Local area

    Accenture Federal Services

    Washington DC
    2 days ago
  •  ...specialist with specific skills in intrusion detection/prevention and cybersecurity tools...  ...threats. Providing detailed triage of CSSP/IR incidents including implementing intrusion...  ...CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr Bespoke Corps LLC
    Work at office
    Monday to Friday
    Weekend work

    Bespoke Corps LLC

    Arlington, VA
    3 days ago
  •  ...firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site...  ...DoD customers, possessing technical skills in intrusion detection and prevention, and will have a BS in a relevant field. Responsibilities... 

    Bespoke Corps LLC

    Arlington, VA
    1 day ago
  • Tyto Athene is searching for a Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington, DC. Our IR analysts...  ...development, implementation, and tuning of the SOC tools detection content and alerting signatures. Accurately document triage... 
    Part time
    Shift work
    Night shift
    Weekend work
    Day shift
    2 days per week

    Tyto Athene, LLC

    Washington DC
    2 days ago
  • $110k - $160k

    CHAOS Industries in Washington, D.C. is looking for a SOC Analyst II to join the Security Operations team. This role involves monitoring, investigating, and responding to security alerts across enterprise systems. The ideal candidate will have 3-5 years of experience in... 

    Chaos, Inc.

    Washington DC
    3 days ago
  • $127k - $140k

     ...Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with...  ...Responsibilities Reporting to the Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active cyber conflict—... 
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Work from home
    Home office
    Flexible hours

    Deepwatch

    Washington DC
    3 days ago
  • $100k - $145k

     ...Dark Wolf Solutions is seeking a Defensive Cyber Operations Analyst in Washington, DC. This role involves continuous system monitoring...  ...threats, with responsibilities including vulnerability management, incident response, and drafting documentation. The ideal candidate will... 

    Dark Wolf

    Washington DC
    22 hours ago
  • $166k - $220k

     ...defense technology company is seeking a Security Operations Analyst in Washington, D.C. The role involves monitoring alerts and responding to incidents across various environments, focusing on optimization of detection signatures and threat hunting. Candidates should have... 

    Anduril

    Washington DC
    5 days ago
  • $80.2k - $111.3k

     ...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex...  ...the organization's ability to prevent, detect, and rapidly respond to sophisticated adversarial...  ...coaching to incident handlers and SOC analysts, elevating investigative techniques,... 
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    6 days ago
  • $320k - $405k

     ...together to build beneficial AI systems. About the Role The Detection & Response (D&R) team plays a critical role in protecting our...  ...for an experienced Technical Program Manager to own and evolve incident management within D&R. This is a senior-level specialization on... 
    Work at office
    Immediate start
    Visa sponsorship
    Flexible hours
    Shift work

    aijoblist

    Washington DC
    4 days ago
  • $100k - $120k

    SkyePoint Decisions is looking for an Incident Detection/Response Manager (SOC Manager) to support the Department of Education’s Cybersecurity efforts. This remote position demands 8+ years in IT, supervising incident response operations, and a necessity for certifications... 
    Remote job

    SkyePoint Decisions

    Washington DC
    3 days ago
  •  ...policies. • Cybersecurity Assessment Expertise: Evaluates incident response readiness, vulnerability management, MFA enforcement,...  ...platforms such as Microsoft Sentinel to assess visibility and detection gaps. • Vulnerability & Risk Analysis: Conducts vulnerability... 

    Potomac Management Solutions, LLC

    Washington DC
    1 day ago
  • A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience... 
    Remote job

    Cyber Synergy Consulting Group

    Washington DC
    2 days ago
  •  ...and map adversary TTPs to ATT&CK tactics and techniques during incident triage and reporting. Demonstrated experience performing IP...  ...stakeholders. Manage incident triage and coordination with analysis and detection sections to identify and analyze technology and cyber impacts... 

    Peraton

    Arlington, VA
    2 days ago
  • $258 - $314 per day

     ...Operations and Vulnerability Management Analyst PAHO is searching for an independent...  ...Program, with focus on security monitoring, incident response, threat hunting, and...  ...Security Operations capability to improve the detection, analysis, response, and coordination of... 
    Daily paid
    Full time
    Contract work
    For contractors
    Work at office

    Pan American Health Organization

    Washington DC
    1 day ago
  •  ...and proactive Information System Security Analyst to join our IT department. This critical...  ...vulnerabilities, responding to incidents, and ensuring compliance with security standards...  .... Key Responsibilities Monitoring and Detection: Monitor the organization's networks and... 

    Tla Llc

    Washington DC
    1 day ago
  • $131.3k - $237.35k

     ...better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Incident Response Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD organizations... 
    Local area
    Immediate start

    Leidos

    Alexandria, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Detection Analyst. Be the first to apply!