Incident Detection Analyst
6AM City, LLC
Description Tyto Athene is searching for an Incident Detection Analyst to support our customer in Washington, DC. Responsibilities Accurately review, annotate, and resolve security incidents tasked by the Intrusion Detection Team, Watch Officer, SOC management or other SOC teams 24 hours a day, 7 days a week, which is subject to change based on AOUSC needs. Conduct Incident Triage to prioritize newly identified security incidents for follow‑on action. Identify all relevant data sources for initial collection to determine prioritization and resource application based on the criticality of the incident and conduct immediate actions to evaluate and contain threats as necessary in accordance with the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), Incident Response Operations Guide, and any other published SOC operations guides and manuals. Please see SLA SOC3. Perform deep dive analysis (manual and automated) of malicious links and files. Ensure efficient configuration and content tuning of shared SOC security tools to eliminate or significantly reduce false alert events. Provide Executive Summary in accordance to IDT Operations Guide. Provide 5W briefing slides for each event for leadership briefing. Provide on‑demand time/trend/event based metric reports for SOC management. Provide clear and actionable event notifications to customers. Notifications to customers will be clear and provide sufficient detail for a mid‑level system or network administrator to understand what has occurred and what needs to take place to remediate the event. Coordinate and provide direct support to local incident responders at the circuit, local court unit and program office levels. Provide notifications, guidance and end‑to‑end incident response support to local incident responders to ensure that the appropriate actions are properly taken to detect, contain, eradicate and recover from identified security incidents. Coordinate with various other SOC teams to leverage the appropriate resources to enable local incident responders. Participate in course of action (COA) development and execution as necessary. Document all communications and actions taken in response to assigned incidents in the SOC ticketing system. Ensure tickets are properly updated in a timely manner and all artifacts are included. Escalate any concerns or requests through the Contractor management as necessary. Directly support the Judiciary Special Tactics and Active Response (JSTAR) team and provide incident response support for critical security incidents as they arise. Perform appropriate event escalation for events, notifications, and non‑responsiveness from customers. Contractors shall track all notifications in the SOC ticketing system and escalate tickets to Watch Officers or SOC management in cases where the customer is non‑responsive or requires clarification that is outside the scope of normal operations. Contractors will be familiar with the JSOCIRP escalation and reporting procedures. Continuously review and update the Incident Handlers (IH) Guide and provide recommendations for annual updates for the JSOCIRP. All SOPs and Op Guides are federal government property. Contract staff provide recommendations in draft form for federal management review, approval and adoption. Incident Responders must be able to perform the tasks and meet the skills, knowledge and abilities as described in NIST Special Publication 800‑181 National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework for the role of Cyber Defense Incident Responder. Qualifications Required 6 years of security intrusion detection examination experience involving a range of security technologies that produce logging data; to include wide area networks, host and Network IPS/IDS/HIPs traffic event review, server web log analysis, raw data logs. Ability to communicate clearly both orally and in writing. Working experience with Splunk SIEM. At least three years of experience working at a senior level, performing analytics examination of logs and console events and creating advanced queries methods in Splunk or advanced Grep skills, firewall ACL review, examining Snort based IDS events, Pcaps, web server log review, in SIEM environments. Education/Certifications Bachelor's degree in information systems, Computer Science or related field is preferred. Splunk Fundamentals I & II certification. Clearance Public Trust Hours of Operation/Shift Monday‑Friday 3PM EST – 11:30PM EST Compensation Compensation is unique to each candidate and relative to the skills and experience they bring to the position. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above‑stated range. Benefits Health/Dental/Vision 401(k) match Paid Time Off STD/LTD/Life Insurance Referral Bonuses Professional development reimbursement Parental leave Equal Opportunity Statement Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any characteristic protected by applicable law. #J-18808-Ljbffr 6AM City, LLC
- .... Government customer to provide onsite incident response to civilian agencies and critical... .... Apply cybersecurity concepts to detection and defense of intrusions into IT networks... ...compromise (IOCs), and escalating to specialized analysts as needed. Required Skills U.S....SuggestedShift workNight shiftWeekend work
- ...Global Solutions in Washington, DC is seeking a Senior Security Operations Analyst to monitor and respond to cybersecurity threats. The candidate will analyze security events, manage incident response, and support the National Indian Gaming Commission's cybersecurity...Suggested
- .... Government customer to provide onsite incident response to civilian government agencies... ...incidents. Apply cybersecurity concepts to detect and defend intrusions into small and... ...compromise (IOCs) and escalation to specialized analysts. Required Skills U.S. citizenship....SuggestedContract workImmediate startShift work
- ...customer to provide support for onsite incident response to civilian Government agencies... ...Applying cybersecurity concepts to the detection and defense of intrusions into small, and... ...Compromise (IOCs), escalating to specialized analysts Required Skills: - Must have an active...SuggestedContract workImmediate startShift work
- Tyto Athene, LLC seeks an Incident Detection Analyst in Washington, DC, to review and resolve security incidents 24/7. Responsibilities include conducting incident triage, deep dive analysis, and providing clear notifications to local incident responders. The ideal candidate...SuggestedLocal area
$131.3k - $237.35k
...and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland... ...is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial...Local areaImmediate startRemote workFlexible hours$131.3k - $237.35k
...customers through scale and repeatability. This role is a Senior Incident Response Analyst supporting the DHS CISA Program within the Department of... ..., SIEM, etc.) to reduce false positives and improve SOC detection capabilities Document Investigation and Incident Response...Flexible hours$128.1k - $239.6k
...Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk,... ...enterprise security. In an Active Defense Analyst, we are looking for someone who has... ...threat intelligence, intrusion analysis, incident response, malware analysis, security and...Summer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work- ...Full-Time Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military... ...operations. Familiarity with security logging, threat detection, response coordination, and post-incident reporting....Full timeContract workPart timeShift workNight shift
- Manager, Detection and Response Services Are you passionate about growing and supporting teams of threat analysts? How about leading the charge against adversaries across a dynamic and... ...real-time threat detection and incident response for our customers. This role...Local areaShift work
$120k - $145k
...Corporation is looking for an experienced Information Security Analyst (SME) to join their team in Washington, DC. The ideal candidate... ...Degree and over 4 years of experience in security analysis and incident response. Responsibilities include maintaining threat awareness...$128k - $160k
A leading law firm is seeking an Information Security Analyst III in Washington, DC. This role is crucial for monitoring security threats, analyzing incidents, and advising on security controls to protect the organization's IT infrastructure. Candidates should possess...- Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III team supporting Military Community and Family Policy... ...operations. Familiarity with security logging, threat detection, response coordination, and post-incident reporting....Contract workShift workNight shift
$73.6k - $130.3k
...training and more. Join us to drive positive, lasting change that moves missions and the government forward! The Business Operations Incident Analyst (Revenue Cycle) serves as a key problem solver and investigator for issues impacting business and financial operations within...Live inWork at officeLocal area- ...specialist with specific skills in intrusion detection/prevention and cybersecurity tools... ...threats. Providing detailed triage of CSSP/IR incidents including implementing intrusion... ...CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr Bespoke Corps LLCWork at officeMonday to FridayWeekend work
- ...firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site... ...DoD customers, possessing technical skills in intrusion detection and prevention, and will have a BS in a relevant field. Responsibilities...
- Tyto Athene is searching for a Tier 2 Incident Response Analyst (IR) to support a law enforcement customer in Washington, DC. Our IR analysts... ...development, implementation, and tuning of the SOC tools detection content and alerting signatures. Accurately document triage...Part timeShift workNight shiftWeekend workDay shift2 days per week
$110k - $160k
CHAOS Industries in Washington, D.C. is looking for a SOC Analyst II to join the Security Operations team. This role involves monitoring, investigating, and responding to security alerts across enterprise systems. The ideal candidate will have 3-5 years of experience in...$127k - $140k
...Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with... ...Responsibilities Reporting to the Manager of Adversary Response, the Incident Response Analyst operates on the front lines of active cyber conflict—...Permanent employmentWork experience placementWork at officeRemote workWork from homeHome officeFlexible hours$100k - $145k
...Dark Wolf Solutions is seeking a Defensive Cyber Operations Analyst in Washington, DC. This role involves continuous system monitoring... ...threats, with responsibilities including vulnerability management, incident response, and drafting documentation. The ideal candidate will...$166k - $220k
...defense technology company is seeking a Security Operations Analyst in Washington, D.C. The role involves monitoring alerts and responding to incidents across various environments, focusing on optimization of detection signatures and threat hunting. Candidates should have...$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex... ...the organization's ability to prevent, detect, and rapidly respond to sophisticated adversarial... ...coaching to incident handlers and SOC analysts, elevating investigative techniques,...Contract workWork experience placementWork at office$320k - $405k
...together to build beneficial AI systems. About the Role The Detection & Response (D&R) team plays a critical role in protecting our... ...for an experienced Technical Program Manager to own and evolve incident management within D&R. This is a senior-level specialization on...Work at officeImmediate startVisa sponsorshipFlexible hoursShift work$100k - $120k
SkyePoint Decisions is looking for an Incident Detection/Response Manager (SOC Manager) to support the Department of Education’s Cybersecurity efforts. This remote position demands 8+ years in IT, supervising incident response operations, and a necessity for certifications...Remote job- ...policies. • Cybersecurity Assessment Expertise: Evaluates incident response readiness, vulnerability management, MFA enforcement,... ...platforms such as Microsoft Sentinel to assess visibility and detection gaps. • Vulnerability & Risk Analysis: Conducts vulnerability...
- A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience...Remote job
- ...and map adversary TTPs to ATT&CK tactics and techniques during incident triage and reporting. Demonstrated experience performing IP... ...stakeholders. Manage incident triage and coordination with analysis and detection sections to identify and analyze technology and cyber impacts...
$258 - $314 per day
...Operations and Vulnerability Management Analyst PAHO is searching for an independent... ...Program, with focus on security monitoring, incident response, threat hunting, and... ...Security Operations capability to improve the detection, analysis, response, and coordination of...Daily paidFull timeContract workFor contractorsWork at office- ...and proactive Information System Security Analyst to join our IT department. This critical... ...vulnerabilities, responding to incidents, and ensuring compliance with security standards... .... Key Responsibilities Monitoring and Detection: Monitor the organization's networks and...
$131.3k - $237.35k
...better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Incident Response Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD organizations...Local areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Detection Analyst. Be the first to apply!
- document review analyst Washington DC
- facility analyst Washington DC
- senior strategy analyst Washington DC
- disaster recovery analyst Washington DC
- consulting analyst Washington DC
- contracts analyst Washington DC
- compensation analyst Washington DC
- due diligence analyst Washington DC
- invoice analyst Washington DC
- senior foia analyst Washington DC

