Cybersecurity Incident and Application Analyst
$130k - $145kGunnison Consulting Group Inc
Description * This position is contingent upon a future opening with Gunnison. Salary: $130,000 - $145,000/year Work location : Hybrid, 2-3 days per week on-site in Bethesda, MD. Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments. Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures. Apply the enterprise incident-response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post-incident analysis. Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security-tool alerts to identify malicious, anomalous, or unauthorized activity. Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses. Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat-detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability-management tools, and related security operations tools. Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data-security risks. Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security-control configurations relevant to incident investigation and response. Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders. Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans. Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures. Lead or support post-incident reviews and lessons-learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements. Assist with annual incident-response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident-response documentation. Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders. Maintain familiarity with NIST SP 800-61 incident-handling guidance and apply it to daily incident-response operations. Requirements Minimum of two (2) to five (5) years of progressively responsible experience in cybersecurity incident response, security operations, network security, application security, cloud security, threat detection, or a related discipline. Candidates should demonstrate experience in: Security-event monitoring, alert triage, incident investigation, incident documentation, escalation, and response coordination. Enterprise incident-response processes, including preparation, detection and analysis, containment, eradication, recovery, and post-incident activities. Network security, web application security, cloud technologies, endpoint security, and security monitoring. Identifying vulnerable services, insecure ports and protocols, default or weak configurations, and common network/application security weaknesses. SIEM analysis, preferably Splunk, including log searches, dashboards, correlation, alert analysis, and report generation. IDS/IPS, firewalls, endpoint detection and response, vulnerability-management, and threat-detection technologies, including Palo Alto, FireEye or comparable platforms, and Tenable. Windows and Linux operating systems, including basic system/log analysis and security troubleshooting. NIST SP 800-61 and the creation or use of incident-response playbooks, RACI charts, escalation procedures, SOPs, and lessons-learned documentation. Preparing technical findings, incident reports, management updates, and executive-level summaries. Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, computer science, information systems, computer engineering, network engineering, digital forensics, systems engineering, or a closely related technical discipline. EC-Council Certified Incident Handler (E|CIH), current and active Offensive Security Certified Professional (OSCP), current and active GIAC Certified Incident Handler (GCIH), current and active Current Splunk certification, such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Core Certified Advanced Power User, or an equivalent Splunk security/engineering credential Clearance Requirement: Ability to obtain and maintain a Public Trust. Desired Qualifications Master’s degree in cybersecurity, information assurance, computer science, digital forensics, information systems, engineering, data analytics, or a related technical discipline. GIAC Certified Intrusion Analyst (GCIA) GIAC Security Essentials (GSEC) GIAC Certified Forensic Analyst (GCFA) GIAC Reverse Engineering Malware (GREM) GIAC Penetration Tester (GPEN) CompTIA Security+, CySA+, PenTest+, or CASP+ Certified Ethical Hacker (CEH) Certified Information Systems Security Professional (CISSP) Palo Alto Networks Certified Network Security Engineer (PCNSE) or related Palo Alto credential Tenable/Nessus platform training or certification FireEye, Trellix, Microsoft Defender, CrowdStrike, SentinelOne, or comparable EDR/XDR training AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Cisco CyberOps Associate/Professional, CCNP Security, or equivalent network-security certification ITIL Foundation, particularly for candidates supporting formal incident, problem, and change-management processes The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include: 3 weeks of Personal Leave your first year 11 paid Holidays each year 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible) 401(k) company match at 50% up to 10% of your salary Medical, Dental and Vision Insurance Life and Disability Insurance Public Transportation Subsidies Certifications and Training Allowance - Up to $5,000/year! Why Join Gunnison? Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation. Quality is our top priority. Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer. There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow. We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding. We hire for careers at Gunnison, not to fill a position. Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time. In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects . By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could , the company has thrived for over 25 years. #J-18808-Ljbffr Gunnison Consulting Group Inc
- Edgewater Federal Solutions is seeking an Incident Response Analyst to join a 24x7 cybersecurity operations team in the Bethesda, MD area. The role requires US citizenship and involves incident tracking, stakeholder communications, remediation, and reporting. The ideal...Suggested
- ...Tier 2 Cybersecurity Incident Response Analyst The Tier 2 Cybersecurity Incident Response Analyst provides advanced incident response support for NIH enterprise and cloud environments. This role responds to hotline-reported incidents and performs investigation, containment...Suggested
- ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland Type: Direct Hire Compensation: 120k Work... ...System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without...SuggestedFull timeLocal area
- Gunnison Consulting Group in Bethesda, MD is seeking an experienced cybersecurity incident responder to support detection, analysis, containment, recovery, and post-incident activities across NIH CIT environments. The role is hybrid, requiring 2-5 years of related experience...Suggested
$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic Cyber group.... ...‑level systems.In This Role, You Will: Respond to cybersecurity incidents across ICS, OT, and IT environments and provide...SuggestedContract workCurrently hiringShift work1 day per week$170k - $180k
...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington, VA office.... ...and growing team supporting the Cybersecurity and Infrastructure Security Agency’s... ...Familiarity with AI/ML concepts and applications that support Workflow and Incident...Work at office3 days per week- ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world. The Cyber Incident Response Analyst...Shift workNight shiftDay shiftAfternoon shift
- Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a multidisciplinary team of IR Tier-1, IR Tier-2,... ...contract. The role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead, overseeing governance, delivery, and...Contract work
$83.5k - $87.5k
...Cayuse Holdings is seeking a Cyber Incident Response Analyst in Washington, DC to enhance the cybersecurity framework. This role involves case management and coordination of cybersecurity incidents while ensuring exceptional customer service. The ideal candidate will...$83.5k - $87.5k
...Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client’s cybersecurity framework by serving as the primary entry point for all external communications... ...Hunting, Vulnerability Management) where applicable. Serve as the point of contact to...Temporary workWork at officeLocal areaFlexible hoursShift work- ...Cayuse is hiring a Cyber Incident Response Analyst in Washington, DC. This role is critical for reinforcing the client’s cybersecurity framework, managing communications about incidents, and engaging in operational coordination. The Analyst will be expected to provide...
- ...in intrusion detection/prevention and cybersecurity tools administration. The specialist will... .... Providing detailed triage of CSSP/IR incidents including implementing intrusion... ...your resume). CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr...Work at officeMonday to FridayWeekend work
$136k - $184k
...challenges at scale and working to protect applications powering the most sophisticated e-... ...customers and data.- You will work alongside incident response teams and provide direct... ...operating risk for our customers.- Monitor cybersecurity media, blog posts, and other sources to...InternshipFlexible hoursShift work$80k - $128k
...currently searching for a Junior Cyber Incident Analyst - Notification Specialist - for our... ...law enforcement reporting, to identify cybersecurity incidents, threats, and vulnerabilities... ...targeted notification section emails as applicable.Submit tickets as necessary to assist...Contract workShift work- A leading cybersecurity firm is seeking a Network Forensics Analyst to support critical incident response missions. Candidates must have 8+ years of experience in network investigations, preferably with an active TS/SCI clearance. The role involves coordinating teams,...
- Accenture Federal Services in Arlington, VA is seeking a Cybersecurity Incident Response Junior Analyst and Triage Analyst to join the CIRT team within the CISO organization. You will monitor, triage, and respond to alerts from SIEM and security sensors, and work with...
- True Zero Technologies in Washington, DC is seeking a seasoned cybersecurity professional to lead incident response efforts as part of our commitment to quality outcomes. You will manage reports, conduct forensic investigations, and support compliance. The ideal candidate...
$80k - $128k
Peraton is looking for an experienced CIRT Tier 1 Analyst to join its Federal Strategic Cyber Mission program in Beltsville, MD. The role involves tracking cybersecurity events, managing incidents, and coordinating with various teams. Candidates should have a Bachelor'...Full time- ...and analyze digital evidence, support government agencies in incident management, and document findings in reports. The ideal candidate... .... Join a collaborative team that values innovation and problem-solving in the growing field of cybersecurity. #J-18808-Ljbffr Nightwing
- ...customer to provide support for onsite incident response to civilian Government agencies... ...within the enterprise - Applying cybersecurity concepts to the detection and defense of... ...sponsored]) - Knowledge of system and application security threats and vulnerabilities (e...Full timeContract workLocal areaImmediate startFlexible hoursShift work
$160k - $180k
...will be full-time on-site. Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident... ...cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. Review, maintain, and...Full timeContract workFlexible hours2 days per week3 days per week- Nightwing is seeking a Cyber Incident Manager based in Arlington, VA, to support U.S. Government agencies in mitigating cyber-attacks... ...Responsibilities include analyzing incident data, performing cybersecurity triage, and tracking incidents from detection to resolution....
- A leading cybersecurity firm in Virginia is seeking a Cyber Eviction Lead to enhance incident response capabilities. The ideal candidate will have a strong background in cyber defense, experience in responding to complex incidents, and relevant certifications. Responsibilities...
- RJIT Solutions in Washington, DC seeks an experienced cybersecurity professional to oversee continuous monitoring, incident response coordination, and audit support as a second-line backstop to the Lead ISSO. You will drive security posture management, coordinate with the...
- Tetrad Digital Integrity LLC is seeking a Senior Incident Response Analyst to join our Security Operations Center. This hybrid position will involve monitoring, detecting, and responding to cybersecurity threats affecting a large-scale environment, especially within mission...
- Nightwing Group in Arlington, VA is seeking a Cyber Incident Management Analyst for weekend night shifts. The role includes managing on-site responses... ...in incident management and strong knowledge of cybersecurity principles. The ideal candidate must hold a relevant degree...Night shiftWeekend work
- Solutions³ LLC is hiring an Incident Manager II in Arlington, VA to support government clients in cyber incident response. The role... ...Join a mission-critical environment supporting U.S. Government agencies to enhance cybersecurity measures. #J-18808-Ljbffr Solutions³ LLC
- A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...
- ...professional to advance cyber defense programs for federal missions. You will evaluate capabilities, lead improvements, and design incident response playbooks within an agile framework. The role emphasizes cross‑functional collaboration, data analytics, and secure...Remote job
- A cybersecurity firm in Arlington, Virginia is seeking a Cyber Action Officer to support incident response efforts for government clients experiencing cyber-attacks. Responsibilities include managing cyber incidents, coordinating reports, and collaborating with partners...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Incident and Application Analyst. Be the first to apply!
- paper application Bethesda, MD
- senior application security Bethesda, MD
- now accepting applications Bethesda, MD
- oracle apps technical consultant Bethesda, MD
- app delivery Bethesda, MD
- vice president of application development Bethesda, MD
- cash application representative Bethesda, MD
- application security lead Bethesda, MD
- application system administrator Bethesda, MD
- applications consultant Bethesda, MD



