Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Incident and Application Analyst

$130k - $145k

Gunnison Consulting Group Inc

Description * This position is contingent upon a future opening with Gunnison. Salary: $130,000 - $145,000/year Work location : Hybrid, 2-3 days per week on-site in Bethesda, MD. Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments. Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures. Apply the enterprise incident-response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post-incident analysis. Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security-tool alerts to identify malicious, anomalous, or unauthorized activity. Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses. Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat-detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability-management tools, and related security operations tools. Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data-security risks. Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security-control configurations relevant to incident investigation and response. Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders. Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans. Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures. Lead or support post-incident reviews and lessons-learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements. Assist with annual incident-response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident-response documentation. Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders. Maintain familiarity with NIST SP 800-61 incident-handling guidance and apply it to daily incident-response operations. Requirements Minimum of two (2) to five (5) years of progressively responsible experience in cybersecurity incident response, security operations, network security, application security, cloud security, threat detection, or a related discipline. Candidates should demonstrate experience in: Security-event monitoring, alert triage, incident investigation, incident documentation, escalation, and response coordination. Enterprise incident-response processes, including preparation, detection and analysis, containment, eradication, recovery, and post-incident activities. Network security, web application security, cloud technologies, endpoint security, and security monitoring. Identifying vulnerable services, insecure ports and protocols, default or weak configurations, and common network/application security weaknesses. SIEM analysis, preferably Splunk, including log searches, dashboards, correlation, alert analysis, and report generation. IDS/IPS, firewalls, endpoint detection and response, vulnerability-management, and threat-detection technologies, including Palo Alto, FireEye or comparable platforms, and Tenable. Windows and Linux operating systems, including basic system/log analysis and security troubleshooting. NIST SP 800-61 and the creation or use of incident-response playbooks, RACI charts, escalation procedures, SOPs, and lessons-learned documentation. Preparing technical findings, incident reports, management updates, and executive-level summaries. Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, computer science, information systems, computer engineering, network engineering, digital forensics, systems engineering, or a closely related technical discipline. EC-Council Certified Incident Handler (E|CIH), current and active Offensive Security Certified Professional (OSCP), current and active GIAC Certified Incident Handler (GCIH), current and active Current Splunk certification, such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Core Certified Advanced Power User, or an equivalent Splunk security/engineering credential Clearance Requirement: Ability to obtain and maintain a Public Trust. Desired Qualifications Master’s degree in cybersecurity, information assurance, computer science, digital forensics, information systems, engineering, data analytics, or a related technical discipline. GIAC Certified Intrusion Analyst (GCIA) GIAC Security Essentials (GSEC) GIAC Certified Forensic Analyst (GCFA) GIAC Reverse Engineering Malware (GREM) GIAC Penetration Tester (GPEN) CompTIA Security+, CySA+, PenTest+, or CASP+ Certified Ethical Hacker (CEH) Certified Information Systems Security Professional (CISSP) Palo Alto Networks Certified Network Security Engineer (PCNSE) or related Palo Alto credential Tenable/Nessus platform training or certification FireEye, Trellix, Microsoft Defender, CrowdStrike, SentinelOne, or comparable EDR/XDR training AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Cisco CyberOps Associate/Professional, CCNP Security, or equivalent network-security certification ITIL Foundation, particularly for candidates supporting formal incident, problem, and change-management processes The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include: 3 weeks of Personal Leave your first year 11 paid Holidays each year 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible) 401(k) company match at 50% up to 10% of your salary Medical, Dental and Vision Insurance Life and Disability Insurance Public Transportation Subsidies Certifications and Training Allowance - Up to $5,000/year! Why Join Gunnison? Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation. Quality is our top priority. Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer. There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow. We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding. We hire for careers at Gunnison, not to fill a position. Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time. In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects . By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could , the company has thrived for over 25 years. #J-18808-Ljbffr Gunnison Consulting Group Inc

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Incident and Application Analyst in Bethesda, MD vacancy
  • Edgewater Federal Solutions is seeking an Incident Response Analyst to join a 24x7 cybersecurity operations team in the Bethesda, MD area. The role requires US citizenship and involves incident tracking, stakeholder communications, remediation, and reporting. The ideal... 
    Suggested

    Edgewater Federal Solutions

    Bethesda, MD
    2 days ago
  •  ...Tier 2 Cybersecurity Incident Response Analyst The Tier 2 Cybersecurity Incident Response Analyst provides advanced incident response support for NIH enterprise and cloud environments. This role responds to hotline-reported incidents and performs investigation, containment... 
    Suggested

    Merit 321

    Bethesda, MD
    3 days ago
  •  ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland Type: Direct Hire Compensation: 120k Work...  ...System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without... 
    Suggested
    Full time
    Local area

    System One

    Bethesda, MD
    3 days ago
  • Gunnison Consulting Group in Bethesda, MD is seeking an experienced cybersecurity incident responder to support detection, analysis, containment, recovery, and post-incident activities across NIH CIT environments. The role is hybrid, requiring 2-5 years of related experience... 
    Suggested

    Gunnison Consulting Group Inc

    Bethesda, MD
    5 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic Cyber group....  ...‑level systems.In This Role, You Will: Respond to cybersecurity incidents across ICS, OT, and IT environments and provide... 
    Suggested
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton Corporation

    Arlington, VA
    4 days ago
  • $170k - $180k

     ...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington, VA office....  ...and growing team supporting the Cybersecurity and Infrastructure Security Agency’s...  ...Familiarity with AI/ML concepts and applications that support Workflow and Incident... 
    Work at office
    3 days per week

    ECS Federal

    Arlington, VA
    3 days ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world.  The Cyber Incident Response Analyst... 
    Shift work
    Night shift
    Day shift
    Afternoon shift

    MANTECH

    McLean, VA
    6 hours ago
  • Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a multidisciplinary team of IR Tier-1, IR Tier-2,...  ...contract. The role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead, overseeing governance, delivery, and... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  • $83.5k - $87.5k

     ...Cayuse Holdings is seeking a Cyber Incident Response Analyst in Washington, DC to enhance the cybersecurity framework. This role involves case management and coordination of cybersecurity incidents while ensuring exceptional customer service. The ideal candidate will... 

    Cayuse Holdings

    Washington DC
    1 day ago
  • $83.5k - $87.5k

     ...Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client’s cybersecurity framework by serving as the primary entry point for all external communications...  ...Hunting, Vulnerability Management) where applicable. Serve as the point of contact to... 
    Temporary work
    Work at office
    Local area
    Flexible hours
    Shift work

    Cayuse Holdings

    Washington DC
    3 days ago
  •  ...Cayuse is hiring a Cyber Incident Response Analyst in Washington, DC. This role is critical for reinforcing the client’s cybersecurity framework, managing communications about incidents, and engaging in operational coordination. The Analyst will be expected to provide... 

    Unavailable

    Washington DC
    1 day ago
  •  ...in intrusion detection/prevention and cybersecurity tools administration. The specialist will...  .... Providing detailed triage of CSSP/IR incidents including implementing intrusion...  ...your resume). CYBERSECURITY SERVICE PROVIDER/INCIDENT RESPONSE ANALYST #J-18808-Ljbffr... 
    Work at office
    Monday to Friday
    Weekend work

    Bespoke Corps LLC

    Arlington, VA
    4 days ago
  • $136k - $184k

     ...challenges at scale and working to protect applications powering the most sophisticated e-...  ...customers and data.- You will work alongside incident response teams and provide direct...  ...operating risk for our customers.- Monitor cybersecurity media, blog posts, and other sources to... 
    Internship
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    2 days ago
  • $80k - $128k

     ...currently searching for a Junior Cyber Incident Analyst - Notification Specialist - for our...  ...law enforcement reporting, to identify cybersecurity incidents, threats, and vulnerabilities...  ...targeted notification section emails as applicable.Submit tickets as necessary to assist... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    6 hours ago
  • A leading cybersecurity firm is seeking a Network Forensics Analyst to support critical incident response missions. Candidates must have 8+ years of experience in network investigations, preferably with an active TS/SCI clearance. The role involves coordinating teams,... 

    Nightwing

    Arlington, VA
    3 days ago
  • Accenture Federal Services in Arlington, VA is seeking a Cybersecurity Incident Response Junior Analyst and Triage Analyst to join the CIRT team within the CISO organization. You will monitor, triage, and respond to alerts from SIEM and security sensors, and work with... 

    Accenture Federal Services

    Arlington, VA
    1 day ago
  • True Zero Technologies in Washington, DC is seeking a seasoned cybersecurity professional to lead incident response efforts as part of our commitment to quality outcomes. You will manage reports, conduct forensic investigations, and support compliance. The ideal candidate... 

    Truezerotech

    Washington DC
    5 days ago
  • $80k - $128k

    Peraton is looking for an experienced CIRT Tier 1 Analyst to join its Federal Strategic Cyber Mission program in Beltsville, MD. The role involves tracking cybersecurity events, managing incidents, and coordinating with various teams. Candidates should have a Bachelor'... 
    Full time

    Peraton

    Beltsville, MD
    3 days ago
  •  ...and analyze digital evidence, support government agencies in incident management, and document findings in reports. The ideal candidate...  .... Join a collaborative team that values innovation and problem-solving in the growing field of cybersecurity. #J-18808-Ljbffr Nightwing

    Nightwing

    Arlington, VA
    3 days ago
  •  ...customer to provide support for onsite incident response to civilian Government agencies...  ...within the enterprise - Applying cybersecurity concepts to the detection and defense of...  ...sponsored]) - Knowledge of system and application security threats and vulnerabilities (e... 
    Full time
    Contract work
    Local area
    Immediate start
    Flexible hours
    Shift work

    BCMC

    Arlington, VA
    9 days ago
  • $160k - $180k

     ...will be full-time on-site. Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident...  ...cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. Review, maintain, and... 
    Full time
    Contract work
    Flexible hours
    2 days per week
    3 days per week

    Gunnison Consulting Group

    Alexandria, VA
    4 days ago
  • Nightwing is seeking a Cyber Incident Manager based in Arlington, VA, to support U.S. Government agencies in mitigating cyber-attacks...  ...Responsibilities include analyzing incident data, performing cybersecurity triage, and tracking incidents from detection to resolution.... 

    Nightwing

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm in Virginia is seeking a Cyber Eviction Lead to enhance incident response capabilities. The ideal candidate will have a strong background in cyber defense, experience in responding to complex incidents, and relevant certifications. Responsibilities... 

    Nightwing

    Arlington, VA
    2 days ago
  • RJIT Solutions in Washington, DC seeks an experienced cybersecurity professional to oversee continuous monitoring, incident response coordination, and audit support as a second-line backstop to the Lead ISSO. You will drive security posture management, coordinate with the... 

    RJIT Solutions

    Washington DC
    4 days ago
  • Tetrad Digital Integrity LLC is seeking a Senior Incident Response Analyst to join our Security Operations Center. This hybrid position will involve monitoring, detecting, and responding to cybersecurity threats affecting a large-scale environment, especially within mission... 

    Tetrad Digital Integrity

    Arlington, VA
    5 days ago
  • Nightwing Group in Arlington, VA is seeking a Cyber Incident Management Analyst for weekend night shifts. The role includes managing on-site responses...  ...in incident management and strong knowledge of cybersecurity principles. The ideal candidate must hold a relevant degree... 
    Night shift
    Weekend work

    Nightwing Group

    Arlington, VA
    3 days ago
  • Solutions³ LLC is hiring an Incident Manager II in Arlington, VA to support government clients in cyber incident response. The role...  ...Join a mission-critical environment supporting U.S. Government agencies to enhance cybersecurity measures. #J-18808-Ljbffr Solutions³ LLC

    Solutions³ LLC

    Arlington, VA
    5 days ago
  • A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding... 

    Nightwing

    Arlington, VA
    4 days ago
  •  ...professional to advance cyber defense programs for federal missions. You will evaluate capabilities, lead improvements, and design incident response playbooks within an agile framework. The role emphasizes cross‑functional collaboration, data analytics, and secure... 
    Remote job

    Noblis

    Bethesda, MD
    4 days ago
  • A cybersecurity firm in Arlington, Virginia is seeking a Cyber Action Officer to support incident response efforts for government clients experiencing cyber-attacks. Responsibilities include managing cyber incidents, coordinating reports, and collaborating with partners... 

    Nightwing

    Arlington, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Incident and Application Analyst. Be the first to apply!