Quick Overview:100% work on site - no remote workSecret clearance with the ability to acquire a TSLocations near the Pentagon or Mayfield VACustomer DEAIntermediate SOC Analyst6 years with Bachelor Position SummaryThe Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. The analyst will leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps. Key ResponsibilitiesMonitor enterprise security systems and analyze alerts to identify potential cybersecurity incidentsReview SIEM, IDS/IPS, EDR, and related security tool alerts for anomalous activity, indicators of compromise (IOCs), and indicators of attack (IOAs).Validate alerts, reduce false positives, and prioritize incidents based on severity and impactPerform triage and analysis of security events to determine scope, severity, and urgencyExamine log data, network telemetry, and endpoint information to identify malicious activityCorrelate event details with internal and external threat intelligenceExecute incident response actions in accordance with established proceduresContain affected systems, remove malicious artifacts, and assist with system recoveryEscalate complex or critical incidents to senior analysts or SOC leadership as neededDocument investigative findings, incident timelines, and remediation actionsCreate and manage incident tickets and upload supporting evidence and artifactsContribute to after action reviews and post incident reportingCommunicate findings clearly and concisely to technical and nontechnical stakeholdersMaintain SOC processes, tools, and playbooks to support effective incident handlingRecommend improvements to SOPs, escalation procedures, and detection capabilitiesParticipate in training exercises and knowledge sharing activitiesSupport red, blue, or purple team exercises as directedStay informed on current and emerging cyber threats, threat actor TTPs, and industry trends Required QualificationsBachelor's degree in Information Technology, Cybersecurity, Information Systems, Computer Science, Data Science, or related field from an ABET accredited or CAE designated institution preferred. Equivalent experience may be considered in accordance with SOW education substitution requirementsMinimum of 6 years of experience in Information Technology and/or Information SecurityExperience with incident response, threat analysis, SIEM platforms, endpoint security tools, and log analysisStrong analytical and investigative skills with the ability to derive accurate conclusions during incident investigationsActive Secret clearance or higher requiredMust be eligible to obtain a Top Secret clearance if requestedAbility to successfully complete a DEA background investigationMust possess at least one applicable DoD 8140 certification or obtain certification within 6 months of onboarding Preferred QualificationsPreferred DCWF Role 511 Cyber Defense Analyst certifications include:CBROPSCFRCompTIA Cloud+, CySA+, PenTest+, or Security+ CEFITSP OSANS GCED, GCFA, GCIA, GDSA, GFACT, GICSP, GISF, or GSECAdditional InformationThis role primarily supports the Operations & Response Team, with potential support across Vulnerability Assessment and Penetration Testing and Engineering teams.The position will coordinate closely with cybersecurity, IT operations, engineering, software operations, and investigative technology teams to support enterprise security operations and incident response activities.
Job Posted by ApplicantPro