empty

T3 Cyber Incident Response Analyst (w/ active TS)

Critical Solutions

Job Description

Posted on: 
November 18, 2024

Summary and company overview

Incident Response Analyst, Tier 3 (w/ active TS)

Location: Washington, DC

Type: Full-time

Clearance: Top Secret

JOB DESCRIPTION

Critical Solutions is seeking a cleared Incident Response Analyst Tier 3. This exciting role requires an appetite for learning, superior attention to detail, the ability to meet tight deadlines, great organizational skills, and the ability to work in a highly collaborative work environment. The successful hire will possess the ability to complete complex tasks and projects quickly with little to no guidance, react with appropriate urgency to situations that require a quick turnaround and provide the appropriate attention and support to overcome technical obstacles.

Responsibilities

  • Utilize state-of-the-art technologies such as Endpoint Detection & Response tools, SEIM-based log analysis, and full packet capture to perform hunt and investigative activity to examine endpoint and network-based activity
  • Conduct network forensics, log analysis, triage, and limited malware analysis and host-based forensics in support of incident response
  • Develop and build security content, scripts, tools, or methods to enhance the incident investigation processes
  • Lead Incident Response activities and mentor junior staff
  • Work with key stakeholders to implement remediation plans in response to incidents
  • Effectively investigate and identify root cause findings then communicate findings to stakeholders including technical staff, and leadership
  • Author Standard Operating Procedures (SOPs) and training documentation when needed
  • Generate end-of-shift reports for documentation and knowledge transfer to subsequent analysts on duty
  • Likely expected to be primary point of contact for an external agency

Job Requirements

BASIC QUALIFICATIONS:

  • Active Top Secret clearance required with SCI eligibility
  • Bachelor's degree or equivalent experience
  • 8+ years of experience, with at least 6 years in an Incident Responder/Handler role (fewer years of experience may be considered in light of additional education, certifications, or other relevant factors)
  • Full understanding of Tier 1 responsibilities/duties and how the duties feed into Tier 2. The ability to take lead on incident research when appropriate and be able to mentor junior analysts
  • Advanced knowledge of TCP/IP protocols
  • Knowledge of Windows, Linux operating systems
  • Knowledge of Intrusion Detection Systems (IDS) and SIEM technologies; Splunk or ArcSight experience
  • Deep packet and log analysis
  • Some Forensic and Malware Analysis

PREFERRED:

  • Cyber Threat and Intelligence gathering, and analysis preferred
  • Knowledge and experience with scripting and programming (Python, PERL, etc.) are also highly preferred

Additional commentary

  • This is a hybrid role with expectations of being on the client site a few days a week.

Clearance Requirement: US CITIZENS AND ACTIVE TOP SECRET CLEARANCE IS REQUIRED. Selected applicant will be required to undergo background investigation and finger printing by the federal agency and must meet the eligibility requirements.

Summary and company overview

Incident Response Analyst, Tier 3 (w/ active TS)

Location: Washington, DC

Type: Full-time

Clearance: Top Secret

JOB DESCRIPTION

Critical Solutions is seeking a cleared Incident Response Analyst Tier 3. This exciting role requires an appetite for learning, superior attention to detail, the ability to meet tight deadlines, great organizational skills, and the ability to work in a highly collaborative work environment. The successful hire will possess the ability to complete complex tasks and projects quickly with little to no guidance, react with appropriate urgency to situations that require a quick turnaround and provide the appropriate attention and support to overcome technical obstacles.

Apply now