Incident Responder - Tier 2

Evans & Chambers Technology
Fort Meade, MD, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$115,000.0 - $147,000.0
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Cyber Security Digital Forensics Python (Programming Language) Log Analysis Packet Analyzer Windows PowerShell Scripting Malware Information Technology Plan of Action and Milestones

Job description

Position Summary: The Tier 2 Incident Responder performs in-depth investigation, containment, and remediation of security incidents escalated from Tier 1, applying the NIST SP 800-61 incident response life cycle and mentors Tier 1 analysts on investigative technique., Duties and Responsibilities: Duties include the following.

  • Investigate escalated alerts and incidents through log analysis, malware analysis, and digital forensics, determining scope, root cause, and impact.
  • Support execution of containment and eradication actions. Support recovery of affected systems to a known-good, hardened baseline.
  • Document incident timelines and findings, create and track POA&M entries to closure and contribute to after-action reviews that feed back into detection content and playbooks.
  • Review and remediate findings.
  • Provide technical mentorship to Tier 1 Analysts and serve as a secondary escalation point during major incidents or surge conditions.

Requirements

Required Education and Experience: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience; three to five years of hands-on incident response, digital forensics, or security operations experience.

Required Certifications: DoD 8570/8140 IAT Level III or CSSP Incident Responder certification (e.g., GCIH, GCFA, or CySA+) required; working knowledge of endpoint detection and response (EDR) tooling, packet analysis, and at least one scripting language (e.g., Python, PowerShell, or Bash) preferred.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all