> Markdown version of [/jobs/ext/1581707-incident-response-security-analyst-temporary](https://www.wearedevelopers.com/jobs/ext/1581707-incident-response-security-analyst-temporary). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response/Security Analyst - Temporary - **Company:** AnaVation, LLC - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Training Data, Microsoft Word, Microsoft Excel, Data Analysis, Antivirus Softwares, Public-Key Cryptography, Configuration Management, Cyber Security, Computer Networks, Databases, Intrusion Detection and Prevention, McAfee VirusScan, System Center Configuration Manager, Power BI, Phishing, Security Information and Event Management, SQL Injection, Wireshark, Software Vulnerability Management, Web Applications, Data Logging, SC Clearance, Nessus, Data Management, Splunk, Vulnerability Analysis - **Published:** July 3, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17477000?backUrl=%2Fcareer%2F17477000%2FIncident-Response-Security-Analyst-Temporary-D-C-Washington ## About the Role * Bachelor's degree in a related field or equivalent demonstrated experience and knowledge. * 4 years' experience as a Security Administrator. * Hands-on experience conducting incident response activities and vulnerability analysis of various systems, applications, security tools, databases, and networks logs. * Performing vulnerability scans with tools such as Tenable. * Experience with Crowdstrike, TenableSC, Splunk. (Experience with comparable tools may be considered). * Experience with NIST SP 800-61 rev2 Computer Security Incident Handling Guide. * Excellent oral and written communication skills. * Familiarity with multi-tiered network applications, common ports and protocols used in those communications, the Common Vulnerability System (CVS) and the exploitation mechanisms of common vulnerability types (e.g., buffer overflows, cross-site-scripting, SQL injection). * Ability to perform online research and comprehend attack signatures while comparing them to network traffic to perform proper analysis of detections. * Ability to use common tools such as Wireshark to examine network traffic. * Ability to obtain and maintain a Top Secret clearance. Qualified candidates must already have an adjudicated Secret Clearance or higher to be considered for this role. * Certifications: Security + required. Desired Qualifications: * Self-Starter - ability to quickly become competent with new security-related tools and processes. * Ability to conduct Deep Dive analysis to determine root cause assessment of various network scanning agents' scanning or communication failures. * Ability to coordinate remediation strategies with agency's department technical staff through completion. * Familiarity with the various use cases and alignment of data from each tool to various security disciplines in configuration management, vulnerability management, risk management and incident management. * Familiarity with encryption technologies used in commercial operating systems, including Public Key Infrastructures, symmetric and asymmetric cryptography, certificate trust stores and the use of key escrow for discovery and legal purpose. * Understanding of the role of interactive training such as phishing exercises for assessment of organizational abilities. * Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources. * Familiarity with information security terminology and being able to develop or select technical training in the discipline of information security geared to an organization. * Familiarity with data management and reporting of training data and statistics using common tools such as Microsoft Excel and Word. ## Description AnaVation is seeking an Incident Response/Security Analyst (Temporary Role) to help our mission-critical customer in Washington, DC., * Create, track, monitor and investigate security related events/incidents through closure. * Monitor, maintain and administer policies and rules within EDR and SIEM tools (e.g., Crowdstrike, Splunk). * Participate in or lead the remediation of incidents and responses that are generated from live threats against the enterprise. * Perform incident response analysis based on investigation requirements. * Support and develop reports during and after incidents, which include all actions taken to properly mitigate, recover and return operations to normal operations. * Assist in developing and implementing defensive cyber best practice tactics, techniques, and procedures. * Assist in conducting vulnerability scans using Tenable SC and Nessus Manager. Manage the applications and conduct vulnerability analysis. * Maintain Incident Ticketing tracking system and related tickets within Remedy. * Monitor and take action within multiple tools providing security functions such as vulnerability management (e.g., Nessus), configuration management (e.g., Tenable Security Center, IBM BigFix, SCCM, McAfee ePO), endpoint protection (e.g., antivirus, ATP), intrusion detection software and hardware. * Perform Splunk queries to examine and query log data from the Enterprise Logging as a Service system. * Interacting with GRC tool (e.g., CSAM) to perform daily/weekly vulnerability analysis. * Creating and compiling weekly security metrics into dashboards and charts. * Flexible with other security related tasks as needed by the customer. * This position is on-site in Washington, DC. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)