> Markdown version of [/jobs/ext/1735606-senior-cyber-defense-incident-responder](https://www.wearedevelopers.com/jobs/ext/1735606-senior-cyber-defense-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Defense Incident Responder - **Company:** American International Group, Inc. - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Unix, Cyber Security, Linux, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Internet Control Message Protocol, Internet Protocol, Intrusion Detection and Prevention, Python (Programming Language), Simple Mail Transfer Protocols, Security Information and Event Management, Simple Network Management Protocols, File Transfer Protocol (FTP), Malware, Information Technology, Cyber Warfare - **Published:** July 8, 2026 - **Apply:** https://aig.wd1.myworkdayjobs.com/aig/job/10780-10790-Parkridge-Boulevard-Reston-VA-USA/Senior-Cyber-Defense-Incident-Responder_JR2601661 ## About the Role · An understanding of cyber security operations processes, procedures, guidelines and solutions, including practical experience of cyber kill chain principles · In-depth understanding of Windows, UNIX, and Linux operating systems, networking, malware defenses, and perimeter controls. · Knowledge of TCP/IP networking and core Internet protocols such as UDP, ICMP, DNS, FTP, SMTP, HTTP, SNMP, etc. · Ability to contribute to the development of SIEM use cases. · Strong oral and written communications skills (e.g., technical writing, user guide development, requirements analysis) and ability to interact effectively with technical and non-technical audiences, as well as present in front of small and large groups. · Understanding of how to read and interpret malware analysis reports. · Self-starter with a sense of urgency who takes ownership and responsibility for service delivery · Works independently with minimal guidance to drive projects to completion, while also working collaboratively with the team to achieve strategic goals · Professional, clear, and concise communication to both technical and non-technical audiences · Strong deductive reasoning, critical thinking, problem solving, prioritization, and consultative skills · Proven organizational skills (time management and prioritization), and also employ a rigorous process for all follow-up / coordination activities · Comfortable working in a dynamic environment, balancing multiple incidents, special projects, and other activities. · Ability to deal diplomatically and effectively at all levels of the business including both technical and non-technical staff, management and senior leadership. · Willingness to support and develop junior team members while also delivering on candidate's own responsibilities. · Bachelor's degree or equivalent practical experience is preferred. · Experience with security monitoring, event and anomaly analysis and intrusion detection/ prevention techniques and an in-depth understanding of Python. ## Description AIG is seeking a highly skilled cyber-defense expert to join AIG's Detect & Response team. The Cyber Risk Defense Analyst will execute a range of threat discovery and incident response duties. The successful candidate will work as part of a team that conducts investigations into potential and actual cyber-attacks affecting AIG's global business units, lines of business, or information technology infrastructure. The Detect & Response team encompasses several teams across disciplines including alert validation and tuning, incident response, and cyber threat intelligence. The teams follow a kill chain-aligned operational model, giving the candidate exposure to all elements of an attack lifecycle. Major Job Responsibilities: · Investigate potential cyber-attacks and intrusion attempts. · Leverage aggregated cyber threat intelligence, log, network flow, and anomaly data for analysis, research and the identification of potential compromise within AIG's infrastructure or applications. · Perform root cause analysis to identify gaps and provide technical and procedural recommendations that will reduce AIG's exposure to cyber-risks. · Prioritize incoming requests to minimize risk exposure and ensure the timely completion of critical tasks and the escalation of time-sensitive issues. · Support the development and maintenance of documented play-book procedures, knowledge articles, and training material. · Create detailed incident and analysis reports, and provide concise summaries for management. · Communicate effectively with other stakeholders of our incident response efforts, including representatives of the business units, technology specialists, vendors, and others. · Contribute to our efforts to drive continuous improvement by recommending and collecting various key metrics for reporting to senior management on Incident Response. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)