> Markdown version of [/jobs/ext/1742733-cybersecurity-consultant](https://www.wearedevelopers.com/jobs/ext/1742733-cybersecurity-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Consultant - **Company:** Copper River Family Of Companies - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $312,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, ARM Architecture, Audit Trail, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Digital Forensics, Domain Name System (DNS), Event Logging, Log Analysis, Phishing, Zero Trust Network Access, Security Information and Event Management, VMware Infrastructure, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, QRadar, Malware, Cyber Threat Analysis, Firewalls (Computer Science), Azure Security Center, Tanium Platform Expertise, Microsoft Sentinel, Splunk, Qualys - **Published:** July 7, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87652315/1 ## About the Role * Memory analysis * Disk analysis * Log analysis * Timeline reconstruction * Registry analysis * Malware triage Security Technologies Consultants should have practical experience with one or more of the following: * Splunk * Microsoft Sentinel * CrowdStrike Falcon * Microsoft Defender * Elastic * QRadar * Palo Alto Cortex * Trellix * Carbon Black * Rapid7 * Tanium * Tenable * Qualys * AWS Security Services * Azure Security Center * Microsoft Defender XDR * EDR/XDR platforms, * Minimum 7 years of cybersecurity experience. * Minimum 5 years supporting Incident Response or Security Operations Center (SOC) environments. * Experience responding to live cybersecurity incidents. * Experience performing enterprise threat hunting. * Strong understanding of: + NIST Cybersecurity Framework + NIST SP 800-61 Computer Security Incident Handling Guide + NIST SP 800-53 + MITRE ATT&CK Framework + Cyber Kill Chain + Zero Trust Architecture * Experience analyzing: + Windows Event Logs + Sysmon + Active Directory + DNS + Firewall logs + Authentication logs + EDR telemetry + Cloud audit logs * Excellent written and verbal communication skills. * Ability to explain technical findings to executive leadership. Desired Qualifications One or more of the following certifications: * CISSP * GIAC Certified Incident Handler (GCIH) * GIAC Certified Forensic Analyst (GCFA) * GIAC Certified Enterprise Defender (GCED) * Certified Ethical Hacker (CEH) * CompTIA CySA+ * CompTIA Security+ * Splunk Certified Architect * Splunk Enterprise Security Certified Admin * Microsoft Certified Security Operations Analyst (SC-200) * Microsoft Cybersecurity Architect (SC-100) * AWS Security Specialty * Certified Cloud Security Professional (CCSP) Preferred Experience Experience supporting: * Federal Civilian Agencies * Department of Defense * Intelligence Community * Critical Infrastructure * Healthcare * Financial Services * Energy Sector Experience with: * Continuous Diagnostics and Mitigation (CDM) * Continuous Monitoring * Threat Intelligence * Insider Threat * Vulnerability Management * Malware Analysis * Digital Forensics * Cloud Incident Response * Identity-based attacks * Zero Trust implementations ## Description Lead or support cybersecurity incident response engagements involving ransomware, advanced persistent threats (APT), insider threats, phishing campaigns, malware infections, unauthorized access, cloud compromises, and other cyber incidents., * Perform incident triage and determine scope and severity. * Identify attack vectors and affected assets. * Collect and preserve forensic evidence. * Perform root cause analysis. * Coordinate containment activities. * Support eradication of adversary presence. * Restore systems to secure operational status. * Develop incident timelines. * Produce executive and technical incident reports. * Recommend security improvements to prevent recurrence. Cyber Hunt Operations Conduct proactive threat hunting activities designed to identify adversaries before significant impact occurs. Responsibilities include: * Develop hunt hypotheses based on current intelligence. * Analyze endpoint, network, cloud, identity, and application logs. * Identify Indicators of Compromise (IOCs) and Indicators of Attack (IOAs). * Detect persistence mechanisms. * Identify lateral movement. * Investigate privilege escalation. * Hunt for known threat actor Tactics, Techniques, and Procedures (TTPs). * Leverage MITRE ATT&CK methodologies. * Produce actionable hunt findings. Incident Handling & Event Management (IHEM) Support enterprise Incident Handling and Event Management capabilities consistent with NIST guidance and industry best practices. Responsibilities include: * Monitor security events and alerts. * Validate and declare security incidents. * Perform event analysis and prioritization. * Coordinate incident response activities. * Conduct technical investigations. * Execute containment procedures. * Support remediation efforts. * Validate recovery activities. * Document lessons learned. * Improve incident response processes. Digital Forensics & Analysis Support forensic investigations involving: * Windows * Linux * Cloud environments * Active Directory * Microsoft 365 * Azure * AWS * Containers * Virtual infrastructure, Candidates must be able to: * Respond to urgent requests within agreed Service Level Agreements (SLAs). * Participate in after-hours, weekend, and holiday incident response activities. * Support remote engagements nationwide. * Participate in surge support during major cybersecurity incidents. Key Competencies * Incident Response Leadership * Cyber Threat Hunting * Digital Forensics * Malware Investigation * Log Analysis * Enterprise Security Monitoring * SIEM Operations * Executive Communication * Technical Documentation * Problem Solving * Crisis Management * Team Collaboration Deliverables Consultants may be expected to produce: * Incident Response Reports * Executive Briefings * Threat Hunt Reports * Root Cause Analysis Reports * Lessons Learned Documentation * Indicators of Compromise (IOC) Reports * Security Recommendations * Recovery Validation Reports * Remediation Plans ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)