Incident Response Analyst

cFocus Software Incorporated
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Cloud Computing Cyber Security Linux Digital Forensics Intrusion Detection and Prevention Security Information and Event Management Computer Networking Systems Malware Information Technology

Job description

cFocus Software seeks a Incident Response Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Monitor security events across the NIH/OD-OIT environment.

  • Detect, analyze, and respond to cybersecurity incidents affecting enterprise systems.
  • Perform incident triage to determine scope, severity, urgency, and operational impact.
  • Support incident containment, eradication, recovery, and restoration activities.
  • Investigate suspected security incidents within established response time requirements.
  • Coordinate incident handling activities with NIH and HHS cybersecurity organizations.
  • Monitor enterprise security logs and alerts.
  • Perform network and host-based intrusion detection.
  • Monitor cloud applications and cloud infrastructure.
  • Support continuous 24x7 security monitoring operations.
  • Identify indicators of compromise (IOCs) and suspicious activity.

Requirements

  • Public Trust Clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of cybersecurity experience.
  • 5+ years supporting cybersecurity incident response or Security Operations Center (SOC) environments.
  • Experience investigating security incidents across Windows, Linux, cloud, and enterprise networks.
  • Experience with SIEM technologies and security monitoring platforms.
  • Experience performing incident triage and root cause analysis.
  • Knowledge of malware analysis and digital forensics concepts.
  • Understanding of NIST Cybersecurity Framework and NIST SP 800-61 Incident Handling Guide.
  • Ability to obtain and maintain required NIH suitability/background investigation.
  • Active GCIH, GCFA, GCIA, CISSP, CySA+, Security+, CEH, CHFI, CISM, or GSEC

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A “disabled veteran” is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on cfocussoftware.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ WWC 2025

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ WWC 2022

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn ¡ LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

Videos

See all

Related articles

See all