Incident Response Analyst
cFocus Software Incorporated
United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Cloud Computing
Cyber Security
Linux
Digital Forensics
Intrusion Detection and Prevention
Security Information and Event Management
Computer Networking Systems
Malware
Information Technology
Job description
cFocus Software seeks a Incident Response Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Monitor security events across the NIH/OD-OIT environment.
- Detect, analyze, and respond to cybersecurity incidents affecting enterprise systems.
- Perform incident triage to determine scope, severity, urgency, and operational impact.
- Support incident containment, eradication, recovery, and restoration activities.
- Investigate suspected security incidents within established response time requirements.
- Coordinate incident handling activities with NIH and HHS cybersecurity organizations.
- Monitor enterprise security logs and alerts.
- Perform network and host-based intrusion detection.
- Monitor cloud applications and cloud infrastructure.
- Support continuous 24x7 security monitoring operations.
- Identify indicators of compromise (IOCs) and suspicious activity.
Requirements
- Public Trust Clearance
- B.S. Computer Science, Information Technology, or a related field
- 5+ years of cybersecurity experience.
- 5+ years supporting cybersecurity incident response or Security Operations Center (SOC) environments.
- Experience investigating security incidents across Windows, Linux, cloud, and enterprise networks.
- Experience with SIEM technologies and security monitoring platforms.
- Experience performing incident triage and root cause analysis.
- Knowledge of malware analysis and digital forensics concepts.
- Understanding of NIST Cybersecurity Framework and NIST SP 800-61 Incident Handling Guide.
- Ability to obtain and maintain required NIH suitability/background investigation.
- Active GCIH, GCFA, GCIA, CISSP, CySA+, Security+, CEH, CHFI, CISM, or GSEC
Benefits & conditions
Invitation for Job Applicants to Self-Identify as a U.S. Veteran
- A âdisabled veteranâ is one of the following:
- a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
- a person who was discharged or released from active duty because of a service-connected disability.
- A ârecently separated veteranâ means any veteran during the three-year period beginning on the date of such veteranâs discharge or release from active duty in the U.S. military, ground, naval, or air service.
- An âactive duty wartime or campaign badge veteranâ means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
- An âArmed forces service medal veteranâ means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on cfocussoftware.applytojob.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents
10 months ago