> Markdown version of [/jobs/ext/1758140-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1758140-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst - **Company:** cFocus Software Incorporated - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing, Cyber Security, Linux, Digital Forensics, Intrusion Detection and Prevention, Security Information and Event Management, Computer Networking Systems, Malware, Information Technology - **Published:** July 1, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/67kfPn4qod ## About the Role * Public Trust Clearance * B.S. Computer Science, Information Technology, or a related field * 5+ years of cybersecurity experience. * 5+ years supporting cybersecurity incident response or Security Operations Center (SOC) environments. * Experience investigating security incidents across Windows, Linux, cloud, and enterprise networks. * Experience with SIEM technologies and security monitoring platforms. * Experience performing incident triage and root cause analysis. * Knowledge of malware analysis and digital forensics concepts. * Understanding of NIST Cybersecurity Framework and NIST SP 800-61 Incident Handling Guide. * Ability to obtain and maintain required NIH suitability/background investigation. * Active GCIH, GCFA, GCIA, CISSP, CySA+, Security+, CEH, CHFI, CISM, or GSEC ## Description cFocus Software seeks a Incident Response Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Monitor security events across the NIH/OD-OIT environment. * Detect, analyze, and respond to cybersecurity incidents affecting enterprise systems. * Perform incident triage to determine scope, severity, urgency, and operational impact. * Support incident containment, eradication, recovery, and restoration activities. * Investigate suspected security incidents within established response time requirements. * Coordinate incident handling activities with NIH and HHS cybersecurity organizations. * Monitor enterprise security logs and alerts. * Perform network and host-based intrusion detection. * Monitor cloud applications and cloud infrastructure. * Support continuous 24x7 security monitoring operations. * Identify indicators of compromise (IOCs) and suspicious activity. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)