SOC / Incident Response Analyst

Amentum Services, Inc.
Washington, DC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Digital Forensics Security Information and Event Management Mitre Att&ck Malware Cyber Threat Analysis Cybercrime

Job description

Amentum is seeking SOC / Incident Response Analyst to support our U.S. Department of Energy contract. Positions will be based in the Washington, D.C area., Provide a wide range of Cyber Intelligence (CI) services to deliver timely, actionable, and relevant threat intelligence on hostile nation-states, cyber adversaries, and criminals seeking to conduct malicious cyber activities against U.S. energy sector partners., Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.

Requirements

  • 3-8+ years supporting Security Operations Centers or Incident Response teams.
  • Experience with SIEM platforms, EDR tools, threat hunting, malware analysis, and digital forensics.
  • Knowledge of MITRE ATT&CK, NIST Cybersecurity Framework, and cyber kill chain methodologies.
  • Security+, GCIH, GCFA, GCFE, or equivalent certifications preferred.

Security Clearance Required:

  • Active TS/SCI or DOE Q

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all