> Markdown version of [/jobs/ext/1967059-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1967059-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst - **Company:** Tetrad Digital Integrity LLC - **Location:** Arlington, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Proxy Servers, Bash Shell, Cyber Security, Information Systems, Computer Networks, Computer Forensics, Linux, Monitoring of Systems, Internet Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Network Protocols, Windows PowerShell, Security Information and Event Management, Scripting, Load Balancing, Mitre Att&ck, Malware, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Security Orchestration, Automation & Response - **Published:** August 7, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-incident-response-analyst-arlington-va--a125c3ba-48dd-4ef2-9752-981809508b0f ## About the Role * Ability to obtain Public Trust clearance and successfully complete the EOD process. * Candidates must possess at least one of the following certifications: GIAC: GCIH, GCIA, GCFA, GCFE, GREM, or GPEN, CISSP, OSCP, OSCE, or OSWP. * Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field and 12-15 years of relevant experience. * Must have technical hands-on experience in the areas of incident detection and response, malware analysis, or computer forensics. * Expertise with Windows and Linux operating systems, enterprise networking, common protocols, and security infrastructure (firewalls, proxies, VPNs, load balancers). * Demonstrated experience investigating cyber incidents, performing root cause analysis, identifying attacker TTPs, and leveraging frameworks such as MITRE ATT&CK and the Cyber Kill Chain. * Proficiency in Python, PowerShell, Bash, or similar scripting languages to support security automation and incident response. PREFERRED QUALIFICATIONS: * Experience in cyber government, and/or federal law enforcement FISMA systems., Analysis Skills, Automation, Bash Scripting, CISSP - Certified Information Systems Security Professional, Case Management, Computer Forensics, Computer Science, Computer Security, Continuous Improvement, Documentation, Federal Government, Firewalls, GCFA - GIAC Certified Forensic Analyst, GCIA - GIAC Certified Intrusion Analyst, GCIH - GIAC Certified Incident Handler, GIAC - Global Information Assurance Certification, GPEN - GIAC Penetration Tester, Government, Incident Response, Information Technology & Information Systems, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Linux Operating System, Load Balancing, Malware Analysis, Microsoft Windows Operating System, Network Protocols, Operational Measurement, Operational Strategy, Operational Support, Performance Analysis, Performance Metrics, Python Programming/Scripting Language, Risk Management, Root Cause Analysis, Scripting (Scripting Languages), Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Security Infrastructure, Standard Operating Procedures (SOP), Telemetry, Use Cases, VPN (Virtual Private Network), Windows PowerShell ## Description TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission-critical government program. As part of the Security Operations Center, you will help monitor, detect, investigate, and respond to cybersecurity threats affecting a large-scale enterprise environment while supporting coordinated incident response across multiple organizations., * Lead and coordinate cyber incident response activities across the full Incident Response lifecycle, including investigation, containment, eradication, and recovery. * Analyze security events, logs, network traffic, endpoint telemetry, and forensic artifacts to determine the scope, root cause, and impact of cyber incidents. * Identify adversary tactics, techniques, and procedures (TTPs) and develop indicators of compromise (IOCs) to improve threat detection and response. * Develop, maintain, and enhance Incident Response processes, playbooks, workflows, and standard operating procedures (SOPs). * Configure, tune, and optimize security technologies, including SIEM, EDR, IDS/IPS, and related monitoring tools, to improve detection accuracy and reduce false positives. * Create and maintain detection content, including correlation rules, use cases, signatures, alerts, and automation scripts to strengthen SOC monitoring capabilities. * Document investigations, response activities, and findings within case management systems, producing clear incident reports and after-action documentation. * Establish and track SOC performance metrics and key performance indicators (KPIs) to measure operational effectiveness and support continuous improvement. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)