Incident Response Analyst

Cyber Synergy Consulting Group, LLC
Washington, DC, United States
1 day ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Shift work
Job source

Tech stack

Python (Programming Language) Log Analysis Network Forensics Packet Analyzer Windows PowerShell Security Information and Event Management Wireshark Scripting Fireeye Splunk Servicenow

Job description

  • Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.
  • Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.
  • Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.
  • Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.
  • Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.
  • Support containment, eradication, and recovery efforts aligned to federal IR procedures.
  • Participate in tabletop exercises, readiness assessments, and operational continuity testing.
  • Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs.
  • Assist with audit support, evidence gathering, and post-incident reviews.
  • Contribute to continuous improvement of incident response processes and playbooks.

Requirements

We are seeking an experienced Incident Response Analyst to support Task 4 - Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.

The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB)., * 2-5+ years of experience in cybersecurity operations, SOC analysis, or incident response.

  • Direct hands-on experience with IR tools, including:

  • CrowdStrike Falcon (EDR)
  • FireEye/Trellix (HX, Helix, or equivalent)
  • Splunk (SIEM, dashboards, search queries)
  • NetWitness (network forensics, packet analysis)
  • Magnet AXIOM (host forensics), Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts., Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance., Ability to clearly document investigations and communicate findings to technical and non-technical audiences., * Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).
  • Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.
  • Experience performing threat hunting across EDR, SIEM, and NDR tools.
  • Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).
  • Experience with ServiceNow or similar ticketing platforms

Benefits & conditions

  • Core hours: 7:00 AM - 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.
  • Participation in on-call rotations may be required.
  • Remote work permitted with reliable connectivity and camera-enabled participation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · World Congress 2026 Europe

Videos

See all

Related articles

See all