> Markdown version of [/jobs/ext/3062707-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3062707-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Analyst - **Company:** Cyber Synergy Consulting Group, LLC - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Python (Programming Language), Log Analysis, Network Forensics, Packet Analyzer, Windows PowerShell, Security Information and Event Management, Wireshark, Scripting, Fireeye, Splunk, Servicenow - **Published:** September 25, 2026 - **Apply:** https://www.juju.com/job/16_625ee6919 ## About the Role We are seeking an experienced Incident Response Analyst to support Task 4 - Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams. The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB)., * 2-5+ years of experience in cybersecurity operations, SOC analysis, or incident response. * Direct hands-on experience with IR tools, including: * CrowdStrike Falcon (EDR) * FireEye/Trellix (HX, Helix, or equivalent) * Splunk (SIEM, dashboards, search queries) * NetWitness (network forensics, packet analysis) * Magnet AXIOM (host forensics), Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts., Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance., Ability to clearly document investigations and communicate findings to technical and non-technical audiences., * Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.). * Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related. * Experience performing threat hunting across EDR, SIEM, and NDR tools. * Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell). * Experience with ServiceNow or similar ticketing platforms ## Description * Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms. * Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM. * Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions. * Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations. * Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms. * Support containment, eradication, and recovery efforts aligned to federal IR procedures. * Participate in tabletop exercises, readiness assessments, and operational continuity testing. * Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs. * Assist with audit support, evidence gathering, and post-incident reviews. * Contribute to continuous improvement of incident response processes and playbooks. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)