> Markdown version of [/jobs/ext/3659004-cyber-analyst-tier-2-incident-commander](https://www.wearedevelopers.com/jobs/ext/3659004-cyber-analyst-tier-2-incident-commander). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Analyst (Tier 2) / Incident Commander - **Company:** Valiant Solutions, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $115,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Data Analysis, Antivirus Softwares, User Authentication, Computer Networks, Digital Forensics, Federal Information Processing Standards (FIPS), Network Security, Log Analysis, Security Information and Event Management, Mitre Att&ck, Cortex XSOAR Platform, 3-tier Architectures, Splunk - **Published:** October 9, 2026 - **Apply:** https://www.builtincolorado.com/job/cyber-analyst-tier-2-incident-commander/11586210?handler=ApplyRedirect ## About the Role The ideal candidate must possess deep knowledge of cybersecurity incidents, anomaly analysis, log analysis, digital forensics, and common threat vectors to effectively determine the required actions to resolve an incident. You must demonstrate a strong understanding of Splunk SIEM, Microsoft Defender EDR, XSOAR, and support forensic tools to effectively analyze data and guide response activities. This role requires a blend of technical expertise and compliance-minded discipline to maintain operational readiness and meet stringent federal reporting procedures., * 7+ years of relevant work experience or a Bachelor's Degree with 2+ years of relevant experience * US Citizenship and must be able to pass a background investigation (Public Trust - High Risk) * Excellent organizational, verbal, presentation/facilitation, and written communication skills. Comfortable presenting briefings to the client. * Demonstrate proficiency in the Incident Response Process and SOC operations, and a good understanding of threat hunting * Good understanding of system log information and where to collect specific data/attributes as required for the Incident Event * Operational understanding of enterprise networking and security tools (firewalls, Antivirus, HIDS, IDS/IPS, proxy, WAF), Windows and Unix/Linux systems' operations * Experience performing log analysis and reporting * Experience creating and tracking investigations to resolution * Experience with Endpoint security solutions, including but not limited to: Windows Defender, Antivirus Solutions, and EDR Tools * Understanding of compliance or regulatory frameworks (i.e., FISMA, NIST, ISO) * Solid understanding of application, authentication, network security principles, and operating system hardening techniques * General knowledge of cyber-attack frameworks (MITRE ATT&CK and Lockheed Cyber Kill Chain) * Understanding of Computer Network Defense (CND) policies, procedures, and regulations * SIEM monitoring and analysis, analyzing network traffic, log analysis, prioritizing and differentiating between potential intrusion attempts and false alarms * Ability to work with or support senior leaders to understand risk factors and communicate effective mitigation strategies * Ability to work independently to address and resolve a security incident with minimal supervision., Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job. ## Description Valiant Solutions is seeking a Cyber Analyst (Tier 2) / Incident Commander to join our rapidly growing and innovative cybersecurity team!, As a Cyber Analyst (Tier 2) / Incident Commander, you and your team will man a 24x7x365 cybersecurity operations and coordination center. You will manage escalated alerts, notifications, and communications while executing core incident response activities, including tracking the lifecycle of events, managing stakeholder communication, and driving remediation and recovery actions. Additionally, you will ensure all reports are accurately documented in the incident tracking system and coordinate directly with reporting entities to gain a full understanding of each event while strictly following established SOPs for the escalation and notification of Federal Leadership., * Supports/develops reports during and after incidents, which include all actions taken to properly mitigate, recover and return operations to normal operations. * Lead and actively participate in security-related meetings and discussions with the client. * Perform incident response analysis based on investigation requirements. * Participate in the remediation of incidents and responses that are generated from live threats against the enterprise. * Record and report all incidents per Federal and department policy. * Create and track network incidents and investigations through closure. * Serve as key personnel for Incident Management; provide coordination, task assignment, and process guidance for incident response events. * Monitor and investigate security events received through the SIEM or other security tools. * Carry out Level 2 triage of incoming Incidents (initial IR assessment of the priority of the event, initial determination of incident nature to determine risk and damage, or appropriate routing of security or privacy data request). * Work directly with the Tier 3 Incident Commander and manage assigned investigations to ensure they are being actively worked on and assist Tier 1 and Tier 2 analysts as needed to resolve investigations. * Review, revise, and recommend technical, process, and physical controls. * Develop and implement defensive cyber best practice tactics, techniques, and procedures.