Incident Response Expert / Cyber Eviction Analyst

Node Inc.
Arlington, VA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Cyber Security Computer Engineering Linux Digital Assets Identity and Access Management Network Security Network Architecture Network Intrusion Detection Systems Security Information and Event Management Cloud Platform System
+4 more
Information Technology Cybercrime ArcSight Event Correlation Splunk

Job description

As an Incident Response Expert / Cyber Eviction Analyst, you will play a critical role in protecting our clients’ digital assets and infrastructure. You will serve as a subject matter expert in cyber incident response, applying deep knowledge of threat actor tools, techniques, and procedures to identify, contain, and eradicate threats. Your expertise will help shape technical objectives, develop creative solutions, and guide incident response teams in high-stakes environments., * Serving as a hunt and incident response subject matter expert, providing technical direction and alternatives to response teams

  • Applying deep knowledge of threat actor tools, techniques, and procedures (TTPs) to complex incident response challenges
  • Producing executive summaries and detailed technical reports for stakeholders
  • Conducting expert analysis and research on hunt and incident response problems with broad direction
  • Setting technical objectives and developing creative solutions to complex security issues
  • Analyzing incident data and victim environments to recommend targeted mitigations
  • Advising on countermeasure implementation and customization
  • Supporting containment and eradication missions
  • Documenting analysis in a standardized knowledge base and maintaining process/procedure documentation
  • Guiding completion of hunt and incident response activities across multiple environments

Requirements

  • Bachelor’s degree in Computer Science, Cyber Security, Computer Engineering, or a related field; or a high school diploma with 10+ years of technical experience
  • 8+ years of cyber incident response experience, including threat hunting, containment, and eradication
  • Proficiency administering and investigating on both Linux/Unix and Windows systems
  • Hands-on experience using Splunk as a SIEM for incident response or threat hunting
  • Strong understanding of network architecture, network security concepts, and attack stages/classes
  • Incident response experience across on-premises, cloud environments, and Windows Active Directory
  • Meets DoD 8140.01 certification requirements at IAT II, IASAE II, or CSSP Analyst level
  • U.S. citizen with an active TS/SCI clearance and ability to obtain DHS suitability
  • Ability to travel domestically on short notice (~25%)
  • Experience producing executive summaries and detailed technical incident response reports

Preferred Qualifications:

  • Holds at least one of the following certifications: GCIA, GCIH, CEH, or GIAC GNFA
  • Experience with leadership or mentoring in incident response teams
  • Familiarity with CND policies and procedures
  • Knowledge of threat environments, network/system administration, and IAM tools
  • Experience with enterprise architecture security review and defense-in-depth strategies
  • Expertise in host and network intrusion detection, event correlation, and malicious activity analysis
  • Strong collaboration skills with stakeholders across multiple locations

Benefits & conditions

We are proud to offer competitive compensation and benefits packages to include:

  • Medical
  • Dental
  • Vision
  • Basic Life
  • Long-Term Disability
  • Health Saving Account
  • 401K
  • Three weeks of PTO
  • 10 Paid Holidays
  • Pre-Approved Online Training

About the company

Node.Digital is an innovative minority-owned solutions and services company specializing in AI & Automation. We combine proprietary agile development services with next-generation technology to create seamless customer experiences, driving digitalization and automation across industries. Our mission is to blend story, strategy, and technology to deliver frictionless multichannel user experiences.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all