> Markdown version of [/jobs/ext/622123-incident-response-expert-cyber-eviction-analyst](https://www.wearedevelopers.com/jobs/ext/622123-incident-response-expert-cyber-eviction-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Expert / Cyber Eviction Analyst - **Company:** Node Inc. - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Cyber Security, Computer Engineering, Linux, Digital Assets, Identity and Access Management, Network Security, Network Architecture, Network Intrusion Detection Systems, Security Information and Event Management, Cloud Platform System, Information Technology, Cybercrime, ArcSight Event Correlation, Splunk - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/67782c47-3929-4b3e-9fba-a7c492d4ca01 ## About the Role * Bachelor's degree in Computer Science, Cyber Security, Computer Engineering, or a related field; or a high school diploma with 10+ years of technical experience * 8+ years of cyber incident response experience, including threat hunting, containment, and eradication * Proficiency administering and investigating on both Linux/Unix and Windows systems * Hands-on experience using Splunk as a SIEM for incident response or threat hunting * Strong understanding of network architecture, network security concepts, and attack stages/classes * Incident response experience across on-premises, cloud environments, and Windows Active Directory * Meets DoD 8140.01 certification requirements at IAT II, IASAE II, or CSSP Analyst level * U.S. citizen with an active TS/SCI clearance and ability to obtain DHS suitability * Ability to travel domestically on short notice (~25%) * Experience producing executive summaries and detailed technical incident response reports Preferred Qualifications: * Holds at least one of the following certifications: GCIA, GCIH, CEH, or GIAC GNFA * Experience with leadership or mentoring in incident response teams * Familiarity with CND policies and procedures * Knowledge of threat environments, network/system administration, and IAM tools * Experience with enterprise architecture security review and defense-in-depth strategies * Expertise in host and network intrusion detection, event correlation, and malicious activity analysis * Strong collaboration skills with stakeholders across multiple locations ## Description As an Incident Response Expert / Cyber Eviction Analyst, you will play a critical role in protecting our clients' digital assets and infrastructure. You will serve as a subject matter expert in cyber incident response, applying deep knowledge of threat actor tools, techniques, and procedures to identify, contain, and eradicate threats. Your expertise will help shape technical objectives, develop creative solutions, and guide incident response teams in high-stakes environments., * Serving as a hunt and incident response subject matter expert, providing technical direction and alternatives to response teams * Applying deep knowledge of threat actor tools, techniques, and procedures (TTPs) to complex incident response challenges * Producing executive summaries and detailed technical reports for stakeholders * Conducting expert analysis and research on hunt and incident response problems with broad direction * Setting technical objectives and developing creative solutions to complex security issues * Analyzing incident data and victim environments to recommend targeted mitigations * Advising on countermeasure implementation and customization * Supporting containment and eradication missions * Documenting analysis in a standardized knowledge base and maintaining process/procedure documentation * Guiding completion of hunt and incident response activities across multiple environments ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)