Cyber Incident Response Analysts
LUNA DATA SOLUTIONS
Austin, TX, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Cyber Security
Linux
File Systems
Issue Tracking Systems
Data Intelligence
Intrusion Detection Systems
Linux System Administration
Log Analysis
Network Monitoring
Security Information and Event Management
In-Plane Switching (IPS)
+6 more
Mitre Att&ck
Malware
Falcon Platform
Cybercrime
Microsoft Sentinel
SentinelOne Expertise
Job description
- Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery.
- Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis.
- Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies.
- Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK.
- Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools.
- Produce incident reports, timelines, and executive summaries for stakeholders.
- Support multi-agency response operations, including SLTT partners and critical infrastructure entities.
- Provide recommendations for detection improvements, hardening, and long-term mitigation.
- Participate in post-incident reviews, lessons learned, and playbook updates.
- Maintain readiness for 24x7 response through on-call rotation or surge support.
Requirements
- 5 years: Advanced host-based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity.
- 5 years: Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines.
- 5 years: Experience producing high-quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows.
- 4 years: Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet-level and log-level data from Corelight, NetWitness, and CRIBL pipelines.
- 3 years: Incident Commander experience.
- 1 year: Experience supporting SLTT or critical infrastructure environments, including multi-tenant IR operations and cross-agency coordination.
Preferred Experience & Certifications
- 5 years: Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK.
- 5 years: Hands-on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems.
- 4 years: Security Certifications preferred: CISSP, CIH, Sec+.
Benefits & conditions
- Competitive compensation and benefits including health, dental, vision, life and accident insurance, disability insurance and much more!
- Altruistic work
- Great work-life balance
- Hybrid work schedule
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago