> Markdown version of [/jobs/ext/637943-contract-cyber-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/637943-contract-cyber-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # contract Cyber Incident Response Analyst - **Company:** TEXAS GOVLINK, INC. - **Location:** Austin, TX, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Linux, File Systems, Issue Tracking Systems, Data Intelligence, Intrusion Detection Systems, Linux System Administration, Log Analysis, Network Monitoring, Security Information and Event Management, In-Plane Switching (IPS), Mitre Att&ck, Malware, Falcon Platform, Cybercrime, Microsoft Sentinel, SentinelOne Expertise - **Published:** June 25, 2026 - **Apply:** https://www.dice.com/job-detail/fe10e676-0c1e-4b0a-a5ca-561ffe368670 ## About the Role 5 years of: * Advanced host-based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity. * Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines. * Experience producing high-quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows. 4 years of: * Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet-level and log-level data from but not limited to Corelight, NetWitness, and CRIBL pipelines. 3 years of: * Incident Commander experience 1 year of: * Experience supporting SLTT or critical infrastructure environments, including multi-tenant IR operations and cross-agency coordination. Preferred: 5 years of: * Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK. * Hands-on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems. 4 years of: * Security Certifications Preferred (CISSP, CIH, Sec+) ## Description Hybrid - in San Antonio, TX OR Austin, TX. Primary location to be assigned by TXCC., We are currently seeking a contract Cyber Incident Response Analyst to be a key resource on a technical services team for our client, the Texas Cyber Command (TXCC)., * Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery. * Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis. * Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies. * Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK. * Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools. * Produce incident reports, timelines, and executive summaries for statewide stakeholders. * Support multi-agency response operations, including SLTT partners and critical infrastructure entities. * Provide recommendations for detection improvements, hardening, and long-term mitigation. * Participate in post-incident reviews, lessons learned, and playbook updates. * Maintain readiness for 24x7 response through on-call rotation or surge support. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)