Incident Responder - Tier 2
Role details
Job location
Tech stack
Job description
Position Summary: The Tier 2 Incident Responder performs in-depth investigation, containment, and remediation of security incidents escalated from Tier 1, applying the NIST SP 800-61 incident response life cycle and mentors Tier 1 analysts on investigative technique., Duties and Responsibilities: Duties include the following.
- Investigate escalated alerts and incidents through log analysis, malware analysis, and digital forensics, determining scope, root cause, and impact.
- Support execution of containment and eradication actions. Support recovery of affected systems to a known-good, hardened baseline.
- Document incident timelines and findings, create and track POA&M entries to closure and contribute to after-action reviews that feed back into detection content and playbooks.
- Review and remediate findings.
- Provide technical mentorship to Tier 1 Analysts and serve as a secondary escalation point during major incidents or surge conditions.
Requirements
Required Education and Experience: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience; three to five years of hands-on incident response, digital forensics, or security operations experience.
Required Certifications: DoD 8570/8140 IAT Level III or CSSP Incident Responder certification (e.g., GCIH, GCFA, or CySA+) required; working knowledge of endpoint detection and response (EDR) tooling, packet analysis, and at least one scripting language (e.g., Python, PowerShell, or Bash) preferred.