Cybersecurity Analyst, Incident Responder

DIGITAL GLOBAL CONNECTORS, LLC
McLean, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

McLean, United States of America

Tech stack

ARM
JIRA
Azure
Cloud Computing
Cloud Computing Security
CompTIA Security+
Computer Security
Information Systems
Computer Networks
Digital Forensics
File Systems
Intrusion Detection and Prevention
Intrusion Detection Systems
Linux Security Modules
Log Analysis
Microsoft Office
Network Forensics
Network Protocols
Cloud Services
Security Information and Event Management
Wireshark
Cloud Platform System
Mitre Att&ck
Malware
Cyber Threat Analysis
Azure Security Center
Information Technology
Cybercrime
Microsoft Sentinel
Windows Security
Cyber Warfare
Splunk
Cisco networks
ServiceNow
Vulnerability Analysis

Job description

Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The Tier 2 Incident Responder is responsible for investigating, containing, eradicating, and recovering from cybersecurity incidents affecting enterprise information systems, networks, cloud environments, and critical business operations.

This position performs advanced analysis of cybersecurity events, coordinates incident response activities, conducts forensic triage, analyzes malware and attacker tactics, and collaborates with Security Operations Center (SOC) personnel, Security Engineers, Threat Hunters, ISSOs, and System Owners to minimize operational impact and strengthen the organization's cybersecurity posture., Incident Response

  • Investigate cybersecurity incidents affecting enterprise information systems, applications, cloud services, and networks.
  • Perform incident triage to determine scope, severity, and operational impact.
  • Execute containment, eradication, and recovery procedures in accordance with established incident response plans.
  • Coordinate response activities with technical teams and program leadership.
  • Validate successful remediation before incident closure.
  • Maintain incident timelines and documentation throughout the response lifecycle.

Security Investigation

  • Analyze suspicious network traffic, endpoint activity, authentication events, and system logs.
  • Identify indicators of compromise (IOCs), indicators of attack (IOAs), and attacker behaviors.
  • Determine root cause and attack vectors.
  • Assess the extent of compromise across affected systems.
  • Identify persistence mechanisms and unauthorized access.
  • Recommend remediation and long-term defensive improvements.

Digital Forensic Triage

  • Collect and preserve digital evidence in accordance with forensic best practices.
  • Perform preliminary forensic analysis of endpoints, servers, and cloud resources.
  • Review memory captures, event logs, registry artifacts, file systems, browser artifacts, and authentication records.
  • Support chain-of-custody documentation.
  • Coordinate with Digital Forensics Analysts for advanced forensic examinations when required.

Malware Analysis Support

  • Analyze suspicious files and malicious code using approved analysis tools.
  • Identify malware behavior and associated indicators.
  • Review sandbox analysis results.
  • Document malware characteristics and recommended detection signatures.
  • Coordinate with Threat Intelligence and Threat Hunting personnel regarding emerging threats.

Threat Detection and Analysis

  • Investigate alerts generated by SIEM, EDR, IDS/IPS, and XDR platforms.
  • Correlate data from multiple security tools to identify attack patterns.
  • Evaluate threat intelligence to determine relevance to ongoing investigations.
  • Recommend improvements to detection logic based on investigative findings.
  • Assist in developing new detection use cases.

Security Tool Operations

Utilize technologies including:

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud
  • CrowdStrike Falcon
  • Palo Alto Cortex XDR
  • Trellix
  • Cisco Secure
  • Wireshark
  • Velociraptor
  • Security Information and Event Management (SIEM)
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)

Support tuning and optimization of security monitoring technologies based on incident findings.

Reporting and Documentation

Develop and maintain:

  • Incident Reports
  • After-Action Reports
  • Root Cause Analyses
  • Investigation Summaries
  • Lessons Learned
  • Security Recommendations
  • Executive Briefings
  • Incident Metrics
  • Threat Assessments
  • Standard Operating Procedures

Ensure documentation is complete, technically accurate, and suitable for operational and audit purposes.

Collaboration

  • Coordinate with Tier 1 SOC Analysts, Threat Hunters, Digital Forensics Analysts, Security Engineers, ISSOs, System Owners, and Government stakeholders.
  • Participate in incident response working groups.
  • Provide technical guidance during active cybersecurity incidents.
  • Support enterprise cybersecurity exercises and tabletop events.
  • Share investigative findings with cross-functional cybersecurity teams.

Continuous Improvement

  • Recommend improvements to incident response procedures and playbooks.
  • Participate in lessons-learned reviews following significant incidents.
  • Assist with development of new detection capabilities.
  • Monitor emerging attack techniques and defensive technologies.
  • Maintain technical proficiency through ongoing training and professional certification.

Requirements

The successful candidate will possess strong technical investigative skills, experience responding to sophisticated cyber threats, and the ability to perform effective incident analysis within complex enterprise environments., * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.

  • Minimum four (4) years of experience performing cybersecurity incident response or cyber defense operations.
  • Experience investigating enterprise cybersecurity incidents.
  • Experience using SIEM, EDR, XDR, and log analysis platforms.
  • Understanding of networking protocols, operating systems, malware behavior, and common attack techniques.
  • Strong analytical, investigative, documentation, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust., * Experience supporting a Federal civilian agency.
  • Experience performing digital forensic triage or malware analysis.
  • Experience supporting cloud incident response in Microsoft Azure or AWS environments.
  • Experience utilizing MITRE ATT&CK during investigations.
  • GIAC Certified Incident Handler (GCIH)
  • CompTIA CySA+
  • CompTIA Security+
  • GIAC Certified Forensic Analyst (GCFA)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Ethical Hacker (CEH) (preferred)

Knowledge, Skills, and Abilities

  • Incident Response
  • Cyber Defense Operations
  • Digital Forensic Triage
  • Malware Analysis
  • Threat Detection
  • Threat Intelligence
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Security Information and Event Management (SIEM)
  • Wireshark
  • Velociraptor
  • Log Analysis
  • Network Traffic Analysis
  • Windows Security
  • Linux Security
  • Cloud Security
  • MITRE ATT&CK Framework
  • NIST SP 800-61 Incident Response
  • NIST Cybersecurity Framework
  • Technical Documentation
  • Root Cause Analysis
  • Microsoft Office Suite
  • ServiceNow
  • Jira

Security Requirements

  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support incident response activities, emergency cybersecurity operations, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
  • Must maintain strict confidentiality while handling sensitive incident data, forensic evidence, investigative records, and Federal information systems.
  • Ability to respond effectively to cybersecurity incidents in a fast-paced operational environment while coordinating with Government stakeholders, technical teams, and program leadership to minimize risk and restore secure operations.

Apply for this position