Incident Response Analyst

Remote Full-time
Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)

Location: Remote with occasional on-site (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)

We are seeking an experienced Incident Response Analyst to support Task 4 – Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.

The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB).

Key Responsibilities
β€’ Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.
β€’ Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.
β€’ Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.
β€’ Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.
β€’ Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.
β€’ Support containment, eradication, and recovery efforts aligned to federal IR procedures.
β€’ Participate in tabletop exercises, readiness assessments, and operational continuity testing.
β€’ Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs.
β€’ Assist with audit support, evidence gathering, and post-incident reviews.
β€’ Contribute to continuous improvement of incident response processes and playbooks.

Required Qualifications
β€’ 2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response.
β€’ Direct hands-on experience with IR tools, including:
β€’ *

CrowdStrike Falcon (EDR)
β€’ FireEye/Trellix (HX, Helix, or equivalent)
β€’ Splunk (SIEM, dashboards, search queries)
β€’ NetWitness (network forensics, packet analysis)
β€’ Magnet AXIOM (host forensics)
β€’ Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts.
β€’ Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance.
β€’ Ability to clearly document investigations and communicate findings to technical and non-technical audiences.
β€’ Eligibility to obtain and maintain a Public Trust clearance.

Preferred Qualifications
β€’ Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).
β€’ Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.
β€’ Experience performing threat hunting across EDR, SIEM, and NDR tools.
β€’ Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).
β€’ Experience with ServiceNow or similar ticketing platforms

Work ScheduleExpectations
β€’ Core hours: 7:00 AM – 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.
β€’ Participation in on-call rotations may be required.
β€’ Remote work permitted with reliable connectivity and camera-enabled participation.

Apply tot his job

Apply To this Job
Apply Now β†’

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Digital Library Federation is hiring: Library Archives Operations Manager in Cha

Remote

Experienced Digital Customer Care Agent for Overnight Remote Operations - Flexible Schedules Available - Competitive Hourly Rate

Remote

[Remote] Retirement Plan Consultant - Keene, NH

Remote

Partner Engagement Specialist - English Speaking

Remote

SAP MM / PP Analyst

Remote

Experienced Account Data Analyst and Administrative Support Specialist for Sales, Service, and Order Management Teams at blithequark

Remote

Telepharmacy Technician Onsite – Store – Chicago, Illinois –Part Time

Remote

Auto Claim Representative II

Remote

Associate Supervisor PT

Remote

Adjunct Faculty, Sports & Exercise Studies

Remote
← Back