Cybersecurity Incident Response Triage IR Analyst
Core
Monitor, investigate, and respond to cybersecurity incidents, policy violations, and insider-threat indicators for US federal government clients.
Role type
Cybersecurity Incident Response Triage Analyst
Builds
Incident response strategies and procedures for federal defense, national security, and public safety organizations
Domain
Cybersecurity / Federal Government
Deliverable
client delivery
Required skills
Incident response lifecycle knowledge, insider-threat indicators, data loss prevention (DLP), SIEM solutions, log analysis, network/host security tools, TCP/IP and packet analysis, malware analysis concepts, Windows/Linux architecture, basic data parsing (regex, grep, sed)
Preferred skills
GIAC certifications (GCED, GCLD, GCIH, GCFA, GREM), CISSP
Technologies
SIEM, Anti-Virus, Intrusion Detection Systems (IDS), Firewalls, Active Directory, Web Proxies, DLP tools, network scanning tools, packet analyzers
Responsibilities
Monitor and respond to cybersecurity incidents; analyze incidents to determine nature and scope; coordinate with CIRT teams; document incidents and response activities; collaborate with legal, HR, and management to investigate issues and interview subjects; assist in refining incident response strategies
Seniority
Junior to Mid-level, hands-on IC