cFocus Software Incorporated
Posted 1mo ago

AOUSC - Incident Response Analyst

cFocus Software Incorporated
Washington, District of Columbia, United States
HybridFull Time
Responsibilities
  • performing triage
  • refining detections
  • analyzing payloads
Requirements
  • Public Trust clearance
  • BS in CS/IT or related
  • 3+ years IR experience
  • 2+ years Python and PowerShell
  • Experience with live triage
  • Log correlation
  • Velociraptor
  • Splunk ES
  • Sentinel, and familiarity with NIST incident handling
Technical tools mentioned
PythonPowerShellVelociraptorSplunk ESSentinel

Job description

cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 3+ years of experience in an IR role. 
  • 2+ years’ experience using Python and PowerShell scripts for decoding/decryption of obfuscated payloads. 
  • 2 years of experience in performing live triage, log correlation, detection rule refinement, to include usage of Velociraptor, Splunk ES and Sentinel.
  • 1 year of experience in federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide. 
  • Active SANS GCIH or GCIA certification

About cFocus Software Incorporated

Private IT services firm providing cybersecurity, cloud, geospatial, and enterprise software services to U.S. federal agencies.

Similar jobs

Incident Response Analyst roles near Washington, District of Columbia
5d
Save
Mark Applied
Hide
Incident Response Senior Analyst (Tier 3)
Quantico, Virginia, United States
$135k-$150k/yr OnsiteFull Time
Resource Management Concepts
Resource Management Concepts: Delivering Mission-Focused IT & Cybersecurity Solutions
3+ YOERequires 3 years of incident response experience, TS/SCI eligibility, DoD 8570 IAT Level II and CSSP Incident Responder certifications, plus an associate degree in a relevant field or 5 years of related experience.
IT, Digital Forensics & Incident Response (DFIR)
1w
Save
Mark Applied
Hide
Senior Incident Response Analyst
Washington, District of Columbia, United States
$132k-$337k/yr OnsiteFull Time
TikTok USDS Joint Venture LLC
TikTok USDS Joint Venture LLC: Ensuring U.S. data security and content integrity for TikTok.
5+ YOERequires 5+ years handling high-severity security incidents, advanced Linux/Unix skills, multi-cloud and container forensics experience, complex investigations, and incident leadership.
Linux, Unix, Docker, Kubernetes, NIST SP 800-61, ISO/IEC 27035, MITRE ATT&CK, PCAP, Zeek
1mo
Save
Mark Applied
Hide
Computer Security Incident Report Analyst with TS/SCI Clearance [Salesforce National Security]
Herndon, Virginia, United States
$111k-$122k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
2+ YOEU.S. citizen with active TS/SCI+Polygraph, 2+ years in cybersecurity or incident response, technical degree or equivalent, SIEM and cloud security experience, strong communication and problem-solving skills.
AWS, Splunk, Azure Sentinel, ElasticStack, Kibana, Grafana, SQL, SPL, GraphQL, Bash, Python, Security Information and Event Manager (SIEM), Mac OSX, Microsoft Windows, Linux/Unix
1mo
Save
Mark Applied
Hide
SOC / Incident Response Analyst
Washington, District of Columbia, United States
OnsiteFull Time
Amentum
AmentumNYSE: AMTM: Global provider of engineering, technical, and mission-critical services.
3+ YOERequires 3–8+ years supporting SOC or incident response teams, experience with SIEM, EDR, threat hunting, malware analysis, and digital forensics, plus active TS/SCI or DOE Q clearance.
SIEM, EDR, MITRE ATT&CK, NIST Cybersecurity Framework
1mo
Save
Mark Applied
Hide
SOC / Incident Response Analyst
Washington, District of Columbia, United States
OnsiteFull Time
Amentum
AmentumNYSE: AMTM: Global provider of engineering, technical, and mission-critical services.
3+ YOE3+ years SOC/incident response experience; familiarity with SIEM, EDR, threat hunting, malware analysis, digital forensics; knowledge of MITRE ATT&CK and NIST CSF; active TS/SCI or DOE Q clearance required.
SIEM, EDR, MITRE ATT&CK, NIST Cybersecurity Framework
1mo
Save
Mark Applied
Hide
Senior Incident Response Analyst
Arlington, Virginia, United States
HybridFull Time
Tetrad Digital Integrity
Tetrad Digital Integrity: Cybersecurity firm delivering cybersecurity performance management and full-lifecycle cyber services to government and commercial clients.
12+ YOEAbility to obtain Public Trust; required bachelor's degree and 12+ years experience; hands-on incident detection/response, malware analysis or forensics; expertise with Windows/Linux, networking, SIEM/EDR/IDS/IPS; scripting (Python, PowerShell, Bash).
SIEM, EDR, IDS/IPS, Python, PowerShell, Bash, Windows, Linux, MITRE ATT&CK, Cyber Kill Chain, firewalls, proxies, VPN
5mo
Save
Mark Applied
Hide
Senior J-9 Hac Incident Response Analyst
Fort Meade, Maryland, United States
OnsiteFull Time
PD Inc
PD Inc: Private Baltimore-based IT consulting and technical services firm providing solutions and personnel to government and commercial clients.
5+ YOEFive+ years incident response, cybersecurity, and log analysis; MS Office proficiency; Bachelor’s degree or equivalent.
8mo
Save
Mark Applied
Hide
Incident Response Analyst
Washington, District of Columbia, United States
$100k-$125k/yr HybridFull Time
Cyber Synergy Consulting Group
Cyber Synergy Consulting Group: Cybersecurity and management consulting firm serving government agencies and private-sector organizations.
2+ YOE2–5+ years in cybersecurity operations; hands-on IR tools (CrowdStrike, FireEye/Trellix, Splunk, NetWitness, Magnet AXIOM); knowledge of NIST/FISMA/OMB; Public Trust eligibility.
CrowdStrike Falcon (EDR), FireEye/Trellix, Splunk, NetWitness, Magnet AXIOM