82 incident response analyst jobs at 51 companies in Timonium, MD
3w
Save
Mark Applied
Hide
3w
Incident Response Analyst
Alexandria or Seaside or McLean
$94k-$127k/yrOnsiteFull Time
VMD Corp: Provides airport security screening and federal IT services.
5+ YOEBachelor’s degree, five years of experience, U.S. citizenship, and active Secret clearance required. Supports cybersecurity incident response across classified and unclassified environments.
Security Information and Event Management (SIEM), IDS/IPS, SIPRNet, NIPR
AmentumNYSE: AMTM: Global provider of engineering, technical, and mission-critical services.
3+ YOERequires 3–8+ years supporting SOC or incident response teams, experience with SIEM, EDR, threat hunting, malware analysis, and digital forensics, plus active TS/SCI or DOE Q clearance.
AmentumNYSE: AMTM: Provides engineering, technology, and mission support to government agencies.
3+ YOE3+ years SOC/incident response experience; familiarity with SIEM, EDR, threat hunting, malware analysis, digital forensics; knowledge of MITRE ATT&CK and NIST CSF; active TS/SCI or DOE Q clearance required.
Tetrad Digital Integrity: Provides cybersecurity performance management software and specialized consulting services.
12+ YOEAbility to obtain Public Trust; required bachelor's degree and 12+ years experience; hands-on incident detection/response, malware analysis or forensics; expertise with Windows/Linux, networking, SIEM/EDR/IDS/IPS; scripting (Python, PowerShell, Bash).
cFocus Software: Provides cybersecurity compliance and enterprise IT services for government.
3+ YOEPublic Trust clearance, BS in CS/IT or related, 3+ years IR experience, 2+ years Python and PowerShell, experience with live triage, log correlation, Velociraptor, Splunk ES, Sentinel, and familiarity with NIST incident handling.
ManTech International: Advancing the future of defense through innovative technology.
3+ YOERequires high school diploma and 7+ years of cybersecurity experience or bachelor's degree and 3+ years, including 2+ years in incident response; active TS/SCI with polygraph required.
Cayuse Holdings: Tribally-owned provider of IT and professional services.
0+ YOERequires 0–2 years related experience, customer or service desk experience, U.S. citizenship, Top Secret/SCI clearance, Security+, ITIL, Microsoft Office, and ServiceNow, Remedy, and Amazon Connect proficiency.
Amazon Connect, ServiceNow, Remedy, Microsoft Word, Microsoft Excel, Microsoft PowerPoint
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to US federal agencies.
1+ YOERequires U.S. citizenship, 1–2 years of information security experience, event and log analysis, SIEM experience, security tools knowledge, network protocols, malware analysis, endpoint analysis, and strong communication skills.
SIEM, Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools, Security Information and Event Management (SIEM), Excel, grep, sed, awk, regex, TCP/IP, Windows, Linux
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
1+ YOEUS citizenship and 1–2 years of information security experience required, including event and log analysis with SIEM. Requires cybersecurity, network, malware, endpoint, communication, and data analysis knowledge.
SIEM, Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools, Excel, grep, sed, awk, regex, TCP/IP, Windows, Linux
ECS FederalEFOR: Federal segment of Everforth delivering technology and engineering solutions.
10+ YOEUS citizen with Top Secret clearance and 10+ years in threat intelligence, incident response, or cybersecurity; expert threat analysis, SOP development, and technical writing; proficiency with Confluence and SharePoint.
Confluence, SharePoint, MITRE ATT&CK, Linux, Windows
(Cyber) Incident Management Analyst - Weekend Night Shift
Arlington, Virginia, United States
OnsiteFull Time
Nightwing: Provides advanced cyber and intelligence solutions for national security.
5+ YOE5+ years in cyber incident management or cybersecurity operations; active TS/SCI; U.S. citizenship; DHS suitability; knowledge of NIST 800-62 and FISMA; incident response expertise.
Gunnison Consulting Group: Provides technology solutions and IT consulting to federal agencies.
2+ YOERequires 2–5 years in cybersecurity incident response or related security disciplines, a relevant bachelor's degree, active E|CIH, OSCP, GCIH, and Splunk certification, plus ability to obtain Public Trust clearance.
FireEye, Palo Alto, Splunk, Tenable, Windows, Linux, NIST SP 800-61, Microsoft Defender, CrowdStrike, SentinelOne, AWS, Microsoft Azure, Google Cloud, Cisco
Gormat: Private cybersecurity and engineering consulting firm serving U.S. Department of Defense, Intelligence Community, federal, and industry clients.
6+ YOE6+ years IT/InfoSec experience, incident response and threat analysis experience, active Secret clearance (eligible for Top Secret), ability to pass DEA background check, and DoD 8140 certification within 6 months.
Digital Global Connectors: Woman-owned cybersecurity services firm providing engineering, assessment, consulting, training, and operations services to federal and private-sector clients.
4+ YOEBachelor's degree and 4+ years incident response experience; US citizenship and ability to obtain Tier 2 Public Trust; expertise with SIEM/EDR/XDR, digital forensics, malware analysis, and incident documentation.
Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, CrowdStrike Falcon, Palo Alto Cortex XDR, Trellix, Cisco Secure, Wireshark, Velociraptor, SIEM, EDR, XDR, Microsoft Office Suite, ServiceNow, Jira
Senior IT Specialist (Cyber Incident Response Analyst) II
Washington, District of Columbia, United States
$122k-$187k/yrHybridFull Time
Supreme Court of the United States: The highest federal court in the United States.
5+ YOETechnology-related degree plus 5 years of IT and cybersecurity experience, or 7 years of demonstrated experience; 3 years incident response and TS clearance required. Cybersecurity certifications are preferred.
KBRNYSE: KBR: Provides engineering, technology, and professional services for global markets.
8+ YOEActive Top Secret/SCI clearance, 8 years incident response experience, DoD 8570 IAT II and CSSP-Analyst certifications, ability to lead investigations and mentor junior analysts.
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Baltimore, Maryland, United States
OnsiteFull Time
OneMain FinancialNYSE: OMF: Provides personal loans and credit cards to nonprime consumers.
8+ YOE8+ years cybersecurity experience with 6+ years SOC experience; bachelor\u0002s degree or equivalent; 2+ DFIR/forensics years; requires multiple certifications (e.g., GCFA, GCIH, CISSP); deep expertise in enterprise incident response, detection engineering, and threat hunting.
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, Bash, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps, Elastic, EDR/XDR, NDR, SIEM, SOAR, IDS/IPS, WAF, firewalls, VPN, DNS, DHCP, proxy, CASB, DLP, IAM, PAM, Kubernetes, Azure, AWS, Microsoft 365, Microsoft Entra ID, VMware, Hyper-V
Peraton: Provides advanced technology and mission support for government agencies.
5+ YOEActive Top Secret clearance with SCI eligibility, 5 years of experience, DoD 8570 IAT II and CSSP-Analyst certifications, incident response, network security, traffic analysis, and strong communication skills.
Peraton: National security and mission-critical government technology services provider.
5+ YOERequires active Top Secret clearance with SCI eligibility, DoD 8570 IAT II and CSSP-Analyst certifications, and 5 years of incident response experience; BS/BA required unless replaced by 4 years relevant experience.