Tier 2 Incident Response Analyst
Posted 2 months ago Expired
This job has expired
Looking for a job like Tier 2 Incident Response Analyst in or near Washington, DC? Upload your resume and we'll notify you when similar positions become available.
Upload Your ResumeAbout This Role
Serve as a Tier 2 Incident Response Analyst, monitoring security tools, triaging alerts, and investigating potential cyber threats for customers. You will be the initial point of contact for cybersecurity incidents, ensuring prompt and effective responses.
Responsibilities
- Utilize security tools to analyze, investigate, and triage security alerts
- Monitor customer environments, including cloud and SaaS solutions for evidence of adversarial activity
- Perform in-depth analysis and investigation of high-priority cybersecurity incidents
- Utilize advanced tools, such as host based digital forensics or malware analysis capabilities, to identify incidents' root causes, scope, and impact
- Collaborate with cyber threat hunting and cyber threat intelligence teams
- Participate in the development, implementation, and tuning of the SOC tools detection content and alerting signatures
- Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System (IMS)
- Perform research into emerging threats and vulnerabilities to aid their prevention and mitigation
- Provide guidance and mentorship to Tier 1 SOC Analysts to enhance their skills and capabilities
Requirements
- Minimum of four (4) years of cybersecurity experience with at least three (3) years in a SOC watch floor analyst or IR role
- SIEM experience (Sumo Logic/Splunk preferred)
- Knowledge of common attacker tools, techniques and procedures (TTP)
- Experience with major cloud service provider offerings
- Knowledge of malware
- Knowledge of enterprise architecture including zero trust principles
- Knowledge of Windows and Unix operating systems
- Knowledge of common phishing techniques and how to investigate them
- Proficiency in technical writing
- Ability to maintain a positive customer service mentality
Qualifications
- Bachelor's Degree or higher in Cybersecurity or related is preferred
- Minimum of four (4) years of cybersecurity experience with at least three (3) years in a SOC watch floor analyst or IR role
Nice to Have
- Previous SOC or incident response experience
- Working knowledge of regex and scripting languages
- SOC analyst relevant certifications such as those from GIAC or CompTIA
Skills
* Required skills
Benefits
Certifications
About Tyto Athene, LLC
Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success across four core technology domains: Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT.