Cybersecurity Incident and Application Analyst
Job in
Bethesda, Montgomery County, Maryland, 20811, USA
Listed on 2026-08-23
Listing for:
Gunnison Consulting Group
Part Time
position Listed on 2026-08-23
Job specializations:
-
IT/Tech
Cybersecurity, Network Security, Security Management & Operations
Job Description & How to Apply Below
Description
* This position is contingent upon a future opening with Gunnison.
Salary: $130,000 - $145,000/year
Work location
:
Hybrid, 2-3 days per week on-site in Bethesda, MD.
- Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments.
- Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures.
- Apply the enterprise incident-response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post-incident analysis.
- Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security-tool alerts to identify malicious, anomalous, or unauthorized activity.
- Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses.
- Perform cybersecurity incident analysis using tools and platforms such as Fire Eye or comparable endpoint/threat-detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability-management tools, and related security operations tools.
- Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data-security risks.
- Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security-control configurations relevant to incident investigation and response.
- Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders.
- Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans.
- Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures.
- Lead or support post-incident reviews and lessons-learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements.
- Assist with annual incident-response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident-response documentation.
- Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders.
- Maintain familiarity with NIST SP 800-61 incident-handling guidance and apply it to daily incident-response operations.
Minimum of two (2) to five (5) years of progressively responsible experience in cybersecurity incident response, security operations, network security, application security, cloud security, threat detection, or a related discipline.
Candidates should demonstrate experience in:
- Security-event monitoring, alert triage, incident investigation, incident documentation, escalation, and response coordination.
- Enterprise incident-response processes, including preparation, detection and analysis, containment, eradication, recovery, and post-incident activities.
- Network security, web application security, cloud technologies, endpoint security, and security monitoring.
- Identifying vulnerable services, insecure ports and protocols, default or weak configurations, and common network/application security weaknesses.
- SIEM analysis, preferably Splunk, including log searches, dashboards, correlation, alert analysis, and report generation.
- IDS/IPS, firewalls, endpoint detection and response, vulnerability-management, and threat-detection technologies, including Palo Alto, Fire Eye or comparable platforms, and Tenable.
- Windows and Linux operating systems, including basic system/log analysis and security troubleshooting.
- NIST SP 800-61 and the creation or use of incident-response playbooks, RACI charts, escalation procedures, SOPs, and lessons-learned documentation.
- Preparing technical findings, incident reports, management updates, and executive-level summaries.
- Bachelor’s degree from an accredited college or university in cybersecurity, information assurance, computer science, information systems, computer engineering, network engineering, digital forensics, systems engineering, or a closely related technical discipline.
- EC-Council Certified Incident Handler (E|CIH), current and active
- Offensive Security Certified Professional (OSCP), current and active
- GIAC Certified Incident Handler (GCIH), current and active
- Current Splunk certification, such as…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×