Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst
Listed on 2026-08-15
-
IT/Tech
Cybersecurity
Responsibilities & Qualifications
RESPONSIBILITIES
- Collect and analyze network and/or host artifacts from a variety of sources to include logs, system images and packet captures to characterize activity, determine root cause, operational impact, and to enable rapid remediation and/or mitigation of cyber threats within the Enterprise Network through the investigation process.
- Perform cyber incident triage; to include determining scope, urgency, and potential impact; identifying the specific vulnerability; and making recommendations that enable expeditious remediation.
- Must have working knowledge of the DoDI 8530.01 (Cybersecurity Activities Support to DoD Information Network Operations).
- Must be proficient with Splunk SIEM or similar tools.
- Provide expert technical support and perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support subordinate organizations and system owners.
- Manage and document cyber defense incidents from initial detection through final resolution methods.
- Provide technical guidance to Tier I analysts and QA alert closures for the shift.
- Maintain an average of at least two new detection use cases per month during each year of contract execution. Detection use cases shall be based on current threats, the MITRE ATT&CK framework, or Government direction.
- Maintain metadata for all detection use cases to include use case, owner, number of false positives identified, number of true positives identified, and average time to execute (based on incident detection monitoring analyst feedback).
- Analyze all completed incident records and make improvements to related detection use cases.
- Make recommendations to correlation rules, filters, signatures, or plays to enhance overall effectiveness by lowering false/benign-positive rates. Track and validate refinement requests and provide metrics for these activities monthly.
- Assist with developing methods for automating the execution of incident detection use cases that result in false-positive rates below 10%. Provide monthly reports on new automation actions and their results.
- At the direction and under the supervision of Government personnel, validate the effectiveness of any plays created by emulating adversary tactics to trigger the necessary alerts (blue team).
- Demonstrate effectiveness by creating detection use cases that successfully detect Red Team (penetration testing) activity.
- Utilize the MITRE ATT&CK matrix and other threat frameworks to develop detection use cases. Continually refine these processes with the goal of automating their execution.
- Provide subject matter expertise in creation, editing, and management of signatures, rules and filters for specialized network defense systems including but not limited to network and ESS IDS, IPS, firewall, web application firewall, proxy and SIEM systems.
- Perform duties as the alternate of the D&R technical lead when needed and effectively disseminate taskings among the team under the guidance of the technical lead.
REQUIRED QUALIFICATIONS
- Minimum of a Top-Secret Clearance with SCI eligibility
- DOD 8570 IAT II and CSSP Analyst Certifications (DoD 8140)
- BS 5-7 Years, MS 3-5, PhD 0-2
- Experience with cyber security architecture principles that achieve cybersecurity framework goals
We are seeking a Cyber Security Operations Incident Responder/Swing
- Shift Lead Analyst to support our Prime Contract with the Defense Threat Reduction Agency at Fort Belvoir. This position requires an active Top-Secret Clearance and a DOD IAT level II and CSSP Analyst Support certification is required.
We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.
Additional Job InformationWORK ENVIRONMENT AND PHYSICAL DEMANDS
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- Location:
Fort Belvoir, VA - Type of environment:
Office - Noise level:
Low - Work schedule:
Swing Shift: Thursday - Sunday. May be requested to work evenings and weekends to meet program and contract needs. - Amount of Travel: 10%
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).