Incident Response Analyst, Senior
Listed on 2025-12-19
-
IT/Tech
Cybersecurity, Information Security, Network Security, Security Manager
Job Number: R0227530
Incident Response Analyst, Senior
Key Role: Apply an understanding of monitoring, analyzing, detecting, and responding to cyber events and incidents in information systems and networks. Contribute to an integrated, dynamic cyber defense and leverage cybersecurity solutions to deliver cybersecurity operational services, including intrusion detection and prevention, situational awareness of network intrusions, security events and data spillage, and incident response actions. Contribute to the development of innovative principles and ideas, work on unusually complex problems, and provide solutions that are highly creative.
Handle major, high impact incidents, generate clear, concise recommendations, and coordinate activities and professional communications across a range of stakeholders. Work closely with security teams to develop, tune, automate, and enhance network and host-based security devices, support the SOC with managing the response to client Cyber intrusions, perform extensive network and host triage, maintain strict chain-of-custody, analyze documentation and reports, and perform remediation, as required.
Basic Qualifications:
- 6+ years of experience in cyber security or information technology disciplines
- 4+ years of experience with Advanced Persistent Threat (APT) hunting, penetration testing, digital forensics, malware reverse engineering, SOC operations, or incident response
- Experience with Incident Response tools such as Sentinel One, Splunk, or Microsoft Defender
- Ability to adapt communications styles and messaging for professionals at all levels of leadership
- An active OSCP, CCNA-Security, CySA+, GCIH, GICSP, Pen Test+, or a similar industry-recognized certification
- Secret clearance
- Bachelor's degree
Additional Qualifications:
- Ability to detect and search for MITRE ATT&CK TTPs and common attacker methodologies using PCAP data with tools such as Wireshark
- Ability to analyze Security Information and Event Management (SIEM) alerts to identify security issues for investigation and remediation
- Ability to profile and track malicious actors that pose a threat in coordination with threat intelligence support teams
- Ability to review and analyze security log files from various sources, including cloud, network, endpoint, or ICAM
- Ability to be self-driven, work independently, and handle multiple tasks concurrently
- TS/SCI clearance
Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Secret clearance is required.
Booz Allen celebrates your contributions, provides you with opportunities and choices, and supports your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care.
The projected compensation range for this position is $86,800.00 to $ (annualized USD).
Commitment to Non-Discrimination: All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).