CSOC Tier 3 Analyst III

RISA

• $87K — $95K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active U.S. TS/SCI security clearance required.
  • Ability to obtain and maintain a Government polygraph after hire.
  • Bachelor's degree with 6 years of experience, or equivalent education/experience.
  • Must obtain IAT Level II and CSSP Incident Responder certifications within 6 months of start.
  • Experience with hands-on incident response and malware analysis.
  • Strong skills in documentation and ticketing systems.

Responsibilities

  • Implement containment strategies during cyber incidents as directed by the Government.
  • Conduct digital media analysis across various data types, including volatile and non-volatile memory.
  • Perform malware reverse engineering and create indicators of compromise.
  • Categorize cyber incidents and develop timelines to brief stakeholders.
  • Collaborate with various partners on advanced investigations and triage efforts.
  • Develop scripts and tools for data collection and analysis when authorized.
  • Compose thorough incident investigation reports with recommendations for future security measures.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) and Roth retirement plans.
  • Paid Time Off.
  • 11 paid Federal Holidays.
Full Job Description
Incident Responder / Malware Analyst (CSOC Tier 3)

Cyber Security Operations Specialist III - CSOC Tier 3

Location: Springfield, VA - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Schedule: Supports a 24x7x365 incident response operation

Travel: None

Salary Range: $87,000 - $95,000

When an incident happens, you are the one who contains it.

RISA is hiring a CSOC Tier 3 analyst for the incident response team defending an Intelligence Community customer's enterprise. This is the top of the escalation chain: containment, eradication, and recovery, plus malware and implant analysis and forensic artifact work. When a Cyber Incident Response Team stands up, you work under the Government CIRT Commander; between incidents, you run the exercises that make the next response better. You will talk to the owner here, not a recruiting queue.

What You Will Do
  • Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
  • Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
  • Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
  • Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
  • Develop and, when authorized, run custom scripts and tools to collect and analyze data.
  • Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
  • Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.

What You'll Bring
  • S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.
  • Hands-on incident response: containment, eradication, and recovery.
  • Host, network, and memory forensics, and malware analysis.
  • Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.

Nice to Have
  • Master's degree.
  • IAT Level III already in hand.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

Similar Jobs

More Jobs at RISA

More Information Technology Jobs

Find similar CSOC Tier 3 Analyst III jobs: