Position DescriptionValiant Solutions is seeking a
Cyber Analyst (Tier 2) / Incident Commander to join our rapidly growing and innovative cybersecurity team!
As a
Cyber Analyst (Tier 2) / Incident Commander, you and your team will man a
24x7x365 cybersecurity operations and coordination center. You will manage escalated alerts, notifications, and communications while executing core incident response activities, including tracking the lifecycle of events, managing stakeholder communication, and driving remediation and recovery actions. Additionally, you will ensure all reports are accurately documented in the incident tracking system and coordinate directly with reporting entities to gain a full understanding of each event while strictly following established SOPs for the escalation and notification of
Federal Leadership.
The ideal candidate must possess deep knowledge of cybersecurity incidents, anomaly analysis, log analysis, digital forensics, and common threat vectors to effectively determine the required actions to resolve an incident. You must demonstrate a strong understanding of
Splunk SIEM,
Microsoft Defender EDR,
XSOAR, and support forensic tools to effectively analyze data and guide response activities. This role requires a blend of technical expertise and compliance-minded discipline to maintain operational readiness and meet stringent federal reporting procedures.
Must be able to obtain and maintain a Public Trust.
This position allows for 100% remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below. Required Certifications:- MUST HAVE one of the following ACTIVE certifications: CISSP, GCIH, Security X, CSAE, or CSIE.
Required Experience: - 7+ years of relevant work experience or a Bachelor's Degree with 2+ years of relevant experience
- US Citizenship and must be able to pass a background investigation (Public Trust - High Risk)
- Excellent organizational, verbal, presentation/facilitation, and written communication skills. Comfortable presenting briefings to the client.
- Demonstrate proficiency in the Incident Response Process and SOC operations, and a good understanding of threat hunting
- Good understanding of system log information and where to collect specific data/attributes as required for the Incident Event
- Operational understanding of enterprise networking and security tools (firewalls, Antivirus, HIDS, IDS/IPS, proxy, WAF), Windows and Unix/Linux systems' operations
- Experience performing log analysis and reporting
- Experience creating and tracking investigations to resolution
- Experience with Endpoint security solutions, including but not limited to: Windows Defender, Antivirus Solutions, and EDR Tools
- Understanding of compliance or regulatory frameworks (i.e., FISMA, NIST, ISO)
- Solid understanding of application, authentication, network security principles, and operating system hardening techniques
- General knowledge of cyber-attack frameworks (MITRE ATT&CK and Lockheed Cyber Kill Chain)
- Understanding of Computer Network Defense (CND) policies, procedures, and regulations
- SIEM monitoring and analysis, analyzing network traffic, log analysis, prioritizing and differentiating between potential intrusion attempts and false alarms
- Ability to work with or support senior leaders to understand risk factors and communicate effective mitigation strategies
- Ability to work independently to address and resolve a security incident with minimal supervision.
Responsibilities: - Supports/develops reports during and after incidents, which include all actions taken to properly mitigate, recover and return operations to normal operations.
- Lead and actively participate in security-related meetings and discussions with the client.
- Perform incident response analysis based on investigation requirements.
- Participate in the remediation of incidents and responses that are generated from live threats against the enterprise.
- Record and report all incidents per Federal and department policy.
- Create and track network incidents and investigations through closure.
- Serve as key personnel for Incident Management; provide coordination, task assignment, and process guidance for incident response events.
- Monitor and investigate security events received through the SIEM or other security tools.
- Carry out Level 2 triage of incoming Incidents (initial IR assessment of the priority of the event, initial determination of incident nature to determine risk and damage, or appropriate routing of security or privacy data request).
- Work directly with the Tier 3 Incident Commander and manage assigned investigations to ensure they are being actively worked on and assist Tier 1 and Tier 2 analysts as needed to resolve investigations.
- Review, revise, and recommend technical, process, and physical controls.
- Develop and implement defensive cyber best practice tactics, techniques, and procedures.
Benefits Snapshot (includes, but not limited to)Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University - Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses
The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the $115,000 - $130,000 range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.
Remote Work PolicyRemote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.