Cyber Defense Incident Responder (Tier 2)

Sentar

$88K — $105K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance with SCI eligibility required (can start with Secret clearance)
  • DODD 8570 IAT Level II Certification
  • DODD 8570 CSSP Incident Responder Certification
  • Minimum 2 years of cybersecurity experience focused on incident response
  • Proficiency with tools like Tanium, Elastic/Kibana, and Microsoft Defender
  • Strong knowledge of DoD cybersecurity frameworks
  • Expertise in forensic analysis and threat hunting

Responsibilities

  • Investigate cyber incidents by analyzing logs and system artifacts to identify threats
  • Assess incident scope and urgency to recommend mitigation strategies
  • Manage incidents from detection to resolution while ensuring compliance with standards
  • Conduct real-time forensic analysis and system remediation tasks
  • Collaborate with law enforcement and counterintelligence on high-profile incidents
  • Update response tactics and deliver training sessions to enhance readiness
  • Work with Red Teams to improve incident response capabilities through testing

Benefits

  • Voluntary medical, dental, vision insurance with flexible spending options
  • Life, critical illness, accident, and long-term care insurance options
  • Group term life and short-term/long-term disability coverage
  • Generous 401(k) match for retirement savings
  • Competitive PTO that increases with tenure
  • Various leave programs including military duty, jury duty, and bereavement
  • Mental health awareness programs
  • Tuition reimbursement for further education
  • Professional development reimbursement opportunities
  • Employee recognition and award programs
Full Job Description
Role Description:

Sentar is seeking a dedicated Cyber Defense Incident Responder (Tier 2) to join our team and provide 24/7/365 cybersecurity monitoring and detection for the government enterprise network. In this role, you will be responsible for conducting in-depth cyber investigations and responding to incidents across the enterprise network. This critical position involves working with advanced tools, engaging with global stakeholders, and ensuring the network's security and operational integrity. This is a fast-paced and high-impact role in a mission-critical environment.

The selected applicant will perform a variety of activities including but not limited to:
  • Investigate Cyber Incidents: Perform in-depth analysis of network and host artifacts (e.g., logs, system images, packet captures) to identify root causes, operational impacts, and enable rapid remediation of threats.
  • Incident Triage: Assess the scope, urgency, and potential impact of incidents, identify vulnerabilities, and recommend effective mitigation strategies.
  • Incident Management: Manage incidents from detection to resolution, documenting actions and outcomes in compliance with DoD Cyber Incident Handling Program (CJCSM 6510.01B).
  • Forensics and Threat Analysis: Conduct real-time forensic collections, intrusion correlation, threat analysis, and direct system remediation tasks.
  • Collaboration: Work closely with subordinate organizations, law enforcement, and counterintelligence teams on high-profile incidents and insider threat investigations.
  • Documentation and Training: Update incident response tactics, techniques, and procedures annually, and deliver quarterly training sessions to enhance team readiness.
  • Red Team Interaction: Collaborate with Red Teams to validate and enhance incident response capabilities through realistic penetration testing exercises.
  • Quality Assurance: Maintain high standards in incident response, ensuring consistent quality and efficiency as assessed by government-defined metrics.


Qualifications:

Clearance Level:
  • Must obtain and maintain an active Top Secret security clearance with SCI eligibility.
  • Can begin this position with verification of adjudicated Secret clerance eligibility.

Certifications:
  • DODD 8570 IAT Level II Certification
  • DODD 8570 CSSP Incident Responder Certification

Experience:
  • At least 2+ years in cybersecurity, with hands-on experience in incident response or related roles.
  • Familiarity with tools such as Tanium, Elastic/Kibana, and Microsoft Defender for Endpoint.
  • Strong understanding of the DoD environment and cybersecurity frameworks.

Skills:
  • Expertise in forensic analysis, threat hunting, and vulnerability assessment.
  • Excellent problem-solving abilities and attention to detail.
  • Strong communication skills for interacting with technical teams, leadership, and external stakeholders.

Benefits at Sentar:

In addition to a great culture, Sentar not only fosters an inclusive work environment but also offers an extensive benefits package designed to cater to the well-being of its employees and their families.
  • Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, jury and military duty
  • Mental health awareness programs
  • Tuition reimbursement
  • Professional development reimbursement
  • Recognition and Awards programs

If you are not ready to apply for this position, submit your resume here to join our talent community . We'll keep you updated occasionally on new job opportunities.

Similar Jobs

More Jobs at Sentar

More Education, Government & Non-Profit Jobs

Find similar Cyber Defense Incident Responder (Tier 2) jobs: