Cybersecurity Incident Response & Threat Detection Analyst

AGE Solutions

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity incident response and threat detection.
  • 2+ years of experience in performing root cause analysis for cybersecurity events.
  • Current DoD Top Secret Clearance with SCI eligibility.
  • At least one IAT-II certification (e.g., CCNA Security, CompTIA Security+).
  • At least one CSSP Incident Responder certification (e.g., CEH, GCIH).
  • Working knowledge of multiple security tools and defenses.
  • Proficiency in scripting using SPL, Python, or PowerShell.

Responsibilities

  • Monitor SIEM and cybersecurity tools 24x7 for threat detection.
  • Protect, detect, and respond to unauthorized activities.
  • Deploy capabilities to respond to alerts and emerging threats.
  • Analyze logged events for attack trends and indicators.
  • Monitor for Advanced Persistent Threats and low-and-slow attacks.
  • Stay updated on threats using intelligence resources like OSINT.
  • Conduct root cause analyses on cybersecurity incidents.

Benefits

  • Full-time role on-site at customer's location in Columbus, OH.
  • Opportunity to work within a critical cybersecurity environment.
  • Engagement in continuous learning and threat detection improvement.
  • Access to cutting-edge cybersecurity tools and technologies.
Full Job Description
AGE Solutions is seeking an experienced Cybersecurity Incident Response & Threat Detection Analyst to support continuous monitoring, detection, analysis, and response to cybersecurity threats within the Enterprise Network Environment.

This position participates in 24x7x365 monitoring of SIEM and other cybersecurity monitoring tools, investigates events and activity indicative of attack or compromise, and actively monitors for Advanced Persistent Threats (APTs) and "low and slow" attacks.

The analyst leverages intelligence resources, including Open Source Intelligence (OSINT), provides technical analysis and sustainment support for cybersecurity tools and applications, and assists with Defense-in-Depth signatures and perimeter defense controls.

Responsibilities Include:
  • Participate in 24x7x365 monitoring of SIEM and other cybersecurity monitoring tools to detect and respond to cybersecurity threats within the Enterprise Network Environment.
  • Perform actions to protect, monitor, detect, analyze, and respond to unauthorized activity.
  • Employ cybersecurity capabilities and deliberate actions to respond to specific alerts and emerging threats.
  • Review logged events and identify trends indicative of attack or compromise within the environment.
  • Actively monitor logs and network traffic for Advanced Persistent Threats (APTs) and "low and slow" attacks.
  • Maintain awareness of potential threats through intelligence resources, including Open Source Intelligence (OSINT).
  • Perform root cause analysis of cybersecurity events and incidents.
  • Provide technical analysis and sustainment support for enterprise cybersecurity tools and applications.
  • Assist with the application of Defense-in-Depth signatures and perimeter defense controls to diminish network threats.
  • Utilize security tools in support of cybersecurity monitoring, detection, analysis, and incident response activities.
  • Develop scripts and tools to enhance threat detection and incident response capabilities using SPL, Python, or PowerShell.
  • Independently evaluate incident severity, business impact, and alternative containment and remediation approaches; recommend response priorities to customer cybersecurity leadership.
  • Use root cause findings to recommend changes to customer incident-response practices and security controls, evaluating security benefits and operational tradeoffs.

Required Skills, Qualifications, and Experience:
  • Experience:
    • Five (5) years of relevant experience.
    • Two (2) years of experience performing root cause analysis of cybersecurity events and incidents.
  • Clearance:
    • Must possess a current DoD Top Secret Clearance with IT-I, T5 investigation with eligibility for Sensitive Compartmented Information (SCI) access.
  • Certifications:
    • Must have at least ONE IAT-II Certification from one of the following:
      • Cisco Certified Network Associate Security (CCNA Security)
      • CompTIA Cybersecurity Analyst (CySA+)
      • Global Industrial Cyber Security Professional (GICSP)
      • GIAC Security Essentials (GSEC)
      • CompTIA Security+ Continuing Education (Security+ CE)
      • Systems Security Certified Practitioner (SSCP)
    • Must have at least one of the following CSSP Incident Responder certifications:
      • Certified Ethical Hacker (CEH)
      • CyberSec First Responder (CFR)
      • CompTIA Cybersecurity Analyst (CySA+)
      • GIAC Certified Forensic Analyst (GCFA)
      • GIAC Certified Incident Handler (GCIH)
      • Cisco Cybersecurity Specialist (SCYBER)
  • Skills and Qualifications:
    • Working knowledge of at least two types of security tools: Firewall, IDS/IPS, Host-Based Antivirus, Data Loss Prevention, Vulnerability Management, Forensics, Malware Analysis, or Device Hardening.
    • Understanding of Defense-in-Depth.
    • Ability to build scripts and tools to enhance threat detection and incident response capabilities, preferably using SPL, Python, or PowerShell.
  • Location:
    • This role is full-time onsite at our customer's location in Columbus, OH.

Work Environment and Physical Demand:
  • Work is primarily performed in a professional office or technical environment.
  • Requires participation in 24x7x365 cybersecurity monitoring operations.
  • Requires prolonged periods of sitting and working at a computer workstation.
  • Requires frequent use of computers, keyboards, monitors, and standard office equipment.
  • Requires the ability to maintain concentration and attention to detail while continuously reviewing cybersecurity logs, network traffic, events, and alerts.
  • Requires the ability to communicate effectively with team members and stakeholders.
  • May require occasional standing, walking, bending, and reaching during the normal course of work.

The projected salary range for this position is $110,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.

Similar Jobs

More Jobs at AGE Solutions

More Information Technology Jobs

Find similar Cybersecurity Incident Response & Threat Detection Analyst jobs: