Incident Response & Threat Detection Analyst

ESM

• $80K — $95K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of relevant cybersecurity experience
  • 2+ years in root cause analysis of cybersecurity incidents
  • Knowledge of SIEM and cybersecurity monitoring tools
  • Familiarity with at least two security tools (e.g., Firewall, IDS/IPS)
  • Ability to script in SPL, Python, or PowerShell
  • Must maintain CSSP Analyst certification (CEH, CFR, GCIA, GCISP)

Responsibilities

  • Monitor SIEM and cybersecurity tools 24/7 to detect threats
  • Analyze security events and network traffic for indicators of compromise
  • Utilize threat intelligence to inform defensive actions
  • Provide technical support for cybersecurity tools and applications
  • Implement defense-in-depth signatures and perimeter controls

Benefits

  • Opportunity to work in a federal environment
  • Engagement in a critical enterprise-level cybersecurity program
  • Access to advanced cybersecurity tools and technologies
  • Collaborative team environment with government customers
  • Potential for professional development and certification maintenance
Full Job Description
We are hiring a Cybersecurity Incident Response & Threat Detection Analyst to support an enterprise-level program within a federal environment.

Job Description and Responsibilities

Participates in 24x7x365 monitoring of SIEM and cybersecurity tools to detect, analyze, and respond to threats and unauthorized activity across the enterprise network. Reviews security events, logs, and network traffic to identify trends, advanced persistent threats (APTs), and other indicators of compromise. Uses threat intelligence and open-source intelligence (OSINT) to maintain awareness of emerging threats and inform defensive actions. Provides technical analysis and sustainment support for cybersecurity tools and applications and assists with implementing defense-in-depth signatures and perimeter controls to mitigate network threats.

Required Knowledge, Skills and Abilities (KSA)
  • Knowledge of SIEM, cybersecurity monitoring tools, network traffic, and security event analysis.
  • Ability to detect, analyze, and respond to cyber threats, including APTs, indicators of compromise, and unauthorized activity.
  • Ability to apply threat intelligence, cybersecurity tools, and defense-in-depth controls to identify and mitigate network threats.
  • Knowledge of at least two types of security tools: Firewall, IDS/IPS, Host based antivirus, Data loss prevention, Vulnerability Management, Forensics, Malware Analysis, Device Hardening.
  • Ability to build scripts and tools to enhance threat detection and incident response capabilities
  • (Preferably in SPL, Python, PowerShell)


Desired KSA
  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
  • Candidate must communicate effectively with team members, team lead, management, and government customers
  • Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision


Minimum Training, Education, and Certifications
  • Five (5) years relevant experience
  • Two (2) years performing root cause analysis of cybersecurity events and incidents.
  • Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP)


Minimum Clearance
  • Top Secret


Physical Requirements
  • Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Regularly required to stoop, kneel, bend, crouch and lift up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
  • Physical demands associated with this position include extensive walking (including stairs) throughout offices and between buildings. May require use of public transportation, personal or Government vehicle to drive to local and/or remote office locations.


Additional Requirements
  • Other duties as assigned


Similar Jobs

More Jobs at ESM

More Information Technology Jobs

Find similar Incident Response & Threat Detection Analyst jobs: