Job Title: Mid-Level Cybersecurity Incident Response Analyst
Location: Bethesda, Maryland
Type: Direct Hire
Compensation: 120k
Work Model: Hybrid
Hours: 40.0
Security Clearance: Public Trust
Responsibilities - Monitor, analyze, and investigate security alerts generated by SIEM, EDR, IDS/IPS, cloud security platforms, and other enterprise security tools.
- Perform incident detection, triage, analysis, documentation, containment, recovery, and escalation activities.
- Conduct incident investigations and determine scope, impact, and recommended response actions.
- Analyze security logs, endpoint artifacts, network traffic, and system data to identify malicious activity.
- Support continuous monitoring of enterprise networks, endpoints, cloud environments, and security infrastructure.
- Perform proactive threat hunting and identify, collect, and document Indicators of Compromise (IOCs).
- Support Cyber Threat Intelligence (CTI) activities through research, correlation, and dissemination.
- Assist senior personnel with digital forensic evidence collection, malware analysis, and forensic investigations.
- Maintain incident documentation and contribute to operational metrics and reporting.
- Participate in tabletop exercises and continuous process improvement initiatives.
- Provide technical guidance and day-to-day support to junior analysts.
**Requirements**
- Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field. Four additional years of relevant experience may substitute for a bachelor's degree.
- Experience: 3-5 years supporting cybersecurity operations, SOCs, incident response, or information security programs with experience in incident investigations, security monitoring, log analysis, and threat detection.
- Preferred Qualifications: Experience with SIEM, EDR, IDS/IPS, SOAR, and cloud security technologies.
- Knowledge of digital forensics, malware analysis, cyber threat intelligence, and threat hunting.
- Familiarity with MITRE ATT&CK and NIST SP 800-61/SP 800-86.
- Experience supporting federal cybersecurity programs.
- Desired Certifications: CompTIA CySA+, CompTIA Security+, GIAC GCIH, GIAC GSEC, ISC2 Certified in Cybersecurity (CC), Microsoft SC-200, or equivalent.
- Strong analytical and investigative skills.
- Working knowledge of incident response methodologies and security operations.
- Strong written and verbal communication skills.
- Ability to prioritize multiple tasks in a fast-paced environment.
- Ability to mentor junior analysts and collaborate across technical teams.
- Commitment to continuous professional development.
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-2
#LI-CK1
Ref: #856-Baltimore-S1