Jobs and Careers
CF
Cyber Incident Response Analyst (Senior) - Public Trust
cFocus Software IncorporatedWashington, United Statesfull_timeVerifiedPosted 13 Sept 2024
About the role
cFocus Software seeks a Cyber Incident Response Analyst (Senior) to join our program supporting United States Courts, Information Technology Security Office in Washington, DC. This position requires US Citizenship and the ability to obtain a Public Trust clearance.
Qualifications:
Qualifications:
- Bachelor’s Degree or equivalent experience in a computer, engineering, or science field.
- Abilty to obtain a Public Trust clearance.
- US Citizenship
- Hold active certifications such as GCIA or GCIH or GSEC or GMON, and Splunk Core Power User.
- 7+ years of relevant experience.
- Lead one or more functional security teams.
- Support the development of staff schedules and staffing forecasts for approval.
- Ensure shift members follow the appropriate incident escalation and reporting procedures.
- Provide support promptly and efficiently through front-line telephone and email communications.
- Assist with knowledge management – Standard Operating Procedures and procedural support data.
- Accept and respond to government technical requests through the AOUSC ITSM ticket (e.g., HEAT or ServiceNow) for advanced subject matter expert (SME) technical investigative support for real-time incident response (IR).
- IR includes cloud-based and non-cloud-based applications such as: Microsoft Azure, Microsoft O365, Microsoft Active Directory, and Cloud Access Security Brokers (e.g., Zscaler).
- Create duplicates of evidence that ensure the original evidence is not unintentionally modified. AOUSC supplied procedures and tools shall be used to acquire the evidence.
- Analyze forensic artifacts of operating systems (e.g., Windows, Linux, and macOS) to discover elements of an intrusion and identify root cause.
- Perform live forensic analysis based on SIEM data (e.g., Splunk).
- Perform filesystem timeline analysis for inclusion in forensic report.
- Extract deleted data using data carving techniques.
- Collect and analyze data from compromised systems using EDR agents and custom scripts provided by the AOUSC.
- Perform static and dynamic malware analysis to discover indicators of compromise (IOC).
- Analyze memory images to identify malicious patterns using Judiciary tools (e.g. Volatility). Analysis results documented in forensics report.
- Write forensic and malware analysis reports.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s