Jobs and Careers
CR
T2 Deputy IR Lead
Critical SolutionsUnited Statesfull_timeVerifiedPosted 2 Apr 2025
💰 $136,000/yr($106,000/yr – $136,000/yr)
About the role
T2 Deputy IR Lead
Location: Ashburn, VA
Clearance: Must be a US citizen and must be willing and be able to favorably pass a (BI) Background Investigation
Full-time, On-site
JOB DESCRIPTION
Critical Solutions has an immediate opening for a Tier 2 Incident Response Lead to support our federal customer in Ashburn, VA.
PRIMARY ROLES AND RESPONSIBILITIES:
- Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to examine endpoint and network-based data.
- Conduct malware analysis, host and network, forensics, log analysis, and triage in support of incident response.
- Recognize attacker and APT activity, tactics, and procedures as indicators of compromise (IOCs) that can be used to improve monitoring, analysis and incident response.
- Develop and build security content, scripts, tools, or methods to enhance the incident investigation processes.
- Lead Incident Response activities and mentor junior SOC staff.
- Work with key stakeholders to implement remediation plans in response to incidents.
- Effectively investigative and identify root cause findings then communicate findings to stakeholders including technical staff, and leadership.
- Flexible and adaptable self-starter with strong relationship-building skills
- Strong problem solving abilities with an analytic and qualitative eye for reasoning
- Ability to independently prioritize and complete multiple tasks with little to no supervision
BASIC QUALIFICATIONS:
- Must be a US citizen, no clearance required, prefer Secret Clearance with the ability to obtain TS/SCI. In addition to specific security clearance requirements, selected candidate will be required to successfully complete a Background Investigation to support this program
- Bachelor's degree in Science or Engineering Field, IT, or Cybersecurity or related field
- 3+ years of experience be in the areas of incident detection and response, remediation malware analysis, or computer forensics.
- Prior relevant experience should be in the areas of incident detection and response, malware analysis, or computer forensics.
- Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
CERTIFICATION REQUIREMENT:
Must have one of the following certifications
- CCFP - Certified Cyber Forensics Professional
- CCNA Security
- CCNP Security
- CEH - Certified Ethical Hacker
- CHFI - Computer Hacking Forensic Investigator
- CISSP - Certified Information Systems Security
- CIRC
- ECES - EC-Council Certified Encryption Specialist
- ECIH - EC-Council Certified Incident Handler
- ECSA - EC-Council Certified Security Analyst
- ECSS - EC-Council Certified Security Specialist
- EnCE
- ENSA - EC-Council Network Security Administrator
- FIWE
- GCFA - Forensic Analyst
- GCFE - Forensic Examiner
- GCIH - Incident Handler
- GISF - Security Fundamentals
- GNFA - Network Forensic Analyst
- GREM - Reverse Engineering Malware
- GWEB - Web Application Defender
- GXPN - Exploit Researcher and Advanced Penetration Tester
- LPT - Licensed Penetration Tester
- OSCE (Certified Expert)
- OSCP (Certified Professional)
- OSEE (Exploitation Expert)
- OSWP (Wireless Professional)
- WFE-E-CI
- FTK-WFE-FTK
- CompTIA Cyber Security Analyst (CySA+)
- CompTIA Linux Network Professional (CLNP)
- CompTIA PenTest+
- GCTI - Cyber Threat Intelligence
- GOSI - Open Source Intelligence
- CTIA - Certified Threat Intelligence Analyst
- Splunk Core Certified Advanced Power User
- Splunk Core Certified
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s