Cybersecurity Incident and Application Analyst

* This position is contingent upon a future opening with Gunnison.


Salary: $130,000 - $145,000/year


Work location: Hybrid, 2-3 days per week on-site in Bethesda, MD.

  • Support cybersecurity incident detection, analysis, response, containment, recovery, and post-incident activities across NIH CIT enterprise network, web application, endpoint, server, and cloud environments.
  • Monitor, investigate, validate, and triage security events, alerts, suspicious activity, and potential indicators of compromise; assign appropriate severity and criticality based on operational impact, threat context, and established escalation procedures.
  • Apply the enterprise incident-response lifecycle: preparation; detection and analysis; containment, eradication, and recovery; and post-incident analysis.
  • Analyze network traffic, system logs, endpoint telemetry, application activity, authentication events, and security-tool alerts to identify malicious, anomalous, or unauthorized activity.
  • Evaluate network, web application, cloud, and endpoint environments for insecure configurations, vulnerable ports, unnecessary services, weak protocols, default credentials, insecure communication methods, and other security weaknesses.
  • Perform cybersecurity incident analysis using tools and platforms such as FireEye or comparable endpoint/threat-detection technologies, Palo Alto IDS/IPS and firewall technologies, Splunk SIEM, Tenable vulnerability-management tools, and related security operations tools.
  • Support investigation of web application and cloud security events, including suspicious access, misconfigurations, exposed services, anomalous traffic, unauthorized changes, and potential data-security risks.
  • Maintain a working knowledge of common ports, protocols, network services, attack vectors, and security-control configurations relevant to incident investigation and response.
  • Conduct or support incident containment and recovery activities in coordination with system owners, network engineers, cybersecurity engineers, application teams, and Government stakeholders.
  • Create, update, and follow incident response playbooks, standard operating procedures, RACI charts, escalation matrices, and communication plans.
  • Document incident timelines, investigative steps, evidence, findings, impact analysis, containment actions, recovery actions, and recommended corrective measures.
  • Lead or support post-incident reviews and lessons-learned activities; assess the effectiveness of the Incident Response Plan (IRP), playbooks, and procedures, and recommend improvements.
  • Assist with annual incident-response exercises, tabletop exercises, and technical tests; document test results, gaps, corrective actions, and updates to incident-response documentation.
  • Produce accurate, timely incident reports, status updates, dashboards, executive summaries, and management briefings appropriate for technical and nontechnical stakeholders.
  • Maintain familiarity with NIST SP 800-61 incident-handling guidance and apply it to daily incident-response operations.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available