Talent.com
Cyber Incident Response Analyst IV
Cyber Incident Response Analyst IVNightwing • Sterling, VA, US
serp_jobs.error_messages.no_longer_accepting
Cyber Incident Response Analyst IV

Cyber Incident Response Analyst IV

Nightwing • Sterling, VA, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers' most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets.

Nightwing provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide front line response for Nightwing and proactively hunt for malicious cyber activity as well as providing forensic analysis etc... We are seeking Cyber Network / Host / Cloud Forensics Analysts (NF / HF / CF) to support the Nightwing infrastructure, thus ensuring our ability to maintain critical support of all customer missions.

The Corporate Incident Response Team uses information collected from a variety of sources to identify network / host / cloud activity, and to analyze it for evidence of suspicious behavior. The Nightwing IR Team will work with and support the Nightwing SOC who performs monitoring and analysis to identify and report events that occur, or might occur, within the network, in order to protect information, information systems, and networks from threats. Additionally, the IR Team will also be an intermediary between the SOC and Nightwing IT Service Desk for all IR related activities that affect Nightwing; as well as working with the Nightwing Digital Forensic / IR, (DFIR) team for analysis support to include proper chain of custody of all data / evidence. The IR Team will facilitate process integration with All teams ensuring full IR visibility across Nightwing networks.

Responsibilities :

  • Conducting incident response for breaches, data exfiltration, hacking and malware investigations.
  • Correlating forensic findings to network events in support of developing an intrusion narrative
  • Performing forensic triage of an incident to include determining scope, urgency and potential impact
  • Tracking and documenting forensic analysis from initial participation through resolution
  • Conducting Insider threat investigations and Ransomware investigations
  • Performing Digital Forensics investigations on varied operating systems such as (but not limited to) Windows, Linux, UNIX, and Mac OSX.
  • Preserving evidence (collect, process, preserve, and store evidence to ensure proper chain of custody)
  • Log collection and disk imaging etc., Data Recovery, and eDiscovery
  • Collecting and documenting system state information (e.g. running processes, network connections) prior to imaging, as required
  • Assisting with the construction of signatures which can be implemented on cyber defense network tools in response to new or observed threats within the network environment or enclave

Required Skills :

  • Must be able to obtain a TS / SCI clearance
  • 8+ years of directly relevant experience in network / host forensic investigations
  • In depth knowledge of CND policies, procedures and regulations
  • In depth knowledge of TCP / IP protocols
  • In depth knowledge of standard protocols – ICMP, HTTP / S, DNS, SSH, SMTP, SMB, NFS, etc.
  • In depth knowledge and experience of Wifi networking
  • In depth knowledge and experience of network topologies - DMZ's, WAN's, etc.
  • Substantial knowledge of Splunk (or other SIEM's)
  • Understanding of MITRE Adversary Tactics, Techniques and Common Knowledge (ATT&CK)
  • Knowledge of defense-in-depth principles and general attack stages with respect to network security architecture
  • Ability to characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
  • Detailed Technical Report writing experience
  • Ability to identify and analyze anomalies in network traffic using metadata
  • Experience with reconstructing a malicious attack or activity based on network traffic
  • Experience examining network topologies to understand data flows through the network
  • Must be able to work collaboratively across physical locations
  • Desired Skills :

  • Substantial knowledge of network device integrity concepts and methodologies
  • Proficiency with network analysis software (e.g. Wireshark)
  • Proficiency with carving and extracting information from PCAP data
  • Proficiency with non-traditional network traffic (e.g. Command and Control)
  • Proficiency with preserving evidence integrity according to standard operating procedures or national standards
  • Proficiency with virtualized environments
  • Proficiency with one or more EDR Tools : CrowdStrike, SentinelOne, Microsoft MDE, or Trellix
  • Proficiency with one or more of the following tools : Host forensic software (EnCase, FTK, X-Ways, Sleuth Kit / Autopsy), SIFT, Volatility, KAPE
  • Experience with Web / client-based applications, and databases including Sybase, Oracle, MS SQL, and Postgres
  • Scripting experience with Python, Bash, PowerShell etc.
  • Understanding of SaaS, PaaS and IaaS in the Cloud environment
  • Required Education :

    BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma & 16+ years of network investigations experience.

    Desired Certifications : (One or More)

  • DoD 8140.01 IAT Level III, IASAE III, CSSP Analyst, CSSP Analyst / CSSP Incident Responder, CEH, GCIA, GCIH, GNFA, GREM, CISSP, GCFE, GCFA, GCLD, GCPS, GCPN, GWEB, GIRD, GSEC, Kubernetes Security Specialist, Microsoft 365 Certifications, Microsoft Azure Certifications, AWS Certifications, SANS Cloud Courses (SEC488, SEC541, SEC549, SEC588) and Network+, Security+
  • Dulles, VA

    Previously part of a leading Fortune 100 company and headquartered in Dulles, VA; Nightwing became independent in 2024 but continues to support the nation's most mission impactful initiatives.

    When we formed Nightwing, we brought a deep set of credentials and an unfaltering commitment to the mission. For over four decades, our team has been providing some of the world's most technically advanced full-spectrum cyber, data operations, systems integration and intelligence support services to the U.S. government on its most important missions.

    At Nightwing, we value collaboration and teamwork. You'll have the opportunity to work alongside talented individuals who are passionate about what they do. Together, we'll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.

    Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.

    At Nightwing, we value collaboration and teamwork. You'll have the opportunity to work alongside talented individuals who are passionate about what they do. Together, we'll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.

    Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.

    Nightwing is An Equal Opportunity / Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.

    Receive tips & info on cleared job search, security clearances and career development.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Incident Response Analyst • Sterling, VA, US

    Job_description.internal_linking.related_jobs
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management Concepts, Inc. • Quantico, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government'...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    Senior Cyber Intrusion Detection Analyst

    Senior Cyber Intrusion Detection Analyst

    Vets Hired • Washington, D.C., District of Columbia, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Cyber Defense Analyst 3

    Cyber Defense Analyst 3

    Inova Health System • Fairfax, VA, United States
    serp_jobs.job_card.full_time
    Inova Cybersecurity is looking for a dedicated Cyber Defense Analyst 3 to join the Team.This remote role will be full-time day shift working Monday - Friday. The Cyber Defense Analyst 3 serves as in...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_less • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Cyber Incident Response Analyst

    Cyber Incident Response Analyst

    Leidos Inc • Ashburn, VA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking a highly skilled.Cyber Incident Response Analyst.Security Operations Center (SOC) support, cyber analysis, and application development. This role supports the DHS SOC, which is res...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Solutions³ LLC • Arlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cybersecurity Vulnerability Analyst (Incident Manager III ) Description : Solutions³ LLC is supporting our prime contractor and their U. Government customer to provide cybersecurity vulne...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Vervic • Arlington, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cybersecurity Vulnerability Analyst (Incident Manager III.Supporting our prime contractor and their U.Government customer to provide cybersecurity vulnerability analysis support to reduce the preva...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    Host Based Cyber Systems Analyst IV

    Host Based Cyber Systems Analyst IV

    Argo Cyber Systems • Arlington, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Argo Cyber Systems provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day
    Cyber Incident Manager / Incident Manager

    Cyber Incident Manager / Incident Manager

    Node.Digital • Arlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cyber Incident Manager / Incident Manager.Must have an active Top Secret Security Clearance.Government customer to provide support for onsite incident response to civilian Government agencies and cr...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Senior Cyber Defense Incident Responder

    Senior Cyber Defense Incident Responder

    Network Designs Inc. • Washington DC, DC, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly de...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    Digital Forensics Incident Response Consultant

    Digital Forensics Incident Response Consultant

    Verizon • Ashburn, VA, United States
    serp_jobs.job_card.full_time +1
    A place to share your ideas freely - even if they're daring or different.Where the true you can learn, grow, and thrive.At Verizon, we power and empower how people live, work and play by connecting...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Analyst - ConMon

    Cyber Analyst - ConMon

    Leidos Inc • Alexandria, VA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking multiple ConMon Analysts to be responsible for overseeing and monitoring authorized IT systems (re-authorization and new systems) throughout their lifecycle for security posture i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Defensive Cyber Operations Analyst

    Defensive Cyber Operations Analyst

    Leidos Inc • Washington, DC, United States
    serp_jobs.job_card.full_time
    The Leidos Digital Modernization sector is continuously looking for Defensive Cyber Operations Analysts interested in joining our team in Washington, DC. We hire for these roles on an ongoing basis ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Cyber Analyst - Mid

    Cyber Analyst - Mid

    Nalley Consulting • Washington, DC, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Join the Nalley Consulting team as a Cyber Analyst at DIA HQ.Cyber Analyst LCAT : Mid Location : DIA HQ, Washington, DC Clearance requirement : TS / SCI clearance. CI poly or willingness to take ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    ENS Solutions, LLC • Reston, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities.As a RMF Cybersecurity Analyst supporting the Federal Government and the Inte...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    SOC Technical Lead

    SOC Technical Lead

    ManTech • McLean, VA, United States
    serp_jobs.job_card.full_time
    This position may require occasional local travel to.The SOC Technical Lead will provide technical leadership and subject matter expertise for incident response and analysis.Lead a team of Cyber Op...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Cyber Engineer Lead

    Cyber Engineer Lead

    ManTech • Springfield, VA, US
    serp_jobs.job_card.full_time
    The Cyber Security Analyst Lead is responsible for the detection, identification, analysis, and reporting of cyber threats, intrusions, anomalous activities, and potential misuse of systems.This ro...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Zero Trust Cyber Security Analyst

    Zero Trust Cyber Security Analyst

    Leidos Inc • Reston, VA, United States
    serp_jobs.job_card.full_time
    The Digital Modernization Health IT group at Leidos currently has an opening for a Zero Trust Cyber Security Analyst.This is a fantastic opportunity to work remotely, as well as use your expertise ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Lead Cyber Threat Analyst

    Lead Cyber Threat Analyst

    DirectViz Solutions, LLC • Washington, DC, United States
    serp_jobs.job_card.full_time
    DirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS offers competitive compensation, compr...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Threat Analysis Division Task Lead

    Cyber Threat Analysis Division Task Lead

    Clearance Jobs • Arlington, VA, US
    serp_jobs.job_card.full_time
    Seize your opportunity to make a personal impact as a Project / Task Manager supporting our program.GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding ca...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Incident Responder / Incident Response Coordinator

    Incident Responder / Incident Response Coordinator

    Nationwide IT Services • Arlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Incident Responder / Incident Response Coordinator Location : .Onsite – Arlington, VA or Mechanicsburg, PA Clearance Requirement : Active Secret Clearance Employment Type : Full-time Company : Nat...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30