Talent.com
serp_jobs.error_messages.no_longer_accepting
Cyber Incident Response Analyst (SME)

Cyber Incident Response Analyst (SME)

CACI InternationalHampton, VA, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

Cyber Incident Response Analyst (SME) on the DCGS Management Center (DMC) program located at Langley AFB. The role requires a strong system administration background, Windows and Linux experience, hands-on ELK / Elastic Stack for threat detection, and the ability to follow established Incident Response processes with minimal supervision. This position is onsite with shift work.

Responsibilities

  • Lead and assist in incident response investigations through all phases (detection, containment, eradication, recovery, lessons learned) to ensure the confidentiality, integrity, and availability of the OA DCGS weapon system.
  • Utilize ELK / Elastic Stack to perform log analysis, threat detection, and investigations; create and maintain security incident reports and dashboards.
  • Escalate and document internal / external security incidents through appropriate ticketing and reporting processing.
  • Design, implement, and maintain cybersecurity SOPs and incident playbooks.
  • Maintain documentation of IR processes and case notes; ensure security testing and evaluations are completed and properly documented.
  • Support proactive threat hunting and vulnerability assessments.
  • Analyze and correlate logs from varied data sources to identify patterns and anomalies.
  • Understand network protocols and establish baselines to identify abnormal activity.
  • Perform cyber threat analysis and reporting on information from internal and external sources and apply cyber threat intelligence to defending the enterprise network.
  • Apply knowledge of Zero-Day vulnerabilities and CVEs to incident handling and remediation.
  • Collaborate with cross-functional teams and external stakeholders as needed.
  • Provide guidance for securing information systems and support cyber vulnerability penetration assessments.
  • Operate independently during shifts and respond to security alerts with urgency.

Qualifications

Required :

  • Top Secret / SCI security clearance.
  • Bachelor's degree in IT Technology, Computer Science, or related field with 4+ years of experience. Degree may be substituted with additional years of experience.
  • DOD 8140 (8570) IAT Level II (Security+ or equivalent).
  • Strong system administration skills across Windows and Linux platforms.
  • In-depth understanding of the Incident Response lifecycle.
  • Proficiency in using the Elastic Stack (Elasticsearch, Logstash, Kibana).
  • Familiarity with enterprise security tools and procedures.
  • Strong problem-solving and analytical skills.
  • Comfortable working with limited supervision in a shift-work setting.
  • Availability to work weekends and holidays as part of our 24 / 7 operations.
  • Desired :

  • AF DCGS experience.
  • Four to seven years of intelligence network communications or Systems Administration experience.
  • Knowledge of security best practices and standards, including NIST, ISO, and SOC operations.
  • Experience with AWS and / or other cloud security platforms.
  • Background as an ISSO, including STIG / SCAP and vulnerability management.
  • Familiarity with tools such as Tanium, Trellix, and ACAS.
  • Understanding of network architecture and traffic analysis.
  • Basic scripting skills (Python, PowerShell, Bash).
  • Elastic certification or SME-level expertise.
  • Effective written and verbal communication skills for documentation and collaboration.
  • What You Can Expect

    CACI offers a culture of integrity, trust, and growth. You'll be part of a high-performing team dedicated to our customers\' missions and the safety of our nation, with flexible time off and robust learning resources. We support continuous growth and offer a comprehensive benefits package including healthcare, retirement, and education benefits. Learn more about CACI here.

    Pay and Equal Opportunity

    The proposed salary range for this position is $75,200-$158,100, commensurate with location, experience, and qualifications. CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Incident Response Analyst • Hampton, VA, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Senior Network Security Engineer • •

    Senior Network Security Engineer • •

    SimVentions, Inc - Glassdoor 4.6Virginia Beach, VA, United States
    serp_jobs.job_card.full_time
    SimVentions, consistently voted one Virginia's Best Places to Work, is looking for an experienced network security professional to join our team! As a Network Security Engineer IV, you will perform...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security GRC Analyst

    Security GRC Analyst

    VirtualVocationsNewport News, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security GRC Analyst.Key Responsibilities Lead the strategy, execution, and improvement of the compliance program, including assessments and policy documentation Devel...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Blue Team Security Engineer

    Blue Team Security Engineer

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer, Blue Team.Key Responsibilities Conduct security risk assessments of third parties and evaluate supplier security risks Build security tooling and au...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Security DevOps Engineer

    Security DevOps Engineer

    VirtualVocationsPortsmouth, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security DevOps Engineer with expertise in Azure security and compliance.Key Responsibilities Identify and remediate security vulnerabilities in Azure workloads and dev...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Network Firewall Engineer

    Network Firewall Engineer

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Network Operations Firewall Engineer.Key Responsibilities Monitor, manage, and support enterprise firewalls and security appliances Implement firewall rule changes, NA...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Software Security Engineer

    Software Security Engineer

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Software Security Engineer, Experienced or Senior (Virtual).Key Responsibilities Operationalize the open-source policy and process through automation Independently inv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Workday Security Architect

    Workday Security Architect

    VirtualVocationsVirginia Beach, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Workday Security Architect to lead the redesign and optimization of a large enterprise Workday security environment. Key Responsibilities Lead design sessions with stake...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    SAP Application Security Engineer

    SAP Application Security Engineer

    VirtualVocationsNewport News, Virginia, United States
    serp_jobs.job_card.full_time +1
    A company is looking for an Application Security Engineer with expertise in SAP systems for a short-term contract.Key Responsibilities Assess and strengthen security configurations within SAP ABA...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst II

    Cybersecurity Analyst II

    VirtualVocationsVirginia Beach, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Analyst II to handle security alerts, incident response, and threat investigations. Key Responsibilities Monitor and triage alerts from various security to...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Security Analyst

    Senior Cyber Security Analyst

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cyber Security Analyst.Key Responsibilities Assist in the design and implementation of comprehensive compliance programs aligned with multiple frameworks Config...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cloud Security Architect

    Senior Cloud Security Architect

    VirtualVocationsVirginia Beach, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Information Security Architect (Remote).Key Responsibilities Develop and implement a comprehensive cloud security strategy aligned with organizational goals and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    SPY-6(V)2 / 3 (EASR) Test Project Officer

    SPY-6(V)2 / 3 (EASR) Test Project Officer

    Decision TechnologiesVirginia Beach, VA, United States
    serp_jobs.job_card.full_time
    Work for a dynamic company specializing in technical support services and engineering consultancy.RF Systems and Missile Sensors, production transition, quality and reliability assessment, test and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Threat Detection Engineer

    Senior Threat Detection Engineer

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Threat Detection Engineer.Key Responsibilities Participate in a 24 / 7 on-call rotation for alert triage and investigation Support functions such as incident resp...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    CISSP Security Architect

    CISSP Security Architect

    VirtualVocationsVirginia Beach, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a MeF Security Architect to lead security architecture and serve as the key point of contact for security-related decisions. Key Responsibilities Develop and extend MeF se...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Cyber Security Engineer / ISSO

    Cyber Security Engineer / ISSO

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Engineer / ISSO.Key Responsibilities Perform day-to-day information assurance and system administration duties for Space Force systems Implement and maint...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cyber Security Engineering Lead

    Cyber Security Engineering Lead

    VirtualVocationsVirginia Beach, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Security Engineering Lead.Key Responsibilities Optimize cybersecurity program processes and contribute to the broader program roadmap Manage and execute cybersec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    CA Top Secret Systems Administrator

    CA Top Secret Systems Administrator

    VirtualVocationsNorfolk, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Computer Associates' Top Secret Security product Systems Administrator (Remote).Key Responsibilities Provide mentor level support and customer assistance through report...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    SafeTrace Analyst

    SafeTrace Analyst

    VirtualVocationsChesapeake, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a SafeTrace Analyst to support Epic's SafeTrace Tx module.Key Responsibilities Support system build, troubleshooting, and reporting for blood product tracking and transfu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Network Security Engineer

    Senior Network Security Engineer

    VirtualVocationsNewport News, Virginia, United States
    serp_jobs.job_card.temporary
    A company is looking for a Senior Network Security Engineer for a fully remote, 5-month contract position.Key Responsibilities Monitor, install, configure, administer, troubleshoot, and maintain ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    AI Security Engineer

    AI Security Engineer

    VirtualVocationsChesapeake, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Engineer with a focus on AI.Key Responsibilities Support ongoing security operations including monitoring, incident response, and risk assessment Assess and m...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30