Demo

Cyber Incident Response Team Analyst (Tier 2)

AGR LLC
Beltsville, MD Full Time
POSTED ON 12/31/2025
AVAILABLE BEFORE 2/28/2026

Location: Beltsville, MD

Work Hours: Evening Shift, 1400 – 2200 EST, TUE-SAT

Program Overview

The DSCM program encompasses cyber security, data analytics, engineering, technical, managerial, operational, logistical and administrative support to aid and advise DOS Cyber & Technology Security (CTS) Directorate.  This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats.  Those supporting the DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.     

About the Role

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

Qualifications:

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date:
    • A CE, CCNA-Security, CND, Network CE, SSCP, Security .
  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.

Preferred Qualifications:

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Security , CySA , Cloud , Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP , PRMP, GREM, GEIR, GNFA, or GCFA.

 


Salary : $75,000 - $85,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cyber Incident Response Team Analyst (Tier 2)?

Sign up to receive alerts about other jobs on the Cyber Incident Response Team Analyst (Tier 2) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,958 - $200,151
Income Estimation: 
$186,685 - $265,377
Income Estimation: 
$173,252 - $220,888
Income Estimation: 
$152,958 - $200,151
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$71,440 - $92,105
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$115,647 - $153,495
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at AGR LLC

  • AGR LLC Beltsville, MD
  • Internetwork Consulting Services (ICS) is currently seeking an experienced Malware Senior Engineer, Subject Matter Expert to become part of the Department ... more
  • 12 Days Ago

  • AGR LLC Beltsville, MD
  • Internetwork Consulting Services (ICS) is seeking an experienced Scanning Engineer with strong Tenable expertise to support its Federal Strategic Cyber Pro... more
  • 12 Days Ago

  • AGR LLC Beltsville, MD
  • Internetworks Consulting Services (ICS) is currently hiring for a Lead Cybersecurity Engineer with Linux and Cloud Integration to join our Federal Strategi... more
  • 12 Days Ago

  • AGR LLC Beltsville, MD
  • Internetwork Consulting Services (ICS) is currently hiring for a Security Development Team Lead to join our Federal Strategic Cyber Programs. Location: Bel... more
  • 12 Days Ago


Not the job you're looking for? Here are some other Cyber Incident Response Team Analyst (Tier 2) jobs in the Beltsville, MD area that may be a better fit.

  • Cyber Synergy Consulting Group Washington, DC
  • Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)Location: Remote with occasional on-site (Washington, D.C. Metro Area)Employment Type: F... more
  • 26 Days Ago

  • MANTECH Mc Lean, VA
  • ManTech seeks a motivated, career and customer-oriented Senior Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x... more
  • 24 Days Ago

AI Assistant is available now!

Feel free to start your new journey!