This site uses cookies. To find out more, see our Cookies Policy

Incident Response Analyst in Durham, NC at Booz Allen Hamilton Inc.

Date Posted: 3/13/2019

Job Snapshot

Job Description

Job Number: R0045839

Incident Response Analyst

The Challenge:

Serve as an incident response analyst, including maintaining responsibility for identifying and responding to security threats. Maintain responsibility for incident confirmation, response, data collection, investigation, and analysis. Leverage comprehension of computer and network architecture to provide analysis during investigations, including identifying adversarial activity and methods for future detection and prevention. Use a combination of open source research, network and host-based forensic analysis, log review and correlation, and pcap analysis to complete investigations. Compose and present reports on findings to leadership for intrusion incidents. Manage the incident life cycle, ensuring that all investigations are kept current and are completed.

Empower change with us.

Build Your Career:

Rewarding work, fun challenges, and a ton of investment in our people—that’s Booz Allen Cyber. When you join Booz Allen, we’ll help you develop the career you want.

  • Competitions — From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we’ve got plenty of chances for you to show off your skills.
  • Paid Research — Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.
  • Cyber University — CyberU has more than 5000 instructor-led and self-paced Cyber courses, a free online library that you can access from just about anywhere—including your phone—and certification exam prep guides that include practical assessments to prepare you for your exam.
  • Academic Partnerships — In addition to our tuition reimbursement benefit, we’ve partnered with University of Maryland University College to offer two graduate certificate programs in Cybersecurity—fully funded without a tuition cap.
  • Maker/Hackerspaces — Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.

You Have:

-Experience with system administration, network engineering, and security engineering

-Experience with performing host or network incident response, malware analysis, or forensics

-Experience with working in a Computer Incident Response Team (CIRT), Computer Security Incident Response Center (CSIRC), or Security Operations Center (SOC)

-Knowledge of host and network log sources to apply to investigation and IR methodology in investigations

-Knowledge of networking, malware analysis, intrusion analysis, infection vector identification, and forensics

-Ability to work as a team player to analyze activity on a complex network and its end points with the goal of protecting the confidentiality, integrity, and availability of systems and data and to learn and adapt quickly

-Ability to work using standard operating procedures and be flexible to work beyond the standard daytime working hours, as needed

-Ability to obtain a security clearance

-BA or BS degree or 4+ years of experience with Cybersecurity-based work

Nice If You Have:

-Possession of excellent oral and written communication skills to document incident response

-CompTIA Net+, CompTIA A+, CompTIA Security+, GIAC Certified Incident Handler (GCIH), CISSP, or EC-Council Certified Incident Handler (ECIH) Certification

Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.

Your Career is Waiting.

Get job alerts. Learn about new work and upcoming events. Share open roles with friends and colleagues.
Our Talent Network is your opportunity hub.


Get Answers and Access.

Need more information? Find it in our FAQs.

Application already in-process? Log in to keep going.