ECS is seeking a Mid Cyber Incident Analyst to work remotely.
ECS is seeking talented professionals to join our successful and growing team supporting the Cybersecurity and Infrastructure Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC). The JCDC is CISA’s flagship initiative for uniting government, industry, and international partners to proactively defend against cyber threats. Our ECS team is at the center of providing support to JCDC as they continue to plan, share, and respond to cyber threats in real time to support the greater cyber community and we are looking to grow our team supporting this critical mission.
We are looking for a Mid. Cyber Incident Analyst for a team that provides deep technical analysis during active cyber incidents, including insights into vulnerabilities, adversarial tactics, and mitigation strategies across diverse environments like IT, OT/ICS, cloud, and AI systems. This position will support a team that interfaces extensively with multiple organizations within CISA including Vulnerability Management (VM) and Threat Hunt (TH) to provide guidance and analysis on active cyber threats for JCDC partners. This position will assist in defining critical data sources for collection, inform processes, write detection rules, and analyze active and emerging cyber threats and incidents from across Federal Civilian Executive Branch (FCEB), Critical Infrastructure (CI) and State, Local, Tribal and Territorial (SLTT).
The Mid. Cyber Incident Analyst will support a team that works closely with many stakeholders, including DHS CISA TH and VM, Agency security analysts / user groups, and the ECS team to ensure alignment between solution development and needs of stakeholders. The Analyst will perform research and assist with solutions for specific IOCs and IOAs. The Analyst will aid in defining tools, processes, and procedures for advancing Threat Hunting and Incident Response capabilities within CISA, FCEB, CI and SLTT.
Responsibilities:
- Perform analysis on active cyber incidents, events and vulnerabilities to provide guidance and targeted recommendations for mitigation
- Support the development of written guidance and recommendations to assist JCDC partners with solutions for active and ongoing cyber vulnerabilities
- Stay current with emerging technologies and trends in cybersecurity, and apply this knowledge to improve threat detection and mitigation efforts
- Through hands-on analysis provide insights into vulnerabilities, adversarial tactics, and mitigation strategies across diverse environments like IT, OT/ICS, cloud, and AI systems
- Assist with mapping technical insights on cyber threats to frameworks like MITRE ATT&CK and other cyber frameworks
- Support a team in the translation of strategic products into clear, practical formats that are tailored to the specific needs and operational constraints of different stakeholder groups, including large and small jurisdictions and critical infrastructure (CI) partners
- Assist in the tailoring of vulnerability mitigation recommendations and contextualized examples to stakeholders to address implementation challenges and encourage rapid adoption
Salary Range: $145,000 - $160,000
General Description of Benefits
Preferred Qualifications- US Citizenship and the ability to obtain and maintain a minimum of DHS (Suitability) EOD/ Public Trust
- 6+ Years of previous experience in a threat intelligence, cyber security, incident response, or similar role
- Strong understanding of computer and network fundamentals
- Basic understanding of computer architecture, operating systems, vulnerabilities, encryption, or other areas of expertise
- Experience defining data sources and writing detection rules for discovering malicious behavior
- With minimum support perform in-depth research tasks and produce written summaries to include insights and predictions based on an analytical process
- Excellent written and oral communication skills
- An understanding of current cyber threats/exploits, attack methodology, and detection techniques using a wide variety of security products including COTS and open source
Top Skills
What We Do
ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries.
ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies.
Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.