Accenture Federal Services logo
Accenture Federal Services
Posted 3 days agoVerified live 1d ago

Cybersecurity Incident Response Triage Analyst

Brief overview

Remote
UndergradOr in progress
$57k–$109k/yrStated range
1+ yrsMinimum
Cybersecurity Incident ResponseEvent and Log AnalysisSecurity Information and Event Management (SIEM)AntivirusIntrusion Detection SystemsFirewallsActive DirectoryData Loss PreventionTCP/IP and Application-Layer ProtocolsPacket AnalysisStatic and Dynamic Malware AnalysisWindows and Linux Endpoint AnalysisWritten and Oral Communication

Job description

Summary

Accenture Federal Services is a technology company serving the US federal government across defense, national security, public safety, civilian, and military health organizations. The Cybersecurity Incident Response Triage Analyst works on the CIRT analysis and triage team to assess alerts, investigate and scope cybersecurity incidents, distinguish true and false positives, and support incident resolution and reporting.

Responsibilities

  • Actively monitor and respond to cybersecurity incidents related to alerted policy violations
  • Analyze and investigate incidents to determine their nature and scope
  • Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution
  • Document incidents and response activities in detail
  • Stay updated with the latest cybersecurity threats and trends
  • Assist in developing and refining incident response strategies and procedures
  • Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives

Skills

  • US Citizenship required
  • 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience
  • 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus, * Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions
  • Excellent written and oral communication skills, attention to detail, and interpersonal skills
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software  packages
  • Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same
  • Familiarity with static and dynamic malware analysis concepts
  • Experience with indicators of attack and compromise
  • Familiarity with Windows / Linux architecture and endpoint analysis of the same
  • Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc
  • SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM

Qualifications

Must Haves

  • US Citizenship required
  • 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience
  • 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus, * Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions
  • Excellent written and oral communication skills, attention to detail, and interpersonal skills
  • Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software  packages
  • Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same
  • Familiarity with static and dynamic malware analysis concepts
  • Experience with indicators of attack and compromise
  • Familiarity with Windows / Linux architecture and endpoint analysis of the same
  • Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc

Nice to Haves

  • SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM

Benefits

  • A collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more.