Cybersecurity Incident Response Triage Analyst
Job Description
Accenture Federal Services is hiring a Cybersecurity Incident Response Triage Analyst to support the CIRT team within the CISO organization. This onsite role in Arlington, VA works shifts to relate, scope, and triage alerts and notifications, helping turn security signals into clear investigation paths.
In this position, you will contribute to incident monitoring and response, investigate and document findings, coordinate with other Cybersecurity Incident Response Teams, and stay current on threats. If you enjoy incident-driven work and clear, detailed reporting, this role supports hands-on investigation across enterprise security environments.
Responsibilities
- Actively monitor and respond to cybersecurity incidents tied to alerted policy violations
- Analyze and investigate incidents to determine nature and scope
- Coordinate with the lead and other Cybersecurity Incident Response Teams to support effective incident resolution
- Document incidents and response activities in detail
- Stay updated on the latest cybersecurity threats and trends
- Assist in developing and refining incident response strategies and procedures
- Collaborate with operations teams, legal, human resources, and management to investigate security issues and interview investigation subjects to determine true and false positives
Requirements
- US Citizenship required
- 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience
- 1-year of experience performing event and log analysis, including one or more of: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools, and other security tools found in large enterprise network environments; plus experience working with Security Information and Event Management (SIEM) solutions
- Excellent written and oral communication skills, attention to detail, and interpersonal skills
- Familiarity with network and host-based security applications and tools, including network/host assessment or scanning tools and network/host-based intrusion detection systems
- Familiarity with TCP/IP, common application layer protocols, and packet analysis
- Familiarity with static and dynamic malware analysis concepts
- Experience with indicators of attack and compromise
- Familiarity with Windows / Linux architecture and endpoint analysis
- Familiarity with basic data parsing and analysis tools, including Excel, grep, sed, awk, regex, etc.
Technologies
- Security Information and Event Management (SIEM)
- Anti-Virus, Intrusion Detection Systems, Firewalls
- Active Directory, Web Proxies, Data loss prevention tools
- Network and host assessment/scanning tools, network and host-based intrusion detection systems
- TCP/IP, packet analysis
- Static malware analysis, dynamic malware analysis
- Windows, Linux, endpoint analysis
- Excel, grep, sed, awk, regex
Bonus if you have
- SANS GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM
Compensation: USD 57,200 - 109,400 per year. Experience: 1 years. Location: Arlington, VA (onsite).