Cyber Incident Response Analyst

Hybrid in Austin, TX, US • Posted 3 hours ago • Updated 3 hours ago
Contract W2
6 Months
No Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • cybersecurity
  • incident response
  • documentation
  • 24x7
  • CISSP
  • Security +
  • threat intelligence

Summary

We are looking for Cyber Incident Response Analysts to support an advanced cybersecurity operations program. Candidates must meet the qualifications outlined below. All work products resulting from this engagement shall be considered works made for hire.

Key Responsibilities

  • Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery.
  • Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis.
  • Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies.
  • Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK.
  • Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools.
  • Produce incident reports, timelines, and executive summaries for stakeholders.
  • Support multi-agency response operations, including SLTT partners and critical infrastructure entities.
  • Provide recommendations for detection improvements, hardening, and long-term mitigation.
  • Participate in post-incident reviews, lessons learned, and playbook updates.
  • Maintain readiness for 24x7 response through on-call rotation or surge support.

 

Required Experience

  • 5 years: Advanced host-based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity.
  • 5 years: Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines.
  • 5 years: Experience producing high-quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows.
  • 4 years: Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet-level and log-level data from Corelight, NetWitness, and CRIBL pipelines.
  • 3 years: Incident Commander experience.
  • 1 year: Experience supporting SLTT or critical infrastructure environments, including multi-tenant IR operations and cross-agency coordination.

Preferred Experience & Certifications

  • 5 years: Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK.
  • 5 years: Hands-on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems.
  • 4 years: Security Certifications preferred: CISSP, CIH, Sec+.

 

What We Offer:

 

  • Competitive compensation and benefits including health, dental, vision, life and accident insurance, disability insurance and much more!
  • Altruistic work
  • Great work-life balance
  • Hybrid work schedule 

 

This is a long-term, multi-year contract engagement in Austin, TX or San Antonio, TX.  Luna Data Solutions, Inc. (LDS) provides equal employment opportunities to all employees. All applicants will be considered for employment. LDS prohibits discrimination and harassment of any type regarding age, race, color, religion, sexual orientation, gender identity, sex, national origin, genetics, protected veteran status, and/or disability status. A 7-year background check is required for this role. 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10314722
  • Position Id: 5482SM_Austin
  • Posted 3 hours ago
Contact the job poster
Kalee Barnes

Kalee Barnes

Recruiter! @ Luna Data Solutions, Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Austin, Texas

Today

Contract

$40 - $45 hourly

Hybrid in San Antonio, Texas

Today

Easy Apply

Contract

Depends on Experience

Hybrid in San Antonio, Texas

Today

Easy Apply

Contract, Third Party

Depends on Experience

Remote

Today

Full-time

Search all similar jobs