We believe in the power of change, harnessed in ways that matter for our country and communities.
Cybersecurity Incident Response Triage Analyst
Location
Virginia
Posted
4 days ago
Salary
$53.9K - $120.1K / year
Seniority
Junior
Job Description
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services
• Actively monitor and respond to cybersecurity incidents related to alerted policy violations • Analyze and investigate incidents to determine their nature and scope. • Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution. • Document incidents and response activities in detail. • Stay updated with the latest cybersecurity threats and trends. • Assist in developing and refining incident response strategies and procedures. • Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives.
Job Requirements
- US Citizenship required
- Excellent communication skills and knowledge in incident response lifecycles, common cyber-attacks, insider-threat indicators and warnings, data loss prevention and detection mechanisms, and federal incident reporting requirements.
- Excellent communication (written and oral), attention to detail & interpersonal skills
- Experience presenting complex technical information to decision makers and leading them through the decision making process
- Work independently to deliver timely solutions without direct supervision
- 1-2 years experience in information security, or other equivalent combination of education or equivalent work experience.
- 1 year(s) of experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions.
- Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages.
- Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same.
- Familiarity with static and dynamic malware analysis concepts.
- Experience with indicators of attack and compromise.
- Familiarity with Windows / Linux architecture and endpoint analysis of the same.
- Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc.
Benefits
- Competitive salary
- Wide variety of benefits
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Lead, coach, and develop a team of Security Consultants through regular feedback, career development, and performance management • Serve as a subject matter expert in at least one security specialty (web, network, cloud, or mobile) and provide technical guidance to internal and external stakeholders • Demonstrate expertise across all vulnerability submission types and support complex escalations and appeals, partnering with other business units as needed • Drive operational excellence by measuring team performance, identifying opportunities for automation, and implementing process improvements • Plan, prioritize, and manage team workloads while adapting to changing business needs and customer priorities • Mentor team members and contribute to the growth of the broader security organization through knowledge sharing and technical leadership • Build strong cross-functional partnerships to improve workflows and deliver high-quality customer outcomes • Lead effective meetings, clearly communicate priorities, and ensure timely execution of action items • Act as a trusted advisor to leadership and customers by providing sound technical judgment and operational insight • Stay current on security industry standards, emerging threats, and best practices to continuously improve team capabilities.
• Lead and mentor a team of junior and mid-level SOC analysts, fostering professional growth and technical proficiency. • Drive resolution for high-priority and critical security incidents, acting as the primary technical point of escalation. • Oversee and strategize proactive threat-hunting operations and detection engineering workflows. • Monitor and triage security alerts. • Build, test, and refine detections to enhance threat identification across Mac, Linux, and Windows systems. • Conduct in-depth analysis of security incidents, including malware, phishing, and advanced persistent threats, leveraging SIEM and EDR capabilities. • Perform proactive threat hunting using the SIEM and EDR features. • Investigate and respond to incidents swiftly, following established incident response protocols. • Document findings clearly and provide actionable remediation recommendations. • Collaborate with cross-functional teams to strengthen security controls and mitigate vulnerabilities. • Stay current on emerging threats, vulnerabilities, and industry trends through self-directed learning. • Participate in on-call rotation for 24x7x365 SOC coverage, demonstrating reliability and accountability. • Escalate confirmed or suspicious incidents and cases to the Incident Response team.
SecOps Business Development Manager
FortinetFortinet is a global leader in high-performance cybersecurity solutions. With a mission to secure People, Devices and Data everywhere, Fortinet offers a comprehensive suite of products and services to protect businesses of all sizes.
Role Description Fortinet is seeking a dynamic and results-oriented individual to join our team as a SECOPS Business Development Manager. In this role, you will be responsible for driving business growth and expanding our market presence in the Security Operations (SECOPS) sector. You will play a pivotal role in identifying new business opportunities, building strategic partnerships, and driving revenue growth through effective sales strategies. - Develop and execute strategic plans to drive business growth in the SECOPS sector, leveraging Fortinet's industry-leading cybersecurity solutions. - Identify and cultivate relationships with key decision-makers, influencers, and stakeholders in target organizations. - Collaborate with cross-functional teams including sales and Pre-Sales, marketing and Channel to develop and execute Go-to-Market strategies. - Drive SecOps sales opportunities together with Sales and Pre-Sales through the entire sales cycle, from lead generation to closing deals. - Conduct market research and analysis to identify emerging trends, competitive landscape, and customer needs. - Provide input to product development teams based on market feedback and customer requirements. - Educate Sales Teams on positioning of the Fortinet offering. - Meet and exceed sales targets, revenue goals, and other key performance metrics. - Represent Fortinet at industry events, conferences, and seminars to showcase our SECOPS solutions and thought leadership. Qualifications - Bachelor's degree in Business Administration, Marketing, Computer Science, or related field. MBA is a plus. - Proven track record of success in business development, sales, or account management roles within the cybersecurity industry, with a focus on SECOPS solutions. - Strong understanding of Security Operations Center (SOC) environments, security incident response, threat detection, and remediation. - Excellent communication, presentation, and negotiation skills. Ability to articulate complex technical concepts to both technical and non-technical audiences. - Self-motivated, proactive, and results-driven with the ability to work effectively in a fast-paced, dynamic environment. - Strong analytical skills with the ability to analyze market trends, customer data, and sales performance metrics. - Experience working with channel partners, resellers, and distributors is a plus. - Willingness to travel as needed. Benefits - Opportunity to work for a global leader in cybersecurity with a strong reputation for innovation and excellence. - Competitive compensation package including base salary, commission, and benefits. - Career growth opportunities in a dynamic and fast-growing industry. - Collaborative and inclusive work environment with a focus on teamwork and professional development. Company Description Fortinet is a global leader in high-performance cybersecurity solutions. With a mission to secure People, Devices and Data everywhere, Fortinet offers a comprehensive suite of products and services to protect businesses of all sizes.
Role Description This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies. Primary Responsibilities - Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis). - Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape. - Develop and maintain threat models, incorporating findings from penetration tests into detection strategies. - Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior. - Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks. - Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines. - Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue. - Review and tune threat intelligence systems, including brand protection and dark web monitoring. - Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools. - Support IR leadership as backup on IR-related activities. Qualifications - Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling. - In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure). - Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes. - Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred. - Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO. - Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team. - Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.



