Back to all jobs

Incident Response Analyst, Mid

Booz Allen

Sep 24

Incident Response Analyst, Mid

Key Role:

Respond and resolve cyber security incidents, and proactively prevents reoccurrence of these incidents. Apply specific functional knowledge to resolve security incidents. Develop or contribute to solutions to a variety of problems of moderate scope and complexity. Work independently with some guidance. This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.

Basic Qualifications:

  • Experience with handling escalations from Tier 1 and managing the process to closure
  • Experience with tuning alerts
  • Knowledge of IOC extraction from malware
  • Ability to provide feedback to the Tier 1 team to mediate false escalations to support the learning process
  • Ability to analyze and resolve network ad host-based security events
  • Ability to obtain a security clearance
  • BA or BS degree

Additional Qualifications:

  • Experience with REMnux tool suite
  • Experience with Splunk, FirePower, Snort, FireEye, or Palo Alto hands-on
  • Ability to disseminate findings to clients in a clear, concise manner

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Compensation:

The proposed salary range for this position in Colorado is $100,000 to $115,000. Final salary will be determined based on various factors.

At Booz Allen, we celebrate your contributions, provide you with opportunities and choice, and support your total well-being. Our comprehensive benefit offerings include healthcare, retirement plan, insurance programs, commuter program, employee assistance program, paid and unpaid leave programs, education assistance, and childcare benefits.

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.