Accenture Federal Services→
Cybersecurity Incident Response Triage… at Accenture… · Arlington
Entry LevelOn-siteFull-timeArlington, VA$57k–$109k/yr
Skills
cybersecurity incident responsesecurity informationevent management (siem)eventlog analysisanti-virus toolsintrusion detection systemsfirewallsactive directoryweb proxiesdata loss prevention toolsnetworkhost-based security applicationshost assessment/scanning toolshost-based intrusion detection systemstcp/ip protocolsapplication layer protocolspacket analysisstatic malware analysisdynamic malware analysisindicators of attackcompromisewindows architecturelinux architectureendpoint analysisdata parsinganalysis toolsregular expressionssans giac certifications
Job Description
Summary: Accenture Federal Services is dedicated to helping the US federal government enhance national security and improve people's lives. They are seeking a Cybersecurity Incident Response Triage Analyst to monitor and respond to cybersecurity incidents, analyze and investigate alerts, and collaborate with various teams to ensure effective incident resolution.
Responsibilities:
- Actively monitor and respond to cybersecurity incidents related to alerted policy violations
- Analyze and investigate incidents to determine their nature and scope
- Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution
- Document incidents and response activities in detail
- Stay updated with the latest cybersecurity threats and trends
- Assist in developing and refining incident response strategies and procedures
- Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives
Required Qualifications:
- US Citizenship required
- 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience
- 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus, Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions
- Excellent written and oral communication skills, attention to detail, and interpersonal skills
- Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software packages
- Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same
- Familiarity with static and dynamic malware analysis concepts
- Experience with indicators of attack and compromise
- Familiarity with Windows / Linux architecture and endpoint analysis of the same
- Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc
Preferred Qualifications:
- SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM
Required Skills: Cybersecurity incident response, Security Information, Event Management (SIEM), Event, log analysis, Anti-virus tools, Intrusion Detection Systems, Firewalls, Active Directory, Web proxies, Data loss prevention tools, Network, host-based security applications, host assessment/scanning tools, host-based intrusion detection systems, TCP/IP protocols, Application layer protocols, Packet analysis, Static malware analysis, Dynamic malware analysis, Indicators of attack, compromise, Windows architecture, Linux architecture, Endpoint analysis, Data parsing, analysis tools, Regular expressions, SANs GIAC Certifications