Cybersecurity Incident Response Triage Analyst
The Work
The Cybersecurity Incident Response Junior Analyst and Triage Analyst role will work in the CIRT team in the CISO organization. This role works on a shift under the analysis and triage team lead to relate, scope, and triage alerts and notifications from the SIEM, security sensors, ticketing system, walk-ins, and phone calls. Requires technical understanding to collaborate with the incident response and operations teams to qualify events as relevant and determine true and false positives. Knowledge in incident response lifecycles, common
cyber-attacks, and federal incident reporting requirements.
Primary responsibilities:
- Actively monitor and respond to cybersecurity incidents related to alerted policy violations
- Analyze and investigate incidents to determine their nature and scope.
- Coordinate with the lead and other Cybersecurity Incident Response Teams for effective incident resolution.
- Document incidents and response activities in detail.
- Stay updated with the latest cybersecurity threats and trends.
- Assist in developing and refining incident response strategies and procedures.
- Collaborate with operations teams, legal, human resources and management to investigate security issues and interview investigation subjects to determine true and false positives.
What you need
- US Citizenship required
- 1 - 2 years of experience in information security, or other equivalent combination of education or equivalent work experience.
- 1-year of experience performing event and log analysis including one or more of the following: Anti-Virus,
- Intrusion Detection Systems, Firewalls, Active Directory, Web Proxies, Data loss prevention tools and other security tools found in large enterprise network environments; along with experience working with Security Information and Event Management (SIEM) solutions.
- Excellent written and oral communication skills, attention to detail, and interpersonal skills.
- Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software
packages. - Familiarity with various network and host-based security applications and tools, such as network and host assessment/scanning tools, network and host-based intrusion detection systems, and other security software
packages. - Familiarity with TCP/IP, common application layer protocols, and packet analysis of the same.
- Familiarity with static and dynamic malware analysis concepts.
- Experience with indicators of attack and compromise.
- Familiarity with Windows / Linux architecture and endpoint analysis of the same.
- Familiarity with basic data parsing and analysis tools, i.e., Excel, grep, sed, awk, regex, etc
Bonus if you have
- SANs GIAC Certifications including but not limited to GCED, GCLD, GCIH, GCFA, GREM
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
- State choose one
- Are you at least 18 years of age? choose one
- Are you legally authorized to work in the United States? choose one
- Many AFS positions require US citizenship. Please indicate your citizenship status so we can determine eligibility for specific roles. choose one · optional
- Will you now or in the future require sponsorship for employment visa status (for example, H-1B visa status)? choose one
- Have you entered into a non-disclosure or non-compete agreement or understanding of any kind? choose one
- Have you worked at Accenture in the past? choose one
- How did you hear about us? choose one
- Do you hold a security clearance? choose one
- At your current employer, are you currently working on a project with Accenture or have you worked on a project with Accenture in the past 24 months? choose one
- Are you a current employee of the U.S. Government (including U.S. Congress or military) or any state or local government? This includes entities owned or controlled by the U.S. Federal Government, such as Amtrak, the United States Postal Service, and USAID (see list of exceptions below). NOTE: answer yes if you have accepted the “Fork-in-the-Road” offer, separated with a Deferred Retirement Plan, or are on administrative leave pending separation from the Government. choose one
- Will you be serving as enlisted personnel in either the Reserves or the National Guard while working for AFS? choose one
- Were you an employee of the U.S. Government (including U.S. Congress or military) or any state or local government within the past 10 years? This includes entities owned or controlled by the U.S. Federal Government, such as Amtrak, the United States Postal Service, and USAID (see list of exceptions below). choose one
- Do you have any family members or people you have close relationships with who work for Accenture Federal Services? choose one
- If yes, please list the full name of the employee(s) and your relationship to them. optional
- Affirmation choose one