iP-Plus Consulting, Inc. CYBERSECURITY INCIDENT RESPONSE & THREAT DETECTION ANALYST Remote · Full time

Provides 24x7x365 cybersecurity monitoring and incident response across the enterprise, leveraging SIEM, security tools, threat intelligence, and log/traffic analysis to detect, investigate, and respond to malicious or unauthorized activity. Supports the sustainment and optimization of cybersecurity tools, Defense-in-Depth capabilities, and perimeter controls to strengthen threat detection and protect the enterprise network.

About iP-Plus Consulting, Inc.

iP-Plus Consulting, Inc. is a mission-focused technology and cybersecurity services firm supporting Federal agencies across defense, logistics, and national security sectors. The company specializes in delivering cybersecurity engineering, information assurance, systems integration, and technology modernization solutions that protect critical infrastructure and enable secure mission operations.

Description

Participates in 24x7x365 monitoring of SIEM and other cybersecurity monitoring tools to detect and respond to cybersecurity threats within the Enterprise Network Environment. Performs actions to protect, monitor, detect, analyze, and respond to unauthorized activity. Employs Cybersecurity capabilities and deliberate actions to respond to specific alerts or emerging threats. Reviews logged events for trends that are indicative of attack or compromise within the environment. Actively monitors logs and traffic for Advanced Persistent Threats (APT) and "low and slow" attacks within the environment. Maintains awareness of possible threats with the use of intelligence resources which include Open Source Intelligence (OSINT). Provides technical analysis and sustainment support for the enterprise for Cybersecurity tools and applications and assists with the application of Defense-In-Depth signatures and perimeter defense controls to diminish network threats.

 

Required Qualifications:

  • 5 years relevant experience
  • 2 years performing root cause analysis of cybersecurity events and incidents.
  • Working knowledge of at least two types of security tools: Firewall, IDS/IPS, Host based antivirus, Data loss prevention, Vulnerability Management, Forensics, Malware Analysis, Device Hardening
  • Understanding of Defense-in-Depth
  • Ability to build scripts and tools to enhance threat detection and incident response capabilities (Preferably in SPL, Python, PowerShell)
  • Must possess IT-I Critical Sensitive security clearance or Tier 5 (T5)
  • Must possess a DOD TOP SECRET Clearance and be eligible for an IT-1 and be eligible for SCI access


REQ: CSSP