M3
Cybersecurity Incident Response Analyst II
Merit 321
๐บ๐ธ United States
On-site
Manager or above
9 months ago
- Incident Response
- NIST
- CISA
- Azure
- AWS
- GCP
- GCIH
- GCIA
- CISSP
9 months ago
Location: [On-site - Bethesda, MD
Position Overview
The Tier 2 Cybersecurity Incident Response Analyst provides advanced incident response support for NIH enterprise and cloud environments. This role responds to hotline-reported incidents and performs investigation, containment, and recovery activities in accordance with NIH policies, HHS requirements, NIST standards, and Client CISA guidance.
Key Responsibilities
- Respond to and manage incidents reported through the NIH cybersecurity hotline
- Log, categorize, investigate, and escalate incidents per NIH procedures
- Perform Tier 2/3 incident response across on-premises and cloud environments (Azure, AWS, GCP)
- Conduct forensic analysis, threat hunting, and log correlation
- Coordinate response activities with NIH stakeholders and service providers
- Develop executive summaries for significant incidents and third-party events
- Develop and maintain incident response playbooks, SOPs, and KB documentation
- Support annual updates to the NIH Incident Response Plan
- Contribute to incident response maturity assessments and improvement roadmaps
- At least 3 years of cybersecurity incident response experience
- Bachelor' degree in related field
- Experience supportingfederal, NIH, HHS, or healthcare environments
- Working knowledge of:
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-61 Rev. 2
- NIST SP 800-53 Rev. 5 (IR, AU, SI, CA families)
- Client CISA guidance
- Hands-on experience responding to incidents in cloud environments
- Strong written communication skills, including executive-level reporting
- Experience developing or maintaining incident response playbooks
Cybersecurity Incident Response Analyst II ยท Merit 321