Back to the roster

SOC Incident Response Analyst I (6am-2pm)

Remote Full-time Hiring now

About the position We are seeking a motivated Incident Response SOC Analyst I to join our SOC team. In this entry-to-mid-level role, you will work under the guidance of senior analysts to monitor security telemetry, triage alerts, perform initial investigations, and assist with containment and remediation activities. This is an excellent opportunity to grow your skills in incident response, threat hunting, forensics, and security tooling. This is a hybrid position, candidates must reside in the DC metropolitan area and be open to working either day or evening shifts Responsibilities

  • Monitor and triage security alerts from SIEM, EDR, IDS/IPS, and other security telemetry sources.
  • Conduct initial incident validation, categorize incidents, and determine severity levels.
  • Perform basic to intermediate incident response activities, including containment, eradication, and recovery steps under supervision.
  • Gather and preserve digital evidence following standard operating procedures and chain-of-custody requirements.
  • Collaborate with IT and security teams to apply mitigations, patches, and configuration changes.
  • Document investigation steps, findings, and remediation actions in incident tickets.
  • Participate in post-incident reviews (PIR) and help develop lessons learned.
  • Respond to on-call rotations as required.
  • Expand knowledge of MITRE ATT&CK, common attack techniques, and security best practices.
  • Assist with monitoring and improving SOC processes, playbooks, and runbooks.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field
  • Minimum 1 year of professional experience in cyber incident response
  • Foundational knowledge of cyber security concepts, such as incident handling lifecycle, threat intelligence, and basic forensics.
  • Familiarity with security tools (SIEM, EDR, SOAR, threat intel feeds) and basic incident response workflows.
  • Hands-on experience with SIEM (e.g., Splunk, QRadar, ArcSight), EDR (e.g., CrowdStrike, Defender, SentinelOne), and basic SOAR concepts.
  • Experience with incident response tooling, digital forensics, and evidence handling.
  • Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, VPNs, firewalls).
  • Strong analytical and problem-solving skills with a structured, methodical approach.
  • Excellent written and verbal communication; ability to produce clear incident reports and documentation.
  • Ability to work in a fast-paced environment and participate in on-call rotations (as needed).
  • Commitment to continuous learning and professional growth in cybersecurity. Nice-to-haves
  • Relevant certifications (e.g., CompTIA Security+, CEH, SANS GCIH, GIAC GCIA, or equivalent).
  • Knowledge of MITRE ATT&CK framework and common attacker techniques.
  • Familiarity with cloud security concepts (AWS/Azure/GCP) and cloud incident response considerations.
  • Scripting or automation skills (PowerShell, Python, Bash) a plus.

Benefits

  • Growth AI-powered career tool that identifies career steps and learning opportunities
  • Support An internal mobility team focused on helping you achieve your career goals
  • Rewards Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community Award-winning culture of innovation and a military-friendly workplace
  • Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
  • We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Apply tot his job Apply To this Job

Apply To This Job

Related roles

Senior Cybersecurity Analyst (SOC) US Region (Remote / Hybrid) Cyber security Washington DC , N[...]

Remote Full-time

SOC Analyst - Hybrid/Remote in Netherlands or Germany (f/m/x)

Remote Full-time

Security Operations Center (SOC) Analyst /w EDR and Incident Handling (ONLY US Cit )

Remote Full-time

SOC Analyst / Threat Hunter

Remote Full-time

Security Analyst - Project Lead - Fully REMOTE - Must have MITRE ATT & CK framework

Remote Full-time

Experienced Data Entry Assistant – Transportation Safety and Compliance (Work From Home Opportunity)

Remote Full-time

Senior Environmental Health And Safety Manager

Remote Full-time

Safety Associate

Remote Full-time

Patient Safety Observer, Med/Surg & ED Observers- 24 hour evenings

Remote Full-time

Director of Safety & Risk Management

Remote Full-time

Experienced Data Entry Amazon Specialist - Entry-Level Part-Time Opportunity at arenaflex

Remote Full-time

Payroll Specialist - 100% Remote (TOR, ON)

Remote Full-time

Experienced Full Stack Data Scientist – Advanced Analytics and AI Development

Remote Full-time

Senior Copywriter - DTC

Remote Full-time

Workday HRIS Analyst

Remote Full-time

Support, Yardi Help Desk - REMOTE (US)

Remote Full-time

Experienced Customer Support Specialist (Night Shift) – Work From Home Opportunity at arenaflex

Remote Full-time

Licensed Clinical Social Worker - Remote

Remote Full-time

Experienced Customer Service/Sales Representative – Remote Opportunity to Revolutionize Family Benefits

Remote Full-time

Experienced Entry-Level Data Entry Specialist – Remote Data Management and Database Enhancement

Remote Full-time