CIRT Tier 2 Analyst
SkyePoint Decisions
| Company | SkyePoint Decisions |
| Category | Security |
| Location | 8101 Odell Rd |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Mid |
| Salary | Not stated by the employer |
| Posted | 23 Jul 2026 |
| Last verified | 2 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results. This is a contingent position based upon customer approval.
SkyePoint Decisions is seeking a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective, and secure business processes.
This position is located in Beltsville, MD and will be onsite 5 days a week. No hybrid/telework allowed.
Work Hours: Mid Shift, 22:00– 6:00 EST, TUES-SAT.
Responsibilities:
Detect, classify, process, track, and report on cyber security events and incidents.
Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
Characterize and analyze network traffic to identify anomalous activity and potential threats.
Protect against and prevent potential cyber security threats and vulnerabilities.
Perform forensic analysis of hosts artifacts, network traffic, and email content.
Analyze malicious scripts and code to mitigate potential threats.
Conduct malware analysis to generate IOCs to identify and mitigate threats.
Collaborate with Department of State teams to analyze and respond to events and incidents.
Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
Create tickets and initiate workflows as instructed in technical SOPs.
Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
Collaborate with other local, national and international CIRTs as directed.
Submit alert tuning requests.
Required Qualifications:
Bachelor's degree and 5 years of experience.
An additional 4 years of experience may be substituted in lieu of the degree bachelors degree requirement.
Must possess or be able to obtain at least one of the following certifications before start date:
CCNA-Security
CND
CySA+
GICSP
GSEC
Security+ CE
SSCP
Continued certification is required as a condition of employment.
Demonstrated experience in the Incident Response lifecycle.
Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
Knowledge of cloud security monitoring and incident response.
Knowledge of integrating IOCs and Advanced Persistent Threat actors.
Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
Knowledge of malware analysis techniques.
Knowledge of the MITRE ATT&CK and D3FEND frameworks.
U.S. Citizenship required.
Active Secret security clearance required in order to start.
Preferred Qualifications:
Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
Knowledge of Microsoft Azure access and identity management.
Proficiency