Cybersecurity Analyst III (Incident Response)
Company: Washington Metropolitan Area Transit Authority
Location: Washington
Posted on: June 1, 2025
Job Description:
Cybersecurity Analyst III (Incident Response)Are you passionate
about safeguarding digital landscapes and collaborating with
top-tier professionals? WMATA is seeking a Cybersecurity Analyst
III to join our dynamic team. In this role, you will leverage your
technical expertise to identify, analyze, and mitigate security
threats, ensuring the integrity and confidentiality of our systems.
You will conduct in-depth security assessments, develop robust
security countermeasures, and collaborate with cross-functional
teams to design and deploy innovative security solutions. You will
be using state-of-the-art cybersecurity tools like Splunk,
Crowdstrike, and Varonis to enhance our security posture while
working in our Cyber Fusion Center.The Cybersecurity Analyst III
role allows you Mentorship opportunities, allowing you to share
your knowledge and experience with junior team members, fostering
their growth and development. You will also benefit from guidance
and insights from seasoned professionals, enhancing your own skills
and career trajectory.We offer a collaborative environment where
your ideas and expertise are valued, along with opportunities for
continuous learning and professional growth. With cutting-edge
tools and technologies at your disposal, you will enhance your
cybersecurity skills while enjoying a competitive compensation and
benefits package. If you're ready to take your cybersecurity career
to the next level and work alongside industry leaders, apply now
and be a part of our mission to protect and innovate!Minimum
QualificationsEducation
- A Bachelor -s degree from an accredited college or
universityExperience
- Four (4) years of experience as a cybersecurity
officer/engineer, information systems security officer, or
specialized expertise in cyber policy, intelligence, analytics,
budget, audit, metrics, or training such that it meets the specific
role postedPreferredEducation
- A Bachelor -s Degree in Computer Science, Cybersecurity or a
related technical fieldMedical Group
Satisfactorily complete the medical examination for this position,
if required. The incumbent must be able to perform the essential
functions of this position either with or without reasonable
accommodations.SummaryThe Cybersecurity Analyst III is responsible
for identifying and remediating security threats. The analyst
designs defensive measures and monitor information collected from a
variety of sources to identify, analyze, and report events that
occur or might occur within the network to protect information,
information systems and networks from threats.Essential Functions
- Provides senior level support regarding data analytics
strategies based on the National Institute of Standards and
Technology (NIST) Cybersecurity Framework. This includes analyzing
threat information from multiple sources, disciplines, and agencies
across the Intelligence Community; Synthesizing and placing
intelligence information in context; draws insights about the
possible implications. Ensures threats and vulnerabilities are
identified as early as possible and mitigated.
- Provides senior level support regarding the development of
cyber threat indicators (attacks and compromise) monitoring to
maintain awareness of the status of the highly dynamic operating
environment; Coordinates and performs the collection, processing,
analysis, and dissemination of cyber threat/warning assessments.
Ensure vulnerabilities are identified as early as possible and
mitigated.
- Provides senior level support regarding the intelligence of
data collected from a variety of cyber defense tools (e.g., IDS
alerts, firewalls, network traffic logs) to analyze events that
occur within the WMATA's environments (on-premises and cloud) for
the purposes of mitigating threats. Ensure vulnerabilities are
identified as early as possible and mitigated.
- Senior level support regarding the development of assessment
plans and measures of performance and/or effectiveness. Conducts
strategic and operational effectiveness assessments as required for
cyber events. Determines whether systems performed as expected and
provides input to the determination of operational effectiveness.
Ensures WMATA has a properly managed cyber analysis framework.
- Provides senior level support regarding the assimilation of
data and information from analytics and intelligence to support the
creation of dashboards which inform senior leaders regarding the
security posture of the organization. Generates routine and urgent
reports and action plans to support enhanced security procedures
and response measures to ongoing or imminent threats. Ensures
Washington Metropolitan Area Transit Authority (WMATA) has a
properly managed and reportable cyber threat intelligence awareness
program.
- Provides senior level support regarding the analysis of
defensive and simulated offensive results, techniques used, and
information collected from a variety of sources to identify,
analyze, and report events that occur or might occur within the
network to protect information, information systems, and networks
from threats. Ensures vulnerabilities are identified as early as
possible and mitigated.
- Provides senior level support regarding the response to routine
and urgent cybersecurity situations within the pertinent domain to
mitigate immediate and potential cyber threats. Uses mitigation,
preparedness, and response and recovery approaches, as needed, to
maximize safety, preservation of property, and information
security. Investigates and analyzes all relevant incident response
activities. To ensure real-time cyber defense incident handling
(e.g., forensic collections, intrusion correlation and tracking,
threat analysis, and direct system remediation) tasks to support
deployable Incident Response Teams (IRTs).
- Provides senior level support regarding incident response
support functions through technical activities that gather evidence
on criminal or foreign intelligence entities to mitigate possible
or real-time threats, protect against insider threats, sabotage,
international terrorist activities, or to support other
intelligence activities. Investigates, analyzes, and responds to
cyber incidents within the network environment or enclave. Ensures
the organization can respond to attacks quickly and eliminate
threats.
- Provides senior level support regarding the consultation for
the support program to establish relationships, between the
incident response team and other groups, both internal (e.g., legal
department) and external (e.g., law enforcement agencies, vendors,
public relations professionals). Ensures the organization can
respond to attacks quickly and eliminate threats.
- Provides senior level support regarding the process to apply
tactics, techniques, and procedures for a full range of
investigative tools and processes to include, but not limited to,
interviews, cyber surveillance, counter surveillance, and
surveillance detection, and appropriately balances the benefits of
intelligence gathering. Ensures vulnerabilities are identified as
early as possible and mitigated.
- Provides senior level support regarding the activities to
produce timely, fused, all-source cyber operations intelligence
and/or indications and warnings intelligence products (e.g., threat
assessments, briefings, intelligence studies, country studies).
Analyzes collected information to identify vulnerabilities and
potential for exploitation. To ensure the reporting of all cyber
events/activity are presented in a timely and actionable media;
relevant to cyber intelligence and security best practices.
- Provides senior level support regarding detailed intelligence
plans to satisfy cyber operations requirements. Collaborates with
cyber operations planners to identify, validate, and impose
requirements for collection and analysis. Participates in targeting
selection, validation, synchronization, and execution of cyber
actions. Synchronizes intelligence activities to support
organization objectives in cyberspace. To ensure the reporting of
all cyber events/activity are presented in a timely and actionable
media; relevant to cyber intelligence and security best
practices.
- Provides senior level support regarding the monitoring of all
defensive measures and information collected from a variety of
sources to identify, analyze, and report events that occur or might
occur within the network to protect information, information
systems, and networks from internal and external threats. Takes
appropriate action by reporting, remediating and/or providing
preventive recommendations being the liaison between the security
engineering and authorizing official (as needed). To ensure the
analysis of the information (data) from various sources within the
enterprise and recognize a possible security violation or
threat.
- Provides senior level support regarding the analysis to
identify, collect, examine, and preserve evidence using controlled
and documented analytical and investigative techniques. The
analysis of digital evidence and investigates computer security
incidents to derive useful information in support of system/network
vulnerability mitigation. To ensure forensically sound collection
of images and inspect to discern possible mitigation/remediation on
enterprise systems.The essential duties listed are not intended to
limit specific duties and responsibilities of any particular
position. Nor is it intended to limit in any way the right of
managers and supervisors to assign, direct and control the work of
employees under their supervision.Evaluation CriteriaConsideration
will be given to applicants whose resumes demonstrate the required
education and experience. Applicants should include all relevant
education and work experience.Evaluation criteria may include one
or more of the following:
- Skills and/or behavioral assessment
- Personal interview
- Verification of education and experience (including
certifications and licenses)
- Criminal Background Check (a criminal conviction is not an
automatic bar to employment)
- Medical examination including a drug and alcohol screening (for
safety sensitive positions)
- Review of a current motor vehicle reportClosingWMATA is an
equal opportunity employer. All qualified applicants will receive
consideration for employment without regard to race, color,
religion, sex, sexual orientation, national origin, disability,
status as a protected veteran, or any other status protected by
applicable federal law.This posting is an announcement of a vacant
position under recruitment. It is not intended to replace the
official job description. Job descriptions are available upon
confirmation of an interview.
#J-18808-Ljbffr
Keywords: Washington Metropolitan Area Transit Authority, Leesburg , Cybersecurity Analyst III (Incident Response), Professions , Washington, Virginia
Didn't find what you're looking for? Search again!
Loading more jobs...