Incident Response & Threat Detection Analyst

ESM•Jefferson Township, OH
•$87,000 - $104,000•Onsite

About The Position

Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cybersecurity Incident Response & Threat Detection Analyst to support an enterprise-level program within a federal environment.

Requirements

  • Knowledge of SIEM, cybersecurity monitoring tools, network traffic, and security event analysis.
  • Ability to detect, analyze, and respond to cyber threats, including APTs, indicators of compromise, and unauthorized activity.
  • Ability to apply threat intelligence, cybersecurity tools, and defense-in-depth controls to identify and mitigate network threats.
  • Knowledge of at least two types of security tools: Firewall, IDS/IPS, Host based antivirus, Data loss prevention, Vulnerability Management, Forensics, Malware Analysis, Device Hardening.
  • Ability to build scripts and tools to enhance threat detection and incident response capabilities (Preferably in SPL, Python, PowerShell).
  • Five (5) years relevant experience
  • Two (2) years performing root cause analysis of cybersecurity events and incidents.
  • Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP)
  • Top Secret clearance

Nice To Haves

  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
  • Candidate must communicate effectively with team members, team lead, management, and government customers
  • Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision

Responsibilities

  • Participates in 24x7x365 monitoring of SIEM and cybersecurity tools to detect, analyze, and respond to threats and unauthorized activity across the enterprise network.
  • Reviews security events, logs, and network traffic to identify trends, advanced persistent threats (APTs), and other indicators of compromise.
  • Uses threat intelligence and open-source intelligence (OSINT) to maintain awareness of emerging threats and inform defensive actions.
  • Provides technical analysis and sustainment support for cybersecurity tools and applications.
  • Assists with implementing defense-in-depth signatures and perimeter controls to mitigate network threats.
  • Other duties as assigned
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service