1

Netwitness Jobs (NOW HIRING)

Qualifications 3+ years experience as a Cyber Security Analyst The tools we use are RSA Netwitness, enVision, QRadar and ArcSight, we'd prefer to have someone with extensive knowledge with those ...

Qualifications 3+ years experience as a Cyber Security Analyst The tools we use are RSA Netwitness, enVision, QRadar and ArcSight, we'd prefer to have someone with extensive knowledge with those ...

Familiarity with NetWitness and/or Microsoft Sentinel. * Experience with tools such as Veracode, Tenable, or Horizon3 AI. * Basic knowledge of firewalls. Work Environment This position is part of a ...

Experience with McAfee ePO, RSA Netwitness, Cisco ASA Firewall and SSM, Microsoft TMG 2010, Citrix NetScaler WAF * Log Analysis, Incident Response/Reporting, Auditing * Proven background in network ...

Be Seen First

... NetWitness, Mandiant Security Verification, and SightGain. • The Application Support Specialist and the Systems Engineer will probably be required to back each other up and backup the incumbent ...

Be Seen First

... NetWitness, Mandiant Security Verification, and SightGain. • The Application Support Specialist and the Systems Engineer will probably be required to back each other up and backup the incumbent ...

Senior Detection Engineer #3279

San Antonio, TX · On-site

$94K - $129K/yr

Strong packet capture and traffic analysis skills using tools like Corelight, NetWitness, and CRIBL to spot anomalies and lateral movement * Experience tuning EDR platforms such as CrowdStrike and ...

... NetWitness, and others. * Work with project managers, product owners, other application teams, cybersecurity personnel, and executives to inform business decisions, work collaboratively, and ...

... NetWitness, and others. * Work with project managers, product owners, other application teams, cybersecurity personnel, and executives to inform business decisions, work collaboratively, and ...

next page

Showing results 1-20

Netwitness information

What are the key skills and qualifications needed to thrive in the Netwitness position, and why are they important?

To thrive as a NetWitness Analyst, you need a solid background in cybersecurity, network analysis, and incident response, often supported by a degree in information technology or related certifications such as CISSP, CEH, or specifically RSA NetWitness certifications. Familiarity with the RSA NetWitness Platform, intrusion detection/prevention systems (IDS/IPS), security information and event management (SIEM) tools, and scripting languages is essential. Strong analytical thinking, effective communication, and attention to detail are important soft skills for success in this position. These capabilities ensure thorough threat detection, accurate forensic investigations, and strong collaboration with security teams to protect an organization's digital assets.

What are the typical day-to-day responsibilities of a NetWitness Analyst?

A NetWitness Analyst is primarily responsible for monitoring network activity, analyzing security incidents, and investigating potential threats using the RSA NetWitness Platform. On a daily basis, you will review logs and alerts, conduct deep packet inspections, and work with other security team members to respond to incidents and improve detection rules. You'll often collaborate with IT, compliance, and threat intelligence teams to address vulnerabilities and help implement proactive security measures. Staying updated on the latest cyber threats and refining response procedures are also key aspects of the role, making it a dynamic and critical position within any organization's security operations center.

What is a NetWitness job?

A NetWitness job typically involves monitoring, analyzing, and responding to cybersecurity threats using the NetWitness platform. Professionals in this role work with security information and event management (SIEM) tools, threat intelligence, and network traffic analysis to detect and mitigate cyber risks. They may also investigate security incidents, configure NetWitness solutions, and collaborate with IT and security teams to enhance an organization's cybersecurity posture. This role is common in Security Operations Centers (SOCs) and requires expertise in cybersecurity principles.

More about Netwitness jobs
What cities are hiring for Netwitness jobs? Cities with the most Netwitness job openings:
What are the most commonly searched types of Netwitness jobs? The most popular types of Netwitness jobs are:
What states have the most Netwitness jobs? States with the most job openings for Netwitness jobs include:
Infographic showing various Netwitness job openings in the United States as of July 2026, with employment types broken down into 87% Full Time, and 13% Contract. Highlights an 100% In-person job distribution.

Incident Response Analyst

Cyber Synergy Consulting Group

Washington, DC • On-site

$100K - $125K/yr

Full-time

Posted 11 days ago


Job description

Incident Response Analyst (Task 4 – Federal Cybersecurity Contract)

Location: Remote with occasional on-site (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)

We are seeking an experienced Incident Response Analyst to support Task 4 – Incident Response Management on a federal cybersecurity services contract. This role provides front-line security event triage, investigation, reporting, and coordination across multiple federal cybersecurity teams.

The ideal candidate has hands-on experience with enterprise IR tooling-CrowdStrike, FireEye (Trellix), Splunk, NetWitness, and Magnet AXIOM-and is comfortable working in a high-tempo operational environment aligned with federal cybersecurity frameworks (NIST, FISMA, OMB).


Key Responsibilities
  • Perform initial triage of security events from SIEM, EDR, NDR, and log sources, including CrowdStrike, FireEye/Trellix, Splunk, NetWitness, and related platforms.

  • Conduct incident investigations, including host and network forensics, log analysis, and evidence review using tools such as NetWitness and AXIOM.

  • Coordinate closely with HHS CSIRC, OpDiv incident response teams, system owners, and security engineering staff to validate findings and recommend containment actions.

  • Provide daily updates, SITREPs, and written documentation of incident status, investigative steps, and remediation recommendations.

  • Develop incident dashboards and knowledge base documentation within Splunk and other IR platforms.

  • Support containment, eradication, and recovery efforts aligned to federal IR procedures.

  • Participate in tabletop exercises, readiness assessments, and operational continuity testing.

  • Monitor and manage the Incident Response Team (IRT) mailbox; escalate urgent items within required SLAs.

  • Assist with audit support, evidence gathering, and post-incident reviews.

  • Contribute to continuous improvement of incident response processes and playbooks.


Required Qualifications
  • 2–5+ years of experience in cybersecurity operations, SOC analysis, or incident response.

  • Direct hands-on experience with IR tools, including:

    • CrowdStrike Falcon (EDR)

    • FireEye/Trellix (HX, Helix, or equivalent)

    • Splunk (SIEM, dashboards, search queries)

    • NetWitness (network forensics, packet analysis)

    • Magnet AXIOM (host forensics)

  • Strong understanding of adversary techniques, malware behavior, incident timelines, and forensic artifacts.

  • Familiarity with NIST 800-61, NIST 800-53, FISMA, OMB guidance.

  • Ability to clearly document investigations and communicate findings to technical and non-technical audiences.

  • Eligibility to obtain and maintain a Public Trust clearance.


Preferred Qualifications
  • Experience supporting federal agencies (HHS, DHS, DoD, DOJ, etc.).

  • Certifications such as Security+, CySA+, CEH, GCIH, GCIA, CHFI, or related.

  • Experience performing threat hunting across EDR, SIEM, and NDR tools.

  • Familiarity with packet analysis tools (Wireshark) and scripting languages (Python, PowerShell).

  • Experience with ServiceNow or similar ticketing platforms


Work Schedule & Expectations
  • Core hours: 7:00 AM – 5:00 PM EST, Monday through Friday, with the flexibility to support after-hours incidents as needed.

  • Participation in on-call rotations may be required.

  • Remote work permitted with reliable connectivity and camera-enabled participation.