Your role and responsibilities
As a Cyber Defender, you will play a vital role in safeguarding an organization's digital infrastructure by identifying, analyzing, and mitigating cyber threats. This position involves using a variety of cybersecurity tools to monitor, prioritize, investigate, and respond to security incidents.
Your primary responsibilities will include:
• Conduct Event Investigations: Investigate security incidents using SIEM, SOAR, EDR, and XDR platforms, and apply industry frameworks like MITRE ATT&CK and the Cyber Kill Chain to understand and counter adversary tactics effectively.
• Manage Incident Reports: Prioritize and manage incident reports, providing actionable recommendations and responses to strengthen the client's security posture.
• Analyze Network and Endpoint Events: Interpret security tools and logs from Windows, MAC, and Linux systems to identify potential threats.
• Engage in Vulnerability Management: Participate in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats.
• Provide Actionable Recommendations: Deliver recommendations and responses to clients to enhance their security posture.
*This person will be required to come into the Fort Meade, MD office 5 days a week
Required education
High School Diploma/GED
Preferred education
Bachelor's Degree
Required technical and professional expertise
• Exposure to Cybersecurity Tools: Familiarity with a variety of cybersecurity tools, including SIEM, SOAR, EDR, and XDR platforms, to monitor, prioritize, investigate, and respond to security incidents.
• Understanding of Industry Frameworks: Knowledge of industry frameworks like MITRE ATT&CK and the Cyber Kill Chain to understand and counter adversary tactics effectively.
• Experience with Network and Endpoint Analysis: Ability to interpret security tools and logs from Windows, MAC, and Linux systems to identify potential threats.
• Exposure to Vulnerability Management: Participation in vulnerability management and cyber threat intelligence activities to identify and anticipate potential threats.
• Certification in Security Technologies: Familiarity with security technologies and certifications related to threat detection, response, and intelligence.
• Security Clearance: Active TS/SCI is required
Preferred technical and professional experience
• Familiarity with Scripting Languages: Exposure to scripting languages such as Python, PowerShell, or Bash is beneficial for automating tasks and interacting with various cybersecurity tools.
• Knowledge of Cloud Security: Understanding cloud security principles and experience working with cloud-based security solutions can be advantageous in identifying and mitigating cyber threats.
• Exposure to Threat Intelligence Platforms: Familiarity with threat intelligence platforms and feeds can aid in staying up-to-date with emerging threats and improving incident response capabilities.
OTHER RELEVANT JOB DETAILS
IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), cash balance pension plan, the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
US Citizenship Required.
The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.