Triangle Cyber is seeking a Cybersecurity Incident Manager (2nd Shift) to provide onsite incident management support for a large federal client.
What You'll Do- Perform Computer Network Defense (CND) incident triage to include determining scope, urgency, and potential impact
- Correlate incident data to identify specific trends in reported incidents
- Recommend defense-in-depth principles and practices (i.e., Defense in Multiple Places, layered defenses, security robustness, etc.)
- Research and compile known resolution steps or workarounds to enable mitigation of potential CND incidents within the enterprise
- Apply cybersecurity concepts to the detection and defense of intrusions into small and large-scale IT networks, and conduct cursory analysis of log data
- Monitor external data sources to maintain currency of CND threat conditions and determine which security issues may have an impact on the enterprise
Required- Must have an active Top Secret clearance
- Must have at least two (2+) years of directly relevant experience in cyber incident management or cybersecurity operations
- Must have a Bachelor of Science (or higher) in Computer Science, Cybersecurity, Information Technology, or a related degree, or a High School Diploma with at least four (4) years of hands-on incident management or cybersecurity experience
- Must have knowledge of incident response and handling methodologies
- Must have knowledge of NIST 800-62 (latest revision), and FISMA standards as they pertain to reporting incidents
- Must have knowledge of the National Cyber Incident Scoring System to be able to prioritize triaging of incident
- Must have knowledge of general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)
- Must have skill in recognizing and categorizing types of vulnerabilities and associated attacks
- Must have knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations
- Must have knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
- Must have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
Preferred- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
- GIAC - GIAC Certified Incident Handler (GCIH)
- GIAC - GIAC Certified Forensic Analyst (GCFA)
- GIAC - GIAC Information Security Professional (GISP)
- GIAC - GIAC Certified Enterprise Defender (GCED)
- (ISC)² - Certified Cyber Forensics Professional (CCFP) (retired)
- (ISC)² - Certified Information Systems Security Professional (CISSP)