Cybersecurity Incident Manager Day (Day Shift)

Triangle Cyber, LLC

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret security clearance
  • 5+ years of experience in cyber incident management or operations
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field, or equivalent experience
  • Proximity to Arlington, VA (within 60 miles) and availability to work on-site, day shift
  • Familiarity with incident response methodologies
  • Understanding of NIST 800-62 and FISMA standards
  • Knowledge of the National Cyber Incident Scoring System for triaging incidents
  • Ability to recognize and categorize vulnerabilities and attacks

Responsibilities

  • Perform incident triage to assess scope, urgency, and impact of CND incidents
  • Correlate incident data to identify trends
  • Recommend and apply defense-in-depth security practices
  • Compile resolution steps for incident mitigation
  • Apply cybersecurity concepts to detect and defend against intrusions
  • Monitor external data sources for relevant CND threat conditions

Benefits

  • Onsite incident management support
  • Collaboration with a large federal client
  • Opportunity to work in a dynamic cybersecurity environment
  • Engagement in critical incident management tasks
  • Access to ongoing professional development and training opportunities
Full Job Description
Triangle Cyber is seeking a Cybersecurity Incident Manager (Day Shift) to provide onsite incident management support for a large federal client.
What You'll Do
  • Perform Computer Network Defense (CND) incident triage to include determining scope, urgency, and potential impact
  • Correlate incident data to identify specific trends in reported incidents
  • Recommend defense-in-depth principles and practices (i.e., Defense in Multiple Places, layered defenses, security robustness, etc.)
  • Research and compile known resolution steps or workarounds to enable mitigation of potential CND incidents within the enterprise
  • Apply cybersecurity concepts to the detection and defense of intrusions into small and large-scale IT networks, and conduct cursory analysis of log data
  • Monitor external data sources to maintain currency of CND threat conditions and determine which security issues may have an impact on the enterprise
Required
  • Must have an active Top Secret clearance
  • Must have at least five (5+) years of directly relevant experience in cyber incident management or cybersecurity operations
  • Must have a Bachelor of Science (or higher) in Computer Science, Cybersecurity, Information Technology, or a related degree, or a High School Diploma with at least four (4) years of hands-on incident management or cybersecurity experience
  • Must reside within 60 miles of Arlington, VA, and be willing to work on-site, Monday through Friday (Day Shift).
  • Must have knowledge of incident response and handling methodologies
  • Must have knowledge of NIST 800-62 (latest revision), and FISMA standards as they pertain to reporting incidents
  • Must have knowledge of the National Cyber Incident Scoring System to be able to prioritize triaging of incident
  • Must have knowledge of general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)
  • Must have skill in recognizing and categorizing types of vulnerabilities and associated attacks
  • Must have knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations
  • Must have knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
  • Must have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
Preferred
  • Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
  • GIAC - GIAC Certified Incident Handler (GCIH)
  • GIAC - GIAC Certified Forensic Analyst (GCFA)
  • GIAC - GIAC Information Security Professional (GISP)
  • GIAC - GIAC Certified Enterprise Defender (GCED)
  • (ISC)² - Certified Cyber Forensics Professional (CCFP) (retired)
  • (ISC)² - Certified Information Systems Security Professional (CISSP)

Similar Jobs

More Jobs at Triangle Cyber, LLC

More Information Technology Jobs

Find similar Cybersecurity Incident Manager Day (Day Shift) jobs: