Incident Response and Forensics Lead

ClearFocus Technologies

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in cybersecurity or incident response
  • Bachelor's degree; associate degree plus 3 years of experience accepted
  • Certified in forensics or incident handling (GCFE, GCIH or CySA)
  • Proficient with forensic tools like Magnet, Graykey, Encase, or Cellebrite
  • Strong experience in incident handling and management at a mid-level position

Responsibilities

  • Manage team operations and ensure effective incident response
  • Conduct briefings and liaise with upper Federal Leadership
  • Collect and analyze intrusion artifacts to thwart potential cyber threats
  • Provide technical support to cyber defense technicians
  • Coordinate overall incident response activities
  • Monitor external data sources for emerging cyber threats

Benefits

  • Full-time onsite role for immersive experience
  • Tailored support in advanced cyber security practices
  • Opportunity for leadership in a critical federal context
  • Collaboration with federal leadership enhancing visibility in cybersecurity
  • Access to cutting-edge forensic tools and technologies
Full Job Description
We are seeking an Incident Response and Forensics Lead for an opportunity that is 100% onsite in Germantown, Maryland

Incident Response & Forensics Lead: 'This is a hands-on role, responsible for managing a team and performing investigations, analysis, and responses to cyber incidents.This person must be able to work on-site .This role provides technical support in areas of cyber security to include cloud security, endpoint security, access management, secure networking and incident response. We need someone with cyber incident investigation and forensics experience (GCFE, GCIH or CySA); experience with Magnet / Graykey and Encase / Cellebrite tooling is an important value add.The ideal candidate will have a background in incident handling and forensics that has been matured into a mid-level PM.

Responsibilities include, but are not limited to:
  • Manage day to day operations of the team
  • Perform briefings, direct coordination with the customer, develop responses to incidents to upper Federal Leadership
  • Collect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
  • Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
  • Coordinate incident response functions.
  • Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response
  • Cybersecurity Operations, Security Risk Assessment
  • 7+ years of related experience with a bachelor or higher degree or an additional 3 years of experience can be substituted with an associate degree
Clearance:
  • Active Top Secret clearance, Q clearance processing

Similar Jobs

More Information Technology Jobs

Find similar Incident Response and Forensics Lead jobs: