We are seeking an Incident Response and Forensics Lead for an opportunity that is 100% onsite in Germantown, MarylandIncident Response & Forensics Lead: 'This is a hands-on role, responsible for managing a team and performing investigations, analysis, and responses to cyber incidents.This person must be able to work on-site .This role provides technical support in areas of cyber security to include cloud security, endpoint security, access management, secure networking and incident response. We need someone with cyber incident investigation and forensics experience (GCFE, GCIH or CySA); experience with Magnet / Graykey and Encase / Cellebrite tooling is an important value add.The ideal candidate will have a background in incident handling and forensics that has been matured into a mid-level PM.
Responsibilities include, but are not limited to:- Manage day to day operations of the team
- Perform briefings, direct coordination with the customer, develop responses to incidents to upper Federal Leadership
- Collect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
- Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
- Coordinate incident response functions.
- Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response
- Cybersecurity Operations, Security Risk Assessment
- 7+ years of related experience with a bachelor or higher degree or an additional 3 years of experience can be substituted with an associate degree
Clearance:- Active Top Secret clearance, Q clearance processing