Senior-Level Cybersecurity Position | Top Secret Clearance Required | On-SiteWe are seeking a Senior Incident Response & Forensics Lead for a hands-on cybersecurity position responsible for managing a team while personally performing investigations, analysis, and responses to cyber incidents.
This role provides technical support across multiple areas of cybersecurity, including cloud security, endpoint security, access management, secure networking, and incident response.
The successful candidate will have demonstrated experience in cyber incident investigation and forensics, with a background in incident handling and forensics that has matured into mid-level project management responsibilities. This is an opportunity for an experienced cybersecurity professional to combine strong technical expertise with team leadership, customer coordination, briefings, and incident response management.
The ability to work on-site is required, and an active Top Secret clearance is required.
Key Responsibilities:Responsibilities include, but are not limited to:
- Manage the day-to-day operations of the team.
- Perform briefings and provide direct coordination with the customer.
- Develop responses to cybersecurity incidents for presentation to upper Federal leadership.
- Perform hands-on investigations, analysis, and response to cyber incidents.
- Collect intrusion artifacts, including source code, malware, trojans, and other relevant artifacts, and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
- Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
- Coordinate incident response functions.
- Provide technical support in cybersecurity areas including:
- Cloud security
- Endpoint security
- Access management
- Secure networking
- Incident response
- Monitor external data sources, including cyber defense vendor sites and Computer Emergency Response resources, for information relevant to cyber defense and incident response activities.
Required Experience & SkillsThe successful candidate will have:
- Active Top Secret security clearance.
- Demonstrated experience with cyber incident investigation and forensics.
- Experience in incident handling and incident response.
- A background in incident handling and forensics that has matured into mid-level project management experience.
- Experience managing the day-to-day operations of a technical team.
- Experience performing investigations, analysis, and responses to cyber incidents.
- Experience providing technical cybersecurity support in cloud security, endpoint security, access management, secure networking, and incident response.
- Experience performing customer briefings and direct customer coordination.
- Experience developing cybersecurity incident responses for upper Federal leadership.
- Experience collecting and analyzing intrusion artifacts, including source code, malware, and trojans.
- Experience coordinating and providing expert technical support to enterprise-wide cyber defense technicians.
- Experience coordinating incident response functions.
- Experience monitoring external cybersecurity data sources, including cyber defense vendor sites and Computer Emergency Response resources.
CertificationsCandidates should have experience or demonstrated expertise supported by one or more of the following cybersecurity certifications:
- GCFE - GIAC Certified Forensic Examiner
- GCIH - GIAC Certified Incident Handler
- CySA+ - CompTIA Cybersecurity Analyst
Forensics & Investigation ToolsExperience with Magnet / Graykey and EnCase / Cellebrite tooling is an important value add for this position.