Incident Response (IR) Manager

Edgewater Federal Solutions, Inc.

$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of leadership experience in comprehensive cybersecurity operations.
  • Bachelor's degree in a relevant cybersecurity-related field.
  • Expert-level knowledge in Incident Response (IR) concepts and operations.
  • Expert-level knowledge in Forensics concepts and operations.
  • Proficient with ticket management tools and practices, as well as computer networking and operating systems.
  • Demonstrated technical aptitude and analysis skills for solving complex cybersecurity problems.

Responsibilities

  • Lead and manage a team of approximately 20 cybersecurity specialists in incident response and forensics.
  • Oversee planning, management, and reporting metrics for the IR team.
  • Ensure timely and accurate delivery of contract deliverables and ad-hoc reports.
  • Support the client's incident response capabilities with policies and guidelines.
  • Coordinate Tier-1 cybersecurity detection and response operations for monitoring and mitigation of security incidents.
  • Manage forensics services for various platforms, and support insider threat investigations.
  • Enable continuous improvements in incident response capabilities for federal leadership.

Benefits

  • Opportunity to lead and mentor a skilled cybersecurity team.
  • Dynamic work environment focused on federal cybersecurity challenges.
  • Direct involvement in enhancing incident response capabilities.
  • Access to comprehensive training and development opportunities.
  • Possibility of working with advanced cybersecurity tools and technologies.
Full Job Description
Overview

Edgewater Federal Solutions is currently seeking a Incident Response (IR) Manager to provide IR leadership, management, and support to an Incident Response team comprised of IR Tier-1, IR Tier-2, and Forensics specialists on a Federal government contract. This role will also serve as the "Right-of-Boom" Deputy to the Cybersecurity Operations Task Lead.

Responsibilities

  • Provide oversight, leadership, management, work assignment, organization, and administrative duties for a combined team of around 20 cyber security specialists specializing in Incident Response and Forensics.
  • Provide robust operational management, planning, oversight, metrics, and reporting for the IR team and support audits, assessments, and capability maturity efforts in various tools including Microsoft SharePoint, Excel, PowerPoint, Power Automate, and Power BI.
  • Ensure the complete, accurate, and timely delivery and/or maintenance of all relevant contract Deliverables and ad hoc work products including briefings, artifacts such as strategy documentation, playbooks, incident tickets and reports, after action reports, shift change and daily mitigation reports, chain of custody forms, forensics reports, shift schedules, and select ad hoc reports and executive briefings as required.
  • Ensure the IR team supports the Client's incident response (IR) capabilities including incident response policy, plan, process, procedures, guidelines for communications, team structure, relationship management between incident response teams, service creation or enhancement with scope definitions, on-going training needs and documentation creation and maintenance.
  • Ensure the IR team provides Tier-1 cybersecurity detection and response operational support to identify and respond to potentially malicious, misuse and abuse of anomalous activities across the Client's operating environments, including initial detection, identification, triage, and mitigation of security related incidents impacting the confidentiality, integrity and availability of the Client's network and systems.
  • Ensure the IR team provides Tier-1 cybersecurity detection and response operational support to identify and accurately categorize cyber security incidents, integrate, and utilize other NIH enterprise security capabilities, support threat mitigation techniques and incident response, minimize ticket/incident backlog in NIH ticketing systems, and notify appropriate authorities of incidents and their severity within established timeframes and guidelines.
  • Ensure the IR team provides Tier-2 and Forensics. This also includes counterintelligence/insider threat support and research and development.
  • Ensure the contract team provides forensics services to the Client, including host and appliance based, mobile devices, network, cloud, and malware forensics.
  • Ensure the contract team provides Counterintelligence (CI) and Insider Threat (InTh) services to the Client, including internal investigations, law enforcement investigations, and active monitoring.
  • Proactively enable, coordinate, collaborate, integrate, and recommend on-going improvements for IR capabilities and provide guidance to Federal (Client) leadership.


Qualifications

  • 5+ years' experience comprehensive cybersecurity operations leadership and management.
  • Bachelor's Degree or higher in relevant cybersecurity-related major.
  • Demonstrated expert-level delivery experience and knowledge of IR concepts, operations, outputs, and maturity levels.
  • Demonstrated expert-level delivery experience and knowledge of Forensics concepts, operations, outputs, and maturity levels.
  • Demonstrated expert-level delivery experience and knowledge of ticket management tools and practices; troubleshooting; investigations; computer networking; and operating systems.
  • Demonstrated expert-level technical ability/aptitude, demonstrated through prior technical experience and accomplishment.
  • Excellent critical thinking, analytic skills, and experience.
  • Excellent time management skills and experience.
  • Excellent management, teamwork, and interpersonal skills against difficult due dates and timelines.
  • Excellent customer service focus to meet the needs of internal and external customers.
  • Excellent presentation development and delivery skills.
  • Excellent program management, project management, and task tracking skills.
  • Ability to work on occasional weekends and holidays.
  • Ability to pass an HHS Tier-2 security clearance background investigation.

Desired:
  • One or more certifications in information security (such as CISSP, CISM, CompTIA Advanced Security Practitioner, CompTIA Security Analytics Expert, CCTHP, CySA+, Security+, etc.).
  • Project Management Certifications (such as CAPM, PMP, ITIL etc.).
  • Current Security clearance

Salary: $120K - $145K

Similar Jobs

More Jobs at Edgewater Federal Solutions, Inc.

More Information Technology Jobs

Find similar Incident Response (IR) Manager jobs: