Tier 3 Incident Response Lead

Tyto Athene, LLC

$170K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree or equivalent in a relevant field
  • 8+ years of cybersecurity experience
  • 8+ years in network and endpoint investigation
  • CISSP and CEH certifications or equivalent
  • 3+ years of incident response experience
  • 3+ years with SIEM systems
  • 2+ years of Endpoint Detection Response (EDR) experience
  • Proficiency in open-source forensic tools and suites
  • Understanding of scripting languages like Python.

Responsibilities

  • Lead investigations of high-priority cybersecurity incidents
  • Analyze security alerts using security tools
  • Monitor customer environments for adversarial activity
  • Identify root causes and impact of incidents
  • Collaborate with threat hunting and intelligence teams
  • Act as the primary contact for law enforcement and third-party vendors
  • Conduct post-incident analysis to identify improvements
  • Develop and tune detection rules for security monitoring
  • Document findings in the SOC's Incident Management System
  • Research emerging threats to improve preventive measures

Benefits

  • Health/Dental/Vision coverage
  • 401(k) matching
  • Paid Time Off
  • Short-Term and Long-Term Disability Insurance
  • Life Insurance
  • Referral Bonuses
  • Professional development reimbursement
  • Parental leave
Full Job Description
Description

Tyto Athene is searching for a Tier 3 Incident Response Lead. You will play a critical role in conducting in-depth analyses and responding to incidents from cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for other analysts, helping guide them through more complex and high-priority incidents.

Responsibilities:
  • Lead cross-functional teams to perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize security tools to analyze, investigate, and triage security alerts
  • Coordinate the monitoring of our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Utilize advanced tools, such as digital forensics or malware analysis capabilities, to identify incidents' root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Serve as the primary incident point of contact with law enforcement, third-party vendors, and other external parties
  • Conduct post-incident analysis and lessons learned to identify improvement opportunities
  • Develop or tune detection rules or signatures to improve the effectiveness of security monitoring and collaborate with engineering teams to implement them
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research on emerging threats and vulnerabilities to aid their prevention and mitigation
  • Assist in developing and implementing initiatives that will enhance the SOC's performance (e.g., SOPs, playbooks, capability deployments)
  • Escalate SOC performance issues or risks to management
  • Provide guidance and mentorship to Tier 1 and Tier 2 SOC Analysts to enhance their skills and capabilities


Qualifications

Required:
  • Bachelor's Degree or an equivalent combination of formal education and experience in relevant field.
  • 8 or more years of cyber security experience.
  • 8 or more years of experience in investigating network and endpoint architecture
  • CISSP and CEH certifications or equivalent.
  • 3 or more years of incident response experience.
  • 3 or more years of SIEM experience.
  • 2 or more years of Endpoint Detection Response (EDR) experience.
  • Demonstrated competency in opensource industry standard forensic tools and suites
  • Experience with operational security, including security operations center (SOC), incident response, malware analysis, or IDS and IPS analyses
  • Understanding of scripting languages such as Python and regular expressions

Desired:
  • CISSP - Certified Information Systems Security Professional
  • GCFA - GIAC Certified Forensic Analyst
  • GCFE - GIAC Certified Forensic Examiner
  • GREM - GIAC Reverse Engineering Malware


Location:
  • This is hybrid position with requirements to report to the client site in Washington, DC for incident support as needed


Compensation:
  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $170-180K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:
  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.


Similar Jobs

More Jobs at Tyto Athene, LLC

More Information Technology Jobs

Find similar Tier 3 Incident Response Lead jobs: