Incident Responders
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+17 more
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired with 8+ years of experience or Master’s degree with 6+ years of experience. Additional experience may be considered in lieu of a degree.\n
- Active TS/SCI security clearance in DISS .\n
- Extensive experience in the Computer Network Defense (CND) discipline.\n
- Significant professional experience monitoring, analyzing, and investigating alerts generated by cybersecurity tools.\n
- Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.\n
- Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.\n
- Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.\n
- Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.\n
- Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.\n, * Must possess one of the following active certifications: CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, CEH, FITSP O, GIAC GMON, GIAC GRID, GIAC GCIA, GIAC GCIH, GIAC GICSP, GIAC GCED, GIAC GDSA, GIAC GSEC, CFR, or Cisco CyberOps.\n
Benefits & conditions
nTraining Schedule: For approximately the first two months of employment, \nboth selected candidates will be required to work a full-time training schedule during the day shift, Monday through Friday. Candidates must be available to work full time during this schedule for the entire initial training period.\n \n \nRegular Weekend Schedule: Following completion of training, one Incident Responder will transition to the \nWeekend Day Shift, 0730 to 1930, and one Incident Responder will transition to the \nWeekend Night Shift, 1930 to 0730. Occasional additional or alternate shift coverage may be required to support team coverage, employee leave, or other program and staffing needs.\n \n \nPrimary Responsibilities\n \n \n
- Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.\n
- Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.\n
- Receive and respond to incident notifications from customers via telephone and email.\n
- Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.\n
- Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.\n
- Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.\n
- Maintain detailed and accurate incident documentation and timelines throughout the response process.\n
- Participate in incident response meetings, briefings, and after action reviews.\n
- Support the execution and evaluation of annual security exercises.\n
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…