Operations Security Advisor/Cybersecurity Incident Response Engineer, Sr
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts for enterprise networks and mission-critical systems, owning the technical direction and coordination of high-impact events in a highly regulated environment. This role applies ITIL-aligned incident management principles to structure major incident handling while maintaining deep technical focus on threat containment and eradication. It also drives proactive cybersecurity initiatives, including automation, custom scripting, and advanced defensive engineering, to strengthen the organizationās ability to prevent, detect, and rapidly respond to sophisticated adversarial tactics., * Lead major incident bridges and war rooms, orchestrating technical teams, tracking actions, and making time-critical decisions to restore service and mitigate business risk.
- Integrate ITIL incident and major incident management practices with technical response workflows, ensuring disciplined prioritization, communication, and closure.
- Design and optimize incident detection and response processes, including playbooks, escalation paths, and automation, to improve consistency, speed, and quality of response.
- Build automation, orchestration, and custom scripting solutions to reduce manual workload, enhance triage and response, and streamline containment and eradication actions.
- Perform advanced threat and forensic analysis of endpoint, network, identity, and cloud data to understand attacker objectives, lateral movement, and persistence mechanisms.
- Partner with problem management and change management functions to translate incident findings into long-term corrective actions, configuration changes, and risk-reducing initiatives.
- Define and track incident metrics such as MTTR, MTTD, incident volume, and recurrence, using data to identify systemic weaknesses and to brief leadership on operational risk.
- Provide technical and procedural coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation quality, and stakeholder communication., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASMās overall compensation and benefits package for employees.
Requirements
- 8+ years of progressive IT and cybersecurity experience with significant responsibility for incident response and major incident leadership.
- Bachelorās degree in IT, Cybersecurity , Computer Science, Business Administration, or a related field, or equivalent work experience.
- Strong understanding of ITIL principles and incident management best practices, including experience with major incident processes.
- Proficiency with incident management and service management tools integrated with security operations.
- Excellent problem-solving, analytical, communication, and interpersonal skills with demonstrated ability to manage multiple simultaneous incidents.
- Candidates must possess a current secret security clearance., * Demonstrated leadership of ITIL-based major incident processes in large enterprises, including executive and customer-facing communications.
- Strong experience with enterprise incident management tools and service management platforms integrated with SOC and cyber defense functions.
- Certifications such as ITIL Foundation plus advanced cybersecurity or incident response credentials evidencing both service management and deep technical capability.
- At least one cybersecurity-related professional certification - or the ability to obtain one within one year of hire - such as Security+, CySA+, GSEC, CEH, GCIA, GCIH, CISM or another industry-recognized equivalent., The physical requirements described in āKnowledge, Skills and Abilitiesā above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, ālight office dutiesā or ālifting up to 50 poundsā or āsome travelā required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
About the company
ASM Research, An Accenture Federal Services Company
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology
Is Software Engineering Over-Saturated?