Cybersecurity Incident Manager Day (Day Shift)
Job Description
Triangle Cyber, LLC is seeking an onsite Cybersecurity Incident Manager (Day Shift) to support a large federal client with CND incident triage and reporting-aligned incident management.
Responsibilities
- Conduct Computer Network Defense (CND) incident triage, including determining scope, urgency, and potential impact
- Correlate incident data to identify trends across reported incidents
- Recommend and apply defense-in-depth principles and practices (e.g., defense in multiple places, layered defenses, security robustness)
- Research and compile known resolution steps and workarounds to support enterprise mitigations for potential CND incidents
- Apply cybersecurity concepts to detect and defend against intrusions affecting both small and large-scale IT networks, including cursory analysis of log data
- Monitor external data sources to stay current on CND threat conditions and assess which issues may impact the enterprise
Requirements
- Active Top Secret clearance
- At least five (5+) years of directly relevant experience in cyber incident management or cybersecurity operations
- Bachelor of Science (or higher) in Computer Science, Cybersecurity, Information Technology, or a related degree; or High School Diploma with at least four (4) years of hands-on incident management or cybersecurity experience
- Residency within 60 miles of Arlington, VA and willingness to work onsite, Monday through Friday (Day Shift)
- Knowledge of incident response and handling methodologies
- Knowledge of NIST 800-62 (latest revision) and FISMA standards as they relate to incident reporting
- Knowledge of the National Cyber Incident Scoring System to prioritize incident triage
- Knowledge of general attack stages, including: footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, and covering tracks
- Ability to recognize and categorize types of vulnerabilities and associated attacks
- Knowledge of basic system administration and operating system hardening, plus CND policies, procedures, and regulations
- Knowledge of different operational threat environments, including: first generation (script kiddies), second generation (non nation-state sponsored), and third generation (nation-state sponsored)
- Knowledge of system and application security threats and vulnerabilities, including: buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, and malicious code
Preferred
- Knowledge of different operational threat environments (first generation, second generation, third generation)
- Knowledge of system and application security threats and vulnerabilities (buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code)
- GIAC certifications: GCIH, GCFA, GISP, GCED
- (ISC)2 certification: CCFP (retired)
- (ISC)2 certification: CISSP