Incident Response Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Incident Response Lead (Cybersecurity): Provide real-time analysis and triage of security events, conduct threat hunting, and perform post-incident root cause analysis with an accent on digital forensics, malware reverse engineering, and cyber threat intelligence application. Focus on automating response tasks through scripting, recommending cyber defenses, and contributing to policy development and team training.
Location: 100% Remote / Hybrid Model (US-based company with Mid-Atlantic region focus)
Company
Veteran-owned small business providing cybersecurity services to government customers, recognized as Best Places to Work and on Inc. 5000 list for fastest growth.
What you will do
- Perform real-time triage and analysis of security events from endpoints, EDR, firewalls, and servers to contain and remediate threats.
- Conduct threat hunting, malware analysis, and forensic evidence collection including system imaging and network traffic analysis.
- Analyze cyber threat intelligence to enhance defensive measures and support ESOC initiatives.
- Develop automation scripts for tasks like data parsing and contribute to post-incident lessons learned and security improvements.
- Recommend cyber defense tools, refine data policies, and support training for team skill development.
Requirements
- Bachelor's Degree in Computer Science, IM, IT, Engineering or equivalent + 6 years technical experience, or 4 years senior management in IT solutions.
- CISSP certification required; GIAC Incident Handler, Intrusion Analyst, CEH, or similar.
- PMP, ITIL 4 Foundation preferred.
- 10 years enterprise IT experience, last 5 years on large government BPAs/contracts.
- Experience with log analysis, scripting, threat intelligence, and forensic procedures.
Culture & Benefits
- Competitive salary paid twice monthly with 401k matching 100% on first 4%.
- 100% company-covered medical premiums, plus paternity/maternity leave.
- 3 weeks PTO + 11 paid holidays, cell phone and home internet reimbursements.
- Training and certification investments, plus incentives for contributions like white papers and webinars.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →