Monitor, analyze, investigate, and respond to cybersecurity events, alerts, and incidents affecting enterprise networks, systems, applications, and data in accordance with established Incident Response procedures.
Perform proactive threat hunting and cybersecurity analysis utilizing SIEM platforms, IDS/IPS, system logs, packet captures, forensic tools, and threat intelligence to identify malicious activity and emerging threats.
Conduct incident triage, root cause analysis, containment, eradication, recovery, and post-incident reporting while ensuring compliance with established Standard Operating Procedures (SOPs) and Tactics, Techniques, and Procedures (TTPs).
Develop, tune, and maintain cybersecurity detection capabilities, including SIEM correlation rules, IDS/IPS signatures, and other defensive security countermeasures.
Perform malware analysis and support forensic collection, preservation, and analysis of digital evidence.
Prepare incident reports, After Action Reports (AARs), lessons learned documentation, and operational metrics.
Coordinate cybersecurity incident reporting, escalation, and notifications with government stakeholders.
Support cybersecurity readiness through tabletop exercises, continuous process improvement, and cybersecurity awareness training.
Top Secret security clearance with SCI eligibility.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical discipline.
Five (5) or more years supporting Cyber Network Defense (CND), SOC, Incident Response, or Defensive Cyber Operations.
Two (2) or more years of performing incident investigation, root cause analysis, and network or system log analysis.