-
Incident Response Lead
- CACI International (Washington, DC)
-
Incident Response Lead
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: Top Secret
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local
* * *
The Opportunity:
Are you ready to play a crucial role in safeguarding our nation's maritime interests? We're seeking a dedicated Incident Response Lead to join our team supporting the United States Coast Guard (USCG). In this position, you will work with the USCG Cyber Command, and/or any other pertinent parties (to include external vendors) at any USCG location to recover from any incident.
+ **Work Schedule:** Currently Hybrid (3 days onsite)
+ **Location:** Washington D.C.
Responsibilities:
_As the Incident Response Lead, you will be responsible for the following:_
• Manage a team of Incident Response Analysts. Includes personnel development, quarterly personnel assessments, bi-monthly timekeeping tasks, and oversight of team’s daily/weekly/monthly tasks.
• Assist NOSC Project Manager with presentation deck and brief Monthly Status Reviews (MSR) to program and client leadership monthly.
• Provide Weekly Status Review (WSR) inputs to NOSC PM.
• Create and maintain strong client relationship.
• Hands-on involvement in gathering artifacts or recovering systems.
• For any incident requiring a response team to be deployed shall be able to deploy within 72 hours of notification. On instances where it is not possible to deploy, support will usually be done via phone and email, or, in rarer cases, remote system access.
• Coordinate with external service providers, USCG system owners, system administrators, and Information System Security Officers (ISSOs), as appropriate.
• Maintain a set of Government furnished portable vulnerability assessment, digital media analysis, and malware analysis tools to support deployment missions, to be used for critical incident response efforts and in response to high priority initiatives determined by USCG Cyber Command leadership.
• Contribute to Incident Assessment and Response Report deliverable.
Qualifications:
_Required:_
• Minimum of 7 years of related experience.
• Active Top Secret with SCI eligibility.
• BA/BS degree or equivalent years of relevant experience.
• Certifications: IAT III, CND and CSSP-IR.
• Subject matter expertise in at least one of the following areas: Cyber Threat Hunting, Malware Analysis & Reverse Engineering, Cyber Threat Intelligence, Digital Forensics & Incident Response.
• Previous experience working in a Cyber Security Operations Center.
• Experience with using a SIEM platform.
• Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, email security, endpoint security, network security, Windows/Linux/macOS systems, cyber threat hunting, malware analysis tools and techniques, cyber threat intelligence, common threat actor TTPs, application security concepts, cloud security fundamentals.
• Knowledge of incident response and handling methodologies.
• Knowledge of the NCCIC National Cyber Incident Scoring System to be able to prioritize triaging of incident.
• Knowledge of general attack stages and skilled in recognizing and categorizing types of vulnerabilities and associated attacks.
_Desired:_
• Experience with using a scripting language such as Python or PowerShell for task automation or tool creation is desirable.
-
________________________________________________________________________________________
What You Can Expect:
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.
An environment of trust.
CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
A focus on continuous growth.
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.
**Your potential is limitless.** So is ours.
Learn more about CACI here. (https://careers.caci.com/global/en/life-at-caci)
________________________________________________________________________________________
**Pay Range** : There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here (https://careers.caci.com/global/en/employee-benefits) .
The proposed salary range for this position is:
$86,600 - $181,800
_CACI is_ _an Equal Opportunity Employer._ _All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any_ _other protected characteristic._
-
Recent Searches
- Business Analytics Lead SQL (Pennsylvania)
- Receiver Material Control (Texas)
- Full Stack NET Developer (Pennsylvania)
- Chief Infrastructure Automation Engineer (Minnesota)
Recent Jobs
-
Incident Response Lead
- CACI International (Washington, DC)
-
Engineering Project Coordinator
- Aston Carter (Wilmington, NC)
-
Program Manager
- DCCA (College Park, MD)
-
Technical Program Manager
- Zoom (San Jose, CA)