Location work will be performed: NCO024 – Morrisville Remote
Job Description: Incident Response Coordinator IV Responds to crisis or urgent situations within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches, as needed, to maximize survival of life, preservation of property, and information security.
Must demonstrate a solid understanding of cyber security analysis, incident response, incident handling, and a proven an incident response team. Experience with Splunk, Sentinel One, Armis, SNA preferred.
Duties:
Support the development of staff schedules and staffing forecasts for approval.
Ensure shift members follow the appropriate incident escalation and reporting procedures.
Provides support promptly and efficiently through front-line telephone and email communications.
Ingest, triage, prioritize, assign, track, document, and manage incidents and results
Provide technical support in response to computer security incidents
Correlate, map, and fuse any and all incident information for the development and distribution of cyber alerts and notices, or other products as Required
Document technical details of current or potential intruder threats consistent with NIST 800-61: Computer Security Incident Handling Guide. Must be flexible and able to work within a 24X7X365 support environment.
Manage information, requests, that may be considered out of the scope of the incident management service and route appropriately
Coordinate, communicate, share information, and work closely with Client components
Assist with developing and maintaining Standard Operating Procedures
EXPERIENCE LEVEL:
8+ years of experience in computer forensics or vulnerability analysis
8+ years of experience in information security, especially in an
8+ incident response role
1 year experience as a certified investigator
EDUCATION:
Must posses a minimum of a Bachelors Degree or Masters Degree, PhD or JD in a technical specialty such as cyber security, computer science, management information systems or related IT field (Master's Degree Preferred)
CERTIFICATIONS: (One or more required)
Certified Investigator
CISSP
GCIH
GPEN
Additional Provisions:
Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
Once candidate’s resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
All candidates must be a US Citizen or permanent status Green Card holder.
Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.) • All overtime must be pre-approved in writing by the client manager or his/her designated representative.
Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.