Senior Cybersecurity Incident Response Specialist

Washington, DC, US • Posted 17 hours ago • Updated 17 hours ago
Full Time
No Travel Required
On-site
$100,000 - $120,000/yr
Company Branding Image
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Active Directory
  • Analytical Skill
  • Android
  • Artificial Intelligence
  • Auditing
  • CISA
  • Certified Ethical Hacker
  • Cisco Certifications
  • Cloud Computing
  • Cloud Security
  • Collaboration
  • Communication
  • CompTIA
  • Computer Networking
  • Computer Science
  • Cyber Security
  • DNS
  • Dashboard
  • Data Flow
  • Decision-making
  • Documentation
  • Dragon NaturallySpeaking
  • Electronic Discovery
  • Enterprise Networks
  • Event Management
  • FISMA
  • FTP
  • Firewall
  • GCIH
  • Government Contracts
  • Group Policy
  • HTTP
  • HTTPS
  • IOS Development
  • Incident Management
  • Linux
  • Machine Learning (ML)
  • Malware Analysis
  • Management
  • Mentorship
  • Microsoft
  • Microsoft Azure
  • Microsoft Office
  • Microsoft Windows
  • Military
  • Mobile Devices
  • NIST SP 800 Series
  • Network
  • Operating Systems
  • PASS
  • Professional Services
  • Python
  • Regulatory Compliance
  • Reporting
  • Research
  • Reverse Engineering
  • Routing
  • SANS
  • SAP BASIS
  • SFTP
  • SIEM
  • SMB
  • SMTP
  • Screening
  • Scripting
  • Secure Shell
  • Security Clearance
  • Security Operations
  • Security+
  • Sensors
  • Server Message Block
  • Standard Operating Procedure
  • Supervision
  • Switches
  • System On A Chip
  • Threat Analysis
  • Unix
  • VLAN
  • Vulnerability Management
  • Web Services
  • Windows PowerShell
  • Workflow

Summary

Bering Straits Native Corporation/Bering Straits Professional Services (BSPS), is seeking an expereinced Senior Cybersecurity Incident Response Specialist to work on a government contract in Washington D.C. on the overnight shift.

Essential Duties & Responsibilities

The Essential Duties and Responsibilities are intended to present a descriptive list of the range of duties performed for this position and are not intended to reflect all duties performed within the job. Other duties may be assigned.

 

·         Member of the SOC team which provides 24 hours per day, 7 days per week, 365 days per year monitoring and incident response services for the organization’s Network, Systems, Applications, and Web services.

·         Provide senior level cybersecurity incident response expertise in support of the client’s Incident Response processes and procedures.

·         Develop operational baselines such data flows and application interactions to enhance SOC’s ability to respond to incidents.

·         Prepare and manage playbooks and relevant scenarios in addition to narratives and visual diagrams and review continuously, in compliance with NIST SP 800-61 and Government guidance.

·         Follow current guidance from NIST 800-61, Federal Incident Notification Guidelines, CISA’s Incident Response and Vulnerability Playbook, and client guidance.

·         Monitor system status and sensor data from deployed sensors and triage for validity from Security Information and Event Management (SIEM) System, email, texts, phone calls and all enterprise managed dashboards.

·         Analyze all sources including network traffic, identity, fault, performance, and bandwidth information, alerts and data to augment detection of network anomalies and unauthorized activity.

·         Meet regularly with client stakeholders to develop content, analytic rules, alerts, dashboards, automation and identify ways to improve availability and efficiency of client’s incident response program.

·         Categorize, Prioritize, and Report on cybersecurity events in accordance with (IAW) SOPs and other relevant policies documents.

·         Implement cybersecurity mitigations leveraging client tools and systems.

·         Create and escalate cybersecurity-related investigations to both internal and external entities such as DHS or other Government Agencies with client and Federal defined timelines.

·         Manage, coordinate, and respond to FOIA, audits, data calls, e-discovery and information requests.

·         Schedule and execute incident response tabletop exercises with each client FISMA system on an annual basis.

·         Review and handle phishing messages reported by client staff.

Required (Minimum Necessary) Qualifications

·         Education Requirements:

o    High School or GED-General Educational Development-GED Diploma

o    Bachelor’s degree in computer science or equivalent is preferred

·         Level of Experience Requirements: Minimum of five years hands-on experience

·         Proven experience detecting, triaging, and responding to cyber incidents across enterprise networks and cloud environments.

·         Proficiency with SIEM, EDR/XDR platforms, and forensic tools.

·         Strong understanding of threat actor TTPs, MITRE ATT&CK framework, and incident containment strategies.

·         Ability to analyze network traffic, logs, and endpoint telemetry to identify malicious activity.

·         Familiarity with malware analysis, reverse engineering basics, and memory analysis concepts

·         Experience developing and tuning detection rules, playbooks, and automated response workflows.

·         Working knowledge of incident response frameworks (e.g., NIST SP 800-61, SANS).

·         Understanding of vulnerability management, threat intelligence integration, and SOC metrics/reporting.

·         Understanding of basic computer and networking technologies.

·         Windows and Linux/Unix operating systems 

·         Networking technologies (routing, switching, VLANs, subnets, firewalls)

·         Common networking protocols – SSH, SMB, SMTP, FTP/SFTP, HTTP/HTTPS, DNS, etc.

·         Common enterprise technologies – Active Directory, Group Policy, and the Microsoft Azure suite of cloud services.

·         Understanding of current system logging technology and retrieving information from a plethora of technology platforms.

·         Ability to work well in a team environment.

·         Self-starter with ability to work with little supervision.

·         Willingness to take on and adapt to new, open-ended tasks for which there is no current standard operating procedure.

·         Ability to research independently and self-teach.

·         Strong analytical and decision-making skills under pressure.

  • CompTIA Security+

 

 

Knowledge, Skills, Abilities, and Other Characteristics

·    

  •                Excellent written and verbal communication, including incident documentation and executive briefings.

·         Ability to lead investigations, mentor junior analysts, and collaborate with cross-functional teams.

·         Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Accordingly, U.S. Citizenship is required.

Preferred

  • Interest in security/hacking culture. Ability to “think like an attacker”
  • General cybersecurity certifications (one or more of the following preferred):
  • CompTIA Cybersecurity Analyst (CySA+)
  • Certified Ethical Hacker (CEH)
  • GIAC Certified Incident Handler (GCIH)
  • Any cloud security certification, especially:
  • CompTIA Cloud+
  • Certified Cloud Security Professional (CCSP)
  • Cloud Security Alliance Certificate of Cloud Security Knowledge (CCSK)
  • Any Microsoft 365/Azure cybersecurity certification, especially:
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Familiarity with the Microsoft 365 and Microsoft Azure suite of products, including Microsoft Sentinel and Microsoft 365 Defender.
  • Knowledge of common enterprise technologies, policies, and concepts such as:
  • Microsoft Sentinel SIEM
  • Kusto Query Language (KQL)
  • Mobile device technologies (iOS, Android)
  • Scripting experience (PowerShell, Python, etc.)
  • Microsoft Power BI
  • Azure DevOps
  • Artificial Intelligence (AI) / Machine Learning (ML) expertise
  • In-depth knowledge of AI and ML concepts.
  • How to practically apply AI/ML technologies to enhance cyber threat hunting and incident response capabilities.
  • Experience with specific AI services offered within Microsoft Azure.

Necessary Physical Requirements

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Employees must always maintain a constant state of mental alertness. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

  • Essential and marginal functions may require maintaining physical condition necessary for bending, stooping, sitting, walking or standing for prolonged periods of time; most of time is spent sitting in a comfortable position with frequent opportunity to move about.

 

Work Environment

Work Environment characteristics described here are representative of those that must be borne by an employee to successfully perform the essential functions of this job.

Will be working in a secure governemnt facility

 

Physical Setting: Washington DC

Schedule and Flexibility: Full Time in Office

SUPERVISORY RESPONSIBILITIES

·         No supervisory responsibilities.

 

ADDITIONAL QUALIFYING FACTORS

·         As a condition of employment, you will be required to pass a pre-employment drug screening and have acceptable background check results. If applicable to the contract, you must also obtain the appropriate clearance levels required and be able to obtain access to military installations.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: RTX1a5b50
  • Position Id: 9041708
  • Posted 17 hours ago

Company Info

About Bering Straits Native Corporation

Bering Straits Native Corporation is an Alaska Native regional corporation established in 1972. The corporation is headquartered in Anchorage, Alaska. Bering Straits operates in various industries including construction, government services, real estate, and tourism. With around 700 employees, Bering Straits plays a significant role in the economic development of the region.

About_Company_One
Contact the job poster
GV

Gita Verma

Program Manager @ Bering Straits Native Corporation
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs