Description
Critical Solutions is seeking an experienced Incident Response Analyst to support a cybersecurity operations centre (SOC) for a federal program in Ashburn, Virginia. The IR will Utilize state of the art technologies such as host forensics tools(FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk) and network forensics (full packet capture solution) to perform hunt and investigative activity to examine endpoint and network-based data.
PRIMARY ROLES AND RESPONSIBILITIES:
- Conduct malware analysis, host and network, forensics, log analysis, and triage in support of incident response.
- Recognize attacker and APT activity, tactics, and procedures as indicators of compromise (IOCs) that can be used to improve monitoring, analysis and incident response.
- Develop and build security content, scripts, tools, or methods to enhance the incident investigation processes.
- Lead Incident Response activities and mentor junior SOC staff.
- Work with key stakeholders to implement remediation plans in response to incidents.
- Effectively investigate and identify root cause findings, then communicate findings to stakeholders, including technical staff and leadership.
- Flexible and adaptable self-starter with strong relationship-building skills
- Strong problem-solving abilities with an analytic and qualitative eye for reasoning
- Ability to independently prioritize and complete multiple tasks with little to no supervision
BASIC QUALIFICATIONS:
- Active DoD Secret Clearance. Ability to obtain and maintain TS/SCI
- Bachelor's degree in Science or Engineering Field, IT, or Cybersecurity or related field
- 3+ years of experience in incident detection and response, malware remediation analysis, or computer forensics.
- Prior relevant experience should be in the areas of incident detection and response, malware analysis, or computer forensics.
- Ability to script in one of the following computer languages: Python, Bash, Visual Basic or Powershell
PREFERRED QUALIFICATIONS:
- Experience in Federal Government, DOD or Law Enforcement in CND, IR or SOC role
- Cyber Kill Chain Knowledge
- One of the following certifications: CCNA, CCNP, CCSP, CEH, CNDA, DCITA, ECES, ECSA, ECSP, ECSS, ENSA, GCIA, GCIH, GISF, GNFA, GPPA, GWEB, LPT, OSCP, OSEE, SEI, CCISO
SCHEDULE
Shift schedule will be determined at the time of the start date
- Day shift Front: 7am - 7pm ET, Sunday - Tuesday and every other Wednesday (8hr shift)
- Day Shift Back: 7am - 7pm ET, Thursday - Saturday and every other Wednesday (8hr shift)
Clearance Requirement: Must be a US Citizen and possess an active DoD Secret Clearance. In addition, selected candidates must undergo a background investigation (BI) and fingerprinting by the federal agency and successfully pass the preceding to qualify for the position. US CITIZENSHIP IS REQUIRED.