Cybersecurity Incident Response Team -CIRT Lead

Cybersecurity Incident Response Team -CIRT Lead

12 Dec 2024
Virginia, Alexandria, 22301 Alexandria USA

Cybersecurity Incident Response Team -CIRT Lead

Cybersecurity Incident Response Team -CIRT LeadAlexandria, VA, USA ● Seaside, CA, USA ● Washington, DC, USA Req #537Thursday, December 12, 2024ASRC Federal NetCentric Technology seeks an on-site Cybersecurity Incident Response Team (CIRT) Lead in Alexandria, Virginia or Seaside California to support our Cybersecurity Support Services contracts. This position performs activities related to leading and coordinating cybersecurity incident response team actions primarily responsible for containing, responding to, and eradicating threats and other malicious activity. This position helps build and improve cybersecurity incident response capabilities by coordinating both internally and externally in routine and/or high-priority investigations, identifying incident response process improvements, preparing reports and briefing technical and non-technical personnel and senior level management. This position may require support to respond to and investigate cyber events should an incident occur after regular business hours. Key Responsibilities:

Incident Management: Act as the primary point of contact for all major security incidents which includes tracking incidents, corrective measures taken, recommendations, and remediation activities; completing incident reports for investigations as needed; providing or contributing to weekly report of events and incidents.

Team Leadership: Supervise and mentor a team of cybersecurity incident response professionals, providing guidance and support to ensure proper monitoring and logging across the network infrastructure and endpoints in an effort to detect and respond to cyber incidents promptly.

Threat Analysis: Analyze and assess cybersecurity threats, vulnerabilities, and incidents to determine root cause trends or patterns that ultimately lead to the development of appropriate response strategies.

Incident Response Planning: Develop and maintain comprehensive incident response plans and procedures.

Communication: Serve as the primary point of contact for incident response activities, communicating with stakeholders, including senior management and cross-functionally amongst IT teams, and external partners. Provide regular reports to program leadership, DoD officials, and other stakeholders on the status of security incidents, lessons learned, and the effectiveness of response strategies.

Compliance: Provide expert guidance on compliance with cybersecurity directives, ensuring the DoD program meets all required security controls and risk management policies.

Continuous Process Improvement: Regularly review and update incident response processes and procedures (SOP) based on new threats and lessons learned from past incidents in accordance with CJCSM 6510.01B, NIST SP 800-61R2, DoD regulations, and industry best practices.

Preferred Skills:

Hands-on knowledge and experience with cybersecurity tools such as Splunk, Tanium, Beyond Trust, ACAS, ESS or Microsoft Defender.

Required Qualifications:

Bachelor’s degree in Cybersecurity, Information Technology, or a related field (or equivalent additional experience).

Active DoD Secret Clearance with the ability to obtain and maintain a Top-Secret Clearance.

7+ years of related information technology and cybersecurity experience.

3+ years CIRT experience with one year of CIRT lead experience.

Active DoD 8570 IAT Level II certification or greater , including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.

Active DoD 8570 CSSP Incident Responder certification a plus, including at least one of the following certifications in good standing: CEH, CFR, CCNA Cyber Ops, CHFI, CySA+, GCFA, GCIH, SCYBER, or PenTest+ Knowledge of Incident Response Handling Procedures (NIST SP 800-61)

Familiarity with cyber adversary tactics and frameworks (such as ATT&CK and D3FEND)

On-site in Alexandria, Virginia or Seaside, California

Advantages of Working at ASRC Federal:

Learning and Development: After 90 days of employment, regular full-time employees are eligible for our professional development program. This includes annual funding for:

Pursuing Associate’s, Bachelor’s, or Graduate Degrees.

Obtaining industry-standard professional certifications.

Participating in professional certificate programs.

Covering registration fees for professional conferences.

Employee Resource Groups (ERGs): Engage with colleagues through our ERGs, which foster networking and collaboration among individuals with shared interests, backgrounds, and experiences. Our ERGs include:

Women’s Impact Network (WIN).

Multicultural ERG.

Military Community (MILCOM).

Pride ERG for LGBTQ+ employees and allies.

Purpose-Driven Careers: Join a company recognized as a:

Certified Great Place to Work .

Military Times’ Best for Vets Employer.

Military.com’s Top 25 Veteran Employer .

Comprehensive Benefits:

Insurance Coverage : Comprehensive plans for medical, dental, vision, life insurance, and short-term/long-term disability.

Paid Leave : Inclusive policies for bereavement, military obligations, and parental needs, along with 11 paid holidays annually.

Retirement Savings : A 401(k) plan with a generous company match and immediate vesting to help secure your financial future.

Incentives : Employee referral bonuses to reward you for helping grow the ASRC Federal Family

Embark on a career with ASRC Federal, where your growth, purpose, and well-being are at the forefront of what we do.We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. This position is offering a pay range of $130,000.00 - $165,000.00 depending on experience, seniority, geographic locations, and other factors permitted by law. Benefits offered may include healthcare, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.EEO Statement ASRC Federal and its Subsidiaries are Equal Opportunity /Affirmative Action employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law. Other details

Job FamilyInformation Technology

Job Sub-FamilyCyber Security

Pay TypeSalary

Required EducationBachelor’s Degree

Alexandria, VA, USA

Seaside, CA, USA

Washington, DC, USA

<

Related jobs

  • ARBY\'S - TEAM MEMBER

  • Job Description:

  • Summary This position serves as the Division Director, Cybersecurity Operations and Response Division. This position is responsible for supervising, directing, and managing the staff and the day-to-day functions of the Cybersecurity Operations and Response Division of OCISO within the strategic vision and enterprise wide initiatives identified and established by the CISO. Responsibilities This is a rewarding opportunity and a perfect step in your career, if you are eager to: Plan, direct, and manage and support Cybersecurity Operations and Response Division activities; (such as establishes long- and short-range goals and objectives, determines the financial and human resources necessary to carry out programs). Represent the Chief Information Security Officer (CISO) and the Office of the Chief Information Security Officer (OCISO) inside and outside the agency and be fully authorized to communicate the Division policies, and priorities. Participate in special projects and initiatives requiring collaboration and engagement at a leadership level and implement assigned projects that require senior management involvement across business units within the division or other USPTO offices. Supervise and manage highly technical staff of Information Technology Cybersecurity Specialists responsible for a wide variety of duties connected with the maintenance, design, and implementation of current, new, and emerging security programs designed to anticipate, assess, and minimize system vulnerability, e.g., intrusion prevention, forensics, computer incident response, security device management, and access authentication programs. The physical worksite for this position is located in Alexandria, Virginia. This position is telework eligible per agency and business unit discretion/policy. This position is eligible for the selectee\'s preference of either: Telework up to 5 days per week fully remote within 50 miles of the USPTO Alexandria, VA headquarters and the duty station is the authorized telework location (typically your home address) OR with a reporting requirement of not less than 15 minutes twice per bi-week to USPTO\'s Alexandria, VA headquarters, (hoteling), and the duty station is the USPTO\'s Alexandria VA HQ. If selected for an interview, applicants are encouraged to discuss telework options and eligibility specific to the position in which they applied with the hiring manager. Requirements Conditions of Employment Qualifications You must meet the United States Office of Personnel Management\'s (OPM) qualification requirements (including specialized experience and/or educational requirements) for the advertised position. You must meet all eligibility and qualifications requirements by the closing date of the job announcement. OPM Qualifications Standards are available at Information Technology (IT) Management Series 2210 (Alternative A). Specialized Experience is experience that has equipped applicants with the particular knowledge, skills and abilities to successfully perform the duties of the position, and that is typically in or related to the position to be filled. To be creditable, specialized experience must have been equivalent to at least the next lower grade level in the federal service. For this position, the next lower grade level is a GS-14. Specialized experience for this position includes: Experience overseeing a large IT organization demonstrating strategic planning, operational management, and resource optimization. AND; Experience providing expert technical knowledge in security operations by monitoring, detecting, and responding to cybersecurity incidents and conducting threat intelligence/risk analysis. AND; Experience conducting forensic and vulnerability management by identifying, assessing, and mitigating vulnerabilities to prevent potential exploits and breaches. AND; Experience in developing and deploying secure technological solutions that are compliant with organizational and regulatory policies. AND; Experience in directing multidisciplinary teams, conducting performance evaluations, developing staff through training programs, and managing disciplinary actions. In addition to meeting specialized experience: For all positions individuals must have IT-related experience demonstrating each of the four competencies listed below. The employing agency is responsible for identifying the specific level of proficiency required for each competency at each grade level based on the requirements of the position being filled. Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Condition of Employment: Incumbent must have one of the following certificates within 120 days from entry on duty (EOD): ISC2 Certified Authorization Professional (CAP); ISC2 Certified Information System Security Professional (CISSP); ISACA Certified Information Security Manager (CISM); GIAC Information Security Fundamentals (GISF); GIAC Security Leadership Certification (GSLC). Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Education Education may not be substituted for experience at this grade level. Additional Information If you are a male applicant born after December 31, 1959, you must certify that you have registered with the Selective Service System. If you are exempt from registration under Selective Service Law, you must provide appropriate proof of exemption. Please visit the Selective Service System website for more information. This is a Non Bargaining Unit position. ENHANCED SECURITY REQUIREMENT: The incumbent in this position must have access to TOP SECRET information to ensure that security weaknesses and concerns at the top secret level are considered when remediation and enhancements to correct security vulnerabilities are put into place in any particular system. Knowledge of top secret level information by the incumbent allows for the appropriate sensitive security controls to be put into place in support of government systems. If selected for this position, you may be required to complete the Fair Credit Act Memo, which gives consent so that one or more consumer credit reports may be obtained for employment purposes. Background Investigation - If selected for this position, you may be required to complete a Declaration for Federal Employment (OF-306), which includes a fingerprint and credit check, to determine your suitability for Federal employment and to authorize a background investigation. The USPTO participates in E-Verify. For more information on E-Verify, please visit the Department of Homeland Security Website. Supervisory Probationary Period-If selected, you may be required to complete an initial one-year supervisory probationary period. All Federal employees are required to have Federal salary payments made by direct deposit to a financial institution of their choice. Relocation Expenses are not authorized and will not be paid. CTAP and ICTAP candidates will be eligible for selection priority if it is determined that they have exceeded the minimum qualifications for the position by attaining at least a \"well qualified\" rating of 85 out of 100. Information about CTAP and ICTAP eligibility is on the Office of Personnel Management\'s Career Transition Resources website at: OPM CTAP/ICTAP. CTAP/ICTAP documentation requirements are listed in the \'Required Documents\' section of this announcement. More than one selection may be made from this announcement if additional identical vacancies in the same title, series, grade, and unit occur within 90 days from the date the certificate was issued. All application materials become the property of the United States Patent and Trademark Office. USPTO Job Applicants requiring reasonable accommodation for any part of the application and hiring process should request accommodation(s) from the USPTO at USTPO Reasonable Accommodation. The United States Patent and Trademark Office is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, retaliation, parental status, military service, or other non-merit factors. If you believe that you have been discriminated against and would like to file an EEO complaint, you must do so within 45 days of the date of the alleged discriminatory act. Claims of employment discrimination must be submitted to the attention of the USPTO\'s Office of Equal Employment Opportunity & Diversity via email (oeeod@uspto.gov) or phone (571-272-8292).

  • Lead, Audience Segment and Product Marketing

  • Senior Director, Enterprise Sales Team - Enterprise

  • Hourly Wage: $16 - $24 per/hour

  • Lead, B2C Demand Generation

Job Details

Jocancy Online Job Portal by jobSearchi.