Chenega logo
ChenegaPosted 25 months ago

Cyber Defense Incident Responder (Advanced)

$159,000–$159,000 year

On-siteArlington, Virginia, United States

Full TimeMid LevelLarge

Job Summary

Lead a small team of advanced and mid-level security analysts to provide Incident Defense services for government clients within TS/SCI and SAP environments. Serve as the primary technical point of contact for complex threat hunting issues, engineer advanced detection alerting rules using Splunk, KQL, and Elastic tools, and conduct adversary emulation for purple and red teaming efforts. Proactively research new malware, lead targeted phishing campaigns, and perform comprehensive investigations with little oversight to locate information for government requests. Maintain the ID Team toolkit, coordinate on-call coverage for after-hours and holidays, and produce high-quality incident reports and briefings for government leadership.

Required Qualifications

  • High school diploma or GED equivalent
  • Bachelor's degree in computer science, Digital Forensics, or related major
  • 6+ years' experience in Threat Hunting, Security Research, or Incident Response
  • Demonstrated leadership skills
  • Scripting experience
  • TS/SCI clearance

Desired Qualifications

  • Bachelor's degree in computer science, Digital Forensics, or related major with an emphasis on Security preferred
  • Demonstrated leadership skills, preferably in a formal leadership role
  • Successfully pass background and drug screening
  • Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves
  • Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies
  • Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response
  • Government/Client Service Experience: Extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients
  • Security Engineering & Architecture: Knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures
  • Adversary Emulation: Skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs)
  • Technical Mentorship: Experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques
  • Advanced Forensics: Deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations
  • Malware & Script Analysis: High-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors
  • Superior Research Capabilities: Exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities
  • Executive Communication: Excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership
  • Technical Translation: Ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers
  • Project & Case Management: Proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity
  • Crisis Management: Ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines
  • Collaboration: Well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners
  • Attention to Detail: Excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce