Incident Manager - III TS/SCI
On-siteArlington, Virginia, United States
Job Summary
Correlate incident data to identify trends, recommend defense-in-depth principles, and perform computer network defense triage to determine scope, urgency, and impact. Research resolution steps for mitigation, analyze network alerts to identify causes, and track incidents from detection through resolution while coordinating with organizational components. Monitor external data sources to maintain currency on threat conditions and recognize key elements when learning infection vectors from external entities. Provide support during assigned shifts Monday through Friday in normal business hours.
Required Qualifications
- U.S. Citizenship
- Must have an active TS/SCI clearance
- Must be able to obtain DHS Suitability
- 5+ years of directly relevant experience in cyber incident management or cybersecurity operations
- Knowledge of incident response and handling methodologies
- Having close familiarity with NIST 800-62 (latest revision), and FISMA standards as they pertain to reporting incidents
- Knowledge of the NCCIC National Cyber Incident Scoring System to be able to prioritize triaging of incident
- Knowledge of general attack stages (e.g., foot printing and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)
- Skill in recognizing and categorizing types of vulnerabilities and associated attacks
- Knowledge of basic system administration and operating system hardening techniques, Computer Network Defense policies, procedures, and regulations
- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
- BS Incident Management, Operations Management, Cybersecurity or related degree
- HS Diploma with 7-9 incident management or cyber security experience
Desired Qualifications
- Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
- GCIH, GCFA GISP, GCED, CCFP or CISSP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.