Incident Manager II Job at KMJJ Enterprise LLC, Arlington, VA

V0t5U25VN2x3L3IrYjNXV0JkcTBzcFhvTlE9PQ==
  • KMJJ Enterprise LLC
  • Arlington, VA

Job Description

Incident Manager II

Description:
Supporting our prime contractor and their U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution.

Seeking Cyber Case Manager to perform investigations to characterize the severity of breaches, develop mitigation plans, and assist with the restoration of services.

Eligibility:
  • Must be a  US Citizen
  • Must have an  active TS/SCI   clearance
  • Must be able to obtain DHS Suitability  prior to starting employment 
  • 2+ years of directly relevant experience in cyber incident management or cybersecurity operations
Responsibilities Include:
  • Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise
  • Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate threats
  • Applying cybersecurity concepts to the detection and defense of intrusions into small, and large-scale IT networks, and conduct cursory analysis of log data
  • Conducting cursory analysis of log data
  • Monitoring external data sources (e.g., Computer Network Defense vendor sites, Computer Emergency Response Teams [CERTs], SANS, Security Focus) to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise
  • Identifying the cause of an incident and recognizing the key elements to ask external entities when learning the background and potential infection vector of an incident
  • Receiving and analyzing network alerts from various sources within the enterprise and determine possible causes of such alerts
  • Tracking and documenting Computer Network Defense (CND) incidents from initial detection through final resolution
  • Working with other components within the organization to obtain and coordinate information pertaining to ongoing incidents.
  • Providing support during assigned shifts
Required Skills:
  • Knowledge of incident response and handling methodologies
  • Knowledge of the NCCIC National Cyber Incident Scoring System to be able to prioritize triaging of incident
  • Knowledge of general attack stages (e.g., foot printing and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)
  • Skill in recognizing and categorizing types of vulnerabilities and associated attacks
  • Knowledge of basic system administration and operating system hardening techniques
  • Knowledge of Computer Network Defense policies, procedures, and regulations
  • Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
  • Must be able to work collaboratively across physical locations
Desired Skills:
  • Knowledge of basic system administration and operating system hardening techniques
  • Knowledge of Computer Network Defense policies, procedures, and regulations
  • Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non nation-state sponsored], and third generation [nation-state sponsored])
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code)
Desired Certifications: GCIH, GCFA GISP, GCED, CCFP or CISSP
Required Education: BS Incident Management, Operations Management, Cybersecurity, or related degree; or HS Diploma with 4+ years of incident management or cyber security experience

Job Tags

Shift work,

Similar Jobs

Cigna

Sr Product Advisor - Cigna Healthcare - Job at Cigna

 ...Reporting to the Cigna Pharmacy Product Strategy Director and working as a key member of the team, this role is responsible for guiding, coaching and mentoring CPM Product Strategy and Management team members, including Advisors and Sr. Advisors. This is a part-time role... 

Apidel Technologies

Scrum Master Level 2 Job at Apidel Technologies

 ...complex and cross functional workacross the Security, Data and Networking domain areas related to transformationto the Cloud. The Scrum Master guides and facilitates a Scrum &/or Kanbanteam involved in a large fast-paced program implementing complex technology... 

*US AMR-Jones Lang LaSalle Americas, Inc.

Senior Facilities Manager Job at *US AMR-Jones Lang LaSalle Americas, Inc.

 ...experience to a new industry, join our team as we help shape a brighter way forward. Transform Facilities at JLL with your leadership experience as a Senior Facilities Manager on a large tech client account. What this job involves: The Senior Facilities... 

VANTAGE Aging Retired and Senior Volunteer Program

Deliver a birthday surprise to local seniors Meals on Wheels Job at VANTAGE Aging Retired and Senior Volunteer Program

As a birthday surprise deliver for Meals on Wheels, the Volunteers main duties include: Pick up per-packaged birthday gifts for local seniors from Meals on Wheels headquarter office Deliver the gift to seniors in the Hamilton County area who ae having a birthday...

Colorado Business Cpa, Llc

Experience Bookkeeper (2-3 Years) Job at Colorado Business Cpa, Llc

 ...Are you an organized, detail-oriented, and proactive bookkeeper/ accountant ready to make a significant impact? Join our dynamic and growing...  ...multiple clients). Tech-Savvy: Proficient in QuickBooks Online, Excel, and other accounting software. Experience with Fathom/and...