Incident Response Team Deputy Lead
Job Description
Description
The U.S. Department of Homeland Security, Customs and Border Protection Security Operations Center (SOC) plays a critical role in safeguarding our nation by preventing, identifying, containing, and eradicating cyber threats to our networks. Join us in our mission to protect the vital systems that secure our country. We are looking for an experienced Incident Response professional to lead our dedicated team within this high-stakes environment.
As the Deputy Team Lead, you will manage daily operations, coordinate team efforts, and perform detailed analysis on network and endpoint activity. Your role will involve incident analysis, developing remediation strategies, and communicating with various stakeholders to enhance our cyber defense initiatives.
Key Responsibilities:
- Assist the CIRT Team Lead in fostering an effective team of analysts, prioritizing incident response actions, and conducting thorough technical analysis.
- Collaborate with other task leads to support customer initiatives and address cyber incidents promptly.
- Create informative dashboards for key metrics and present technical insights to customer leadership.
- Engage with senior leaders to ensure the stabilization and sustainability of critical systems within the SOC.
- Utilize advanced technologies, such as host forensics, Endpoint Detection & Response tools, and log analysis frameworks, to conduct investigations.
- Perform in-depth analysis on hosts and networks to support incident responses effectively.
- Identify and analyze attacker tactics and procedures to enhance incident detection capabilities.
- Develop and implement security content and tools to improve investigation workflows.
- Lead incident response activities and mentor junior SOC staff to build a strong cybersecurity talent pipeline.
- Work closely with stakeholders to execute remediation efforts following incidents.
- Provide clear communications regarding findings to both technical teams and organizational stakeholders.
- Stay up-to-date with the latest threat intelligence and security trends, ensuring your skills are aligned with current cyber threats.
- Demonstrate superior problem-solving abilities with strong analytical skills.
- Communicate findings and updates effectively, ensuring attention to detail and accurate reporting.
Basic Qualifications:
- Bachelor's degree in a science, engineering, IT, or cybersecurity field.
- 5+ years of experience in incident detection, response, malware analysis, or computer forensics.
- Proven ability to prioritize multiple tasks independently.
- Experience managing complex project tasks in a team environment.
- Strong communication skills and experience engaging with senior organizational leaders.
- Advanced understanding of the Incident Response Lifecycle and its application.
- Collaborative mindset to identify and resolve security-related issues effectively.
- Proficient in creating and implementing processes, playbooks, and standard operating procedures.
- Ability to script in Python, Bash, Visual Basic, or PowerShell.
- Experience with cyber incident investigations focused on adherence to escalation protocols.
Clearance: All SOC employees must possess a CBP Background Investigation to support this program.
Preferred Qualifications:
- Experience in Federal Government, DOD, or Law Enforcement in a Cybersecurity role.
- Familiarity with the Cyber Kill Chain and MITRE ATT&CK framework.
- Knowledge of Structured Analytic Techniques.
Required Certifications: Candidates must hold at least one of the following certifications:
- CompTIA Cyber Security Analyst (CySA+)
- CompTIA Linux Network Professional (CLNP)
- CompTIA Pentest+
- GPEN - Penetration Tester
- GSNA - System and Network Auditor
- CISSP - Certified Information Systems Security Professional
- CEH - Certified Ethical Hacker
- CHFI - Computer Hacking Forensic Investigator
If you are ready to take on an impactful role and help shape the future of cybersecurity at a vital government agency, we encourage you to apply and be part of our mission-focused team.