Cyber Defense Incident Responder (SME)

Who We’re Looking For (Position Overview): Spry Methods is on the search for a Cyber Defense Incident Responder (SME) to join our team in the National Capital Region. What Your Day-To-Day Looks Like (Position Responsibilities):
  • Coordinates and provides expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.
  • Correlates incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. 
  • Performs analysis of log files from a variety of sources to identify possible threats to network security. 
  • Performs cyber defense incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation.
  • Performs cyber defense trend analysis and reporting. 
  • Assist in Incident Response processes and in the enhancement of behavioral analytics including the development of Concept of Operations and Standard Operating Procedures.
  • Develops and maintains models for cyber threat mitigation and improves on threat modeling.
  • Uses Behavior Analytics (UBA) and ensures all infrastructure components meet proper performance standards. 
  • Individual will be the primary Cyber Defense Incident Responder embedded in a enterprise security operations center team. 
  • Primarily responsible for digital forensics and incident response, individual will be adept at handling cyber security incidents in a high tempo environment with constantly changing mission parameters. 
  • Significant experience in digital forensics analysis is a must, with demonstrable experience in digital evidence analysis, identifying perpetrators and identifying root cause on intrusion methodologies.  

  • What You Need to Succeed (Minimum Requirements):
  • 10 + years of relevant experience
  • Personnel will have one or more of the following GIAC or equivalent certifications (GMON, GCIH, GCFA, GCIA, GNFA, GCTD, GCFR, GASF, GMOB).
  • Willing to support a 24/7/365 mission.
  • Experience with Splunk Enterprise Security required.
  • Experience with Axiom Forensics suite.
  • Top Secret Clearance Required
  • #CJ
    Get hired quicker

    Be the first to apply. Receive an email whenever similar jobs are posted.

    Report this job
    Apply for this job