Detect and Response Lead
Fort Belvoir, VA, United States
Full Time Senior-level / Expert Clearance required USD 63K - 147K *
TekSynap
TekSynap utilizes the best information management technology to meet the business needs of Federal, State and Local Government customers.Responsibilities & Qualifications
RESPONSIBILITIES
- Review all cases and create lessons learned documentation for analysts and government agencies to increase awareness.
- Documents plans of action and milestones for corrective action following assessment activities and in response to identified vulnerabilities
- Provide regular case review briefs and reports to CSSP government customers.
- Manage 24/7 operations team of incident responders and Forensics Analysts to include: leave, shift coverage, annual reviews, perform feedback sessions, monitor training requirements, document successes and areas of improvement, high priority case remediation and its reporting requirements to leadership and DODIN when required.
- Monitor changes to ESM requirements (DOD 8530.01) and improve CSSP Detect and Response processes to ensure compliance every 6 months.
- Perform or direct changes to SOPs and Work Instructions as needed to ensure they are as up to date as possible and disseminate changes to Teams.
- Reports daily tasks performed by Detect & Response and Forensics Teams for shift change and provides continuity of effort across shifts.
- Collect and analyze network and/or host artifacts from a variety of sources to include logs, system images and packet captures to characterize activity, determine root cause, operational impact, and to enable rapid remediation and/or mitigation of cyber threats within the Enterprise Network through the investigation process.
- Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise.
- Perform cyber incident triage; to include determining scope, urgency, and potential impact; identifying the specific vulnerability; and making recommendations that enable expeditious remediation.
- Provide expert technical support and perform real-time cyber defense incident handling (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation) tasks to support subordinate organizations and system owners.
- Manage and document cyber defense incidents from initial detection through final resolution methods.
- Maintain an average of at least two new detection use cases per month during each year of contract execution. Detection use cases shall be based on current threats, the MITRE ATT&CK framework, or Government direction.
- Maintain metadata for all detection use cases to include use case owner, number of false positives identified, number of true positives identified, and average time to execute (based on incident detection monitoring analyst feedback).
- Analyze all completed incident records and make improvements to related detection use cases.
- Conduct refinements to correlation rules, filters, signatures, or plays to enhance overall effectiveness by lowering false-positive rates. Track and validate refinement requests and provide metrics on these activities monthly.
- Assist with developing methods for automating the execution of incident detection use cases that result in false-positive rates below 10%. Provide monthly reports on new automation actions and their results.
- Demonstrate effectiveness by creating detection use cases that successfully detect Red Team (penetration testing) activity.
- Utilize the MITRE ATT&CK matrix and other threat frameworks to develop detection use cases. Continually refine these processes with the goal of automating their execution.
- Provide subject matter expertise in creation, editing, and management of signatures, rules and filters for specialized network defense systems including but not limited to network and ESS IDS, IPS, firewall, web application firewall, proxy and SIEM systems.
- Analyze SIEM views daily to ensure views support detection and response operations. Modify SIEM views to eliminate false-positive or unnecessary alerts.
REQUIRED QUALIFICATIONS
- Minimum of a Top Secret Clearance.
- DOD 8570 IAT III and CSSP Analyst Certification
- BS 8-10 Years, MS 6-8, PhD 3-5
- Experience with cyber security architecture principles that achieve cybersecurity framework goals.
Overview
We are seeking a Detect amd Response Lead to join our DTRA ITSS II contract at Fort Belvoir, Virginia.
TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. “Technology moving at the speed of thought” embodies these principles – the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.
Visit us at www.TekSynap.com.
Apply now to explore jobs with us!
Additional Job Information
WORK ENVIRONMENT AND PHYSICAL DEMANDS
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- Location: Fort Belvoir, Virginia
- Type of environment: Office setting
- Noise level: Soft
- Work Schedule is day shifts.
- Amount of Travel: None.
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to use hands to finger, handle, or feel; reach with hands and arms; and talk or hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.
WORK AUTHORIZATION/SECURITY CLEARANCE
Active Top-Secret clearance.
OTHER DUTIES
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice and additional certification requirements may be required.
EQUAL EMPLOYMENT OPPORTUNITY
To provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as “protected status”). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation Clearance Compliance Cyber defense DoD DoDD 8570 Firewalls Forensics IDS IPS MITRE ATT&CK Monitoring Pentesting PhD Red team Security Clearance SIEM Top Secret Top Secret Clearance Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.