Cybersecurity Incident and Application Lead
Unissant, Inc. delivers innovative capabilities to the agencies that keep our nation healthy and safe. We apply our domain expertise, data acumen, and technology know-how to achieve breakthrough results for our clients. Working collaboratively, we advance missions and careers through a focus on honesty, integrity, and dependability.
About the role
The ideal candidate is a strong incident response and application security professional who remains calm under pressure and brings deep technical knowledge across network security, web application security, cloud technologies, and threat detection. This individual is motivated by protecting enterprise systems, improving response readiness, and working collaboratively to resolve high-priority cybersecurity events.
Responsibilities
- Lead the full lifecycle of incident detection, analysis, containment, recovery, and post-incident activities across enterprise systems.
- Coordinate incident response efforts, manage escalations, and support cross-functional response activities.
- Monitor, detect, and report suspected cybersecurity incidents using enterprise logging, SIEM, EDR, IAM, antivirus, and cloud tools.
- Configure alerts and reporting to help identify indicators of compromise, suspicious behavior, and insecure configurations.
- Track incidents through remediation and support the development of lessons learned, SOPs, and process improvements.
- Assist with incident response testing, reporting, and stakeholder communications.
Requirements
- Minimum of 5–7 years of hands-on experience in network security, web application security, and cloud technologies.
- Strong knowledge of ports, protocols, weak configurations, vulnerable services, and common intrusion techniques.
- Experience applying incident response processes across preparation, detection and analysis, containment, recovery, and post-incident review.
- Hands-on experience with technologies such as Splunk, Tenable, FireEye, IDS/IPS platforms, and related event analysis tools.
- Good understanding of Windows and Linux operating systems.
- Ability to create management reports, escalation documentation, and incident response process materials.
Qualifications
- Bachelor's Degree is required. Preferred field of study in Computer Science, Information Technology, Information Systems, Operations Management, or related field of study.
- MBA/Master's Degree in a relevant field of study preferred.
Skills
- Excellent verbal and written skills, ability to present proposals and performance data, comfortable interfacing all levels of organization.
- Ability to write clear and concise creative content in a highly confidential manner.
Certifications
Desired certifications include ECIH, OSCP, GCIH, and Splunk certifications.
Clearance
Ability to obtain and maintain a Public Trust clearance.
Schedule
- Work under this task order is expected to be performed primarily remotely at the contractor's non-Federally controlled facility.
- Key personnel are expected to work onsite in Bethesda, Maryland two days per week, with onsite schedules and working hours subject to approval by Federal staff.
- Additional onsite meetings or temporary support within Federally controlled facilities may be required based on program needs.
- Flexible in working extended hours.
Environmental Requirements
- Mainly a routine office environment.
- May be required to lift up to ten (10) pounds.