Jobs · Information Technology · Virginia

Cybersecurity Operations Specialist 720

Freedom Technology Solutions Group, LLC · Springfield, VA · 3 wk ago
On-siteInformation TechnologyFull-time

Freedom Technology Solutions Groups is seeking a Cybersecurity Operations Specialist to provide CSOC Tier 2 and 3 services, including 24x7x365 coordination, execution, and implementation of containment, eradication, and recovery measures for cyber events and incidents. CSOC Tier 3 services include malware and implant analysis, as well as forensic artifact handling and analysis. During a CIRT activation, contractors will operate under the direct control of the Government CIRT Commander. Outside incident response periods, the contractor will conduct continuous exercises and dry runs to improve response outcomes. All Tier 3 personnel must hold or obtain (within six months of start) a certification compliant with DoDD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Incident Responder.

Responsibilities

  • Coordinate and implement tasks, perform analysis, and document response activities during cyber security incident response, including containment measures, IP/domain blocks, and disabling user accounts as directed.
  • Collaborate with the Security and Installations Directorate (SI) Office of Counterintelligence (SIC), Insider Threat Office (SIII), and other law enforcement or counterintelligence personnel for advanced incident investigation and triage.
  • Produce security incident reports in collaboration with appropriate authorities.
  • Categorize incidents and events.
  • Coordinate with other contracts, organizations, and services to ensure proper reporting, containment, and eradication of incidents.
  • De-conflict blue/red team activity with open incidents or events.
  • Ensure NGA recovers from incidents or events through coordination with relevant stakeholders.
  • Build timelines, documents, briefings, and other products to inform stakeholders of incident response actions, analysis, and impacts of adversary and blue force activities.
  • Document actions and analysis in the authorized ticketing system to enable systematic reconstruction of response efforts.
  • Develop, update, and generate reports in systems such as the Joint Incident Management System (JIMS) and Incident Case Management System (ICMS) when approved by the Government.
  • Develop, maintain, and execute (when authorized) custom scripts, tools, and capabilities for data collection, analysis, and incident response.
  • Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory and system artifact collection and analysis.
  • Develop and identify indicators of compromise for dissemination to cybersecurity stakeholders and other contract services.
  • Provide adversary attribution and perform malware analysis and signature development.
  • Coordinate with CSOC Tier 1 and 2 services to remediate discrepancies and provide recommendations to prevent recurrence.
  • Provide input and coordinate with stakeholders to develop the daily CSOC Significant Activity Report, daily CSOC Operations Update, and Weekly CSOC Status Report.
  • Serve as a C-IRT member under the direct control of the Government C-IRT Commander when required.
  • Develop and coordinate courses of action with stakeholders and execute Defensive Cyberspace Operations-Internal Defensive Measures on NGA networks when authorized.
  • Perform malware reverse engineering and digital media analysis on host, server, and network data as required.
  • Execute custom scripts, tools, and capabilities for data collection and incident response when authorized by the Government.
  • Develop and deliver incident investigation reports to the Government within 30 days of C-IRT stand-down, documenting the incident lifecycle, adversary and friendly forces activity, analysis, timelines, and recommendations for corrective actions and new TTPs.
  • Conduct weekly Quality Control reviews of a percentage of closed CSOC Tier 2 tickets to ensure proper analysis, categorization, documentation, and notification.

Requirements

  • Bachelor’s degree and/or 6 years of experience in Cyber Security (CSOS).
  • Active TS/SCI clearance with the ability to obtain a polygraph.
  • DoDD 8140.01 and DoD 8570.01-M IAT Level II and CSSP Incident Responder certification (IAT Level III required within six months of start).

Preferred Qualifications

  • Master’s degree.
  • IAT Level III certification.

Benefits

  • Matching 401k.
  • Fully paid medical benefits.
  • Generous paid time off, including paid site closure days.
  • Competitive salary.
  • Paid training and tuition reimbursement.
  • Referral bonuses.
  • Fully paid life and disability insurance.
  • Annual logo wear allowance.
  • Company-sponsored events (game nights, holiday party, summer party, happy hours).

Similar jobs

Cyber Operations Specialist

United States Army ReserveMorgantown, WV· 17 mo ago
Management$25k/yrapply on usarmybridgeport.betterteam.com