Incident Response Deputy Team Lead
Leidos is seeking an experienced Incident Response professional to join our team supporting the U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC). The CBP SOC is a U.S. Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services for CBP information systems, including LAN/WAN, commercial Internet connections, public-facing websites, wireless, mobile/cellular, cloud, security devices, servers, and workstations. The SOC ensures the overall security of CBP Enterprise-wide information systems and investigates suspected and confirmed security violations.
About the role
As a leader of this highly visible cyber Security Operations Center (SOC) for U.S. Customs and Border Protection (CBP), you will manage day-to-day operations, coordinate team efforts, and perform in-depth technical analysis of network and endpoint logs and activity. Responsibilities include cyber incident analysis, escalation, containment, remediation, and root cause analysis to protect customer systems, networks, and assets.
Responsibilities
- Assist the CIRT Team Lead with managing the team of CIRT analysts, Incident Response actions and priorities, technical analysis, root cause analyses, and customer interfacing.
- Partner with other task leads to support customer initiatives and cyber incidents.
- Create dashboards for key metrics and processes and deliver technical presentations to various levels of customer leadership.
- Interface with senior DHS and CBP leaders and directors to maintain and sustain critical systems supporting the CBP Security Operations Center.
- Utilize state-of-the-art technologies such as host forensics tools (FTK/Encase), Endpoint Detection & Response tools, log analysis (Splunk), and network forensics (full packet capture solution) to perform hunt and investigative activities.
- Conduct in-depth analysis on hosts and networks, forensic analysis, log analysis, and triage in support of incident response.
- Recognize attacker and APT activity, tactics, and procedures as indicators of compromise (IOCs) to improve monitoring, analysis, and incident response processes.
- Develop and build security content, scripts, tools, or methods to enhance incident investigation processes.
- Lead incident response activities and mentor junior SOC staff.
- Work with key stakeholders to implement remediation plans in response to incidents.
- Investigate and identify root cause findings, then communicate them to stakeholders, including technical staff and leadership.
- Stay up to date with the latest threat intelligence, security trends, tools, and capabilities.
- Independently prioritize and complete multiple tasks with little to no supervision.
- Effectively communicate with customer leadership and disseminate timely updates of critical incidents with emphasis on attention to detail and accurate reporting.
Requirements
- Bachelor’s degree in a science or engineering field, IT, or Cybersecurity-related field.
- 12+ years of experience in incident detection and response, remediation, malware analysis, or computer forensics.
- Ability to prioritize and complete multiple tasks with little to no supervision.
- Experience organizing, directing, and managing contract operation support functions involving multiple, complex, and interrelated project tasks.
- Experience effectively communicating at senior levels within a customer organization.
- Advanced knowledge of the Incident Response Lifecycle and its applicability to various types of incidents and situations.
- Ability to collaborate with technical staff and customers to identify, assess, and resolve complex security problems/issues/risks and facilitate resolution and risk mitigation.
- Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and brief stakeholders on incident statuses.
- Experience creating new processes, playbooks, and SOPs for new tools and workflows.
- Ability to script in one or more of the following: Python, Bash, Visual Basic, or PowerShell.
- Experience running cyber incident investigations with emphasis on attention to detail, adept communication skills, and adherence to defined escalation paths.
- Must currently possess a CBP Background Investigation clearance.
Qualifications
- Experience in Federal Government, DOD, or Law Enforcement in CND, CIRT, or SOC roles.
- Knowledge of the Cyber Kill Chain and the MITRE ATT&CK framework.
- Knowledge of Structured Analytic Techniques.
Skills
- Strong problem-solving abilities with an analytic and qualitative eye for reasoning.
- Flexible and adaptable self-starter with strong relationship-building skills.
Required Certifications
The candidate should have at minimum ONE of the following certifications:
- CompTIA Cyber Security Analyst (CySA+)
- CompTIA Linux Network Professional (CLNP)
- CompTIA Pentest+
- GPEN – Penetration Tester
- GWAPT – Web Application Penetration Tester
- GSNA – System and Network Auditor
- GISF – Security Fundamentals
- GXPN – Exploit Researcher and Advanced Penetration Tester
- GWEB – Web Application Defender
- GNFA – Network Forensic Analyst
- GMON – Continuous Monitoring Certification
- GCTI – Cyber Threat Intelligence
- GOSI – Open Source Intelligence
- OSCP (Certified Professional)
- OSCE (Certified Expert)
- OSWP (Wireless Professional)
- OSEE (Exploitation Expert)
- CCFP – Certified Cyber Forensics Professional
- CISSP – Certified Information Systems Security
- CEH – Certified Ethical Hacker
- CHFI – Computer Hacking Forensic Investigator
- LPT – Licensed Penetration Tester
- CSA – EC Council Certified SOC Analyst (Previously ECSA – EC-Council Certified Security Analyst)
- ENSA – EC-Council Network Security Administrator
- ECIH – EC-Council Certified Incident Handler
- ECSS – EC-Council Certified Security Specialist
- ECES – EC-Council Certified Encryption Specialist
Pay
Pay Range: $131,300.00 - $237,350.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Benefits
Pay and benefits are fundamental to any career decision. Leidos offers competitive compensation, Health and Wellness programs, Income Protection, Paid Leave, and Retirement. More details are available at www.leidos.com/careers/pay-benefits.