Manager, Incident Response
Pondurance · United States · 3 days ago
RemoteRemoteInformation Technology$150k–$175k/yrFull-time
Responsibilities
- Provide thought, technical, and general leadership to the IR Consulting Team and other stakeholders
- Aid in managing the team portfolio to defined metrics (utilization, revenue, margin, etc.)
- Deliver services to customers by attending key meetings, performing quality assurance reviews of deliverables, and providing direct consultation with customers as needed
- Collaborate with the Product Management Team to define and evolve our book of service offerings
- Work with Sales as support on prospective client calls, project scoping, and budgets
- Maintain individual and team skills and knowledge base on industry best practices, tools, tabletop exercise techniques, and scenario-based and live testing exercises
- Manage customer stakeholders and apply security incident investigation protocols from incident confirmation through resolution to lessons-learned
- Quickly mitigate damages by coordinating with technical teams and third-party vendors to triage and contain threats
- Manage and update incident response playbooks and toolkits based on new procedures, best practices, advanced open-source technologies, and various incident response products
- Design and deploy real-time monitoring and triage of incidents and alerts received
- Identify and document requirements to improve, automate, and work with developers to build tools that drive out inefficiencies, ineffectiveness, and uncompromisingly improve the customer experience
- Build and foster relationships with local, state, federal, and international law enforcement authorities
Requirements
- Minimum of 5 years of experience in cybersecurity
- 1 or more years of experience leading information security and/or consulting teams
- A Bachelor’s Degree with disciplines in the area of Computer Science, Management Information Systems, or Cyber Security, or equivalent experience, is preferred
- One or more of the following technical certifications preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications
- Proven track record of complex problem-solving and decision-making ability
- Expert level of analytical, planning, and organizational ability
- Strong, proactive communication skills are required
Skills
- Experience with Windows OS and networking protocols
- Experience with Unix OS and networking protocols
- Experience with network traffic analysis
- Experience with scripting and/or programming
- Experience with commercial EDR (SentinelOne, Blackberry PROTECT, CarbonBlack, CrowdStrike)
- Experience with forensic tool suites (FTK, AXIOM, EnCase)
- Experience with reverse engineering and malware analysis
Pay
The anticipated base salary range for this position is $150,000 - $175,000 annually. Actual compensation will be determined in good faith based on factors such as relevant experience, technical expertise, certifications, geographic location (where applicable), and internal equity. This position may also be eligible for bonus or other incentive compensation, as well as the benefits described below.
Schedule
This is a remote role, but if you live close by, you’ll have access to our office located in McLean, VA.
Benefits
- Medical, dental, vision, disability, FSA, HSA, life, and AD&D insurance
- 401(k) Plan
- PTO, sick, holiday, & parental leave