Senior CERT Specialist
New York City Office of Technology & Innovation · Brooklyn, NY · 1 mo ago
OTHRFull-time
About the role
The Office of Technology and Innovation (OTI) seeks a Senior Computer Emergency Response Team (CERT) Specialist to support the City of New York in its cybersecurity efforts. OTI leverages technology to drive opportunity, improve public safety, and enhance government operations.
Responsibilities
- Serve as a senior technical escalation point for high-profile cybersecurity incidents, supporting the CERT Lead in ensuring 24x7 operational readiness;
- Lead complex incident response engagements end-to-end, coordinating activities among City departments, external partners, and state, federal, and private entities;
- Provide technical mentorship, peer review, and on-the-job training to CERT Specialists, including guidance on forensic methodology, analytical rigor, and report quality;
- Act as a subject matter expert in investigating cybersecurity incidents through advanced log, file, and malware analysis;
- Perform and oversee memory, network, disk, and cloud forensics across enterprise environments (AWS, Azure, GCP);
- Devise and validate remediation strategies and assist affected City agencies in containing, eradicating, and recovering from cybersecurity incidents;
- Lead the development of post-incident action plans and root-cause analyses to improve Mean Time to Detect, Respond, and Recover/Restore;
- Design, build, and enhance cyber-incident detection tools, automation, and response capabilities, including custom tooling and detection content;
- Partner with cyber threat intelligence teams to operationalize indicators, TTPs, and campaign intelligence into proactive countermeasures and threat hunts;
- Design, lead, and facilitate cyber tabletop exercises with City departments to identify capability gaps, procedural weaknesses, and critical infrastructure dependencies;
- Contribute to the development, review, and continuous improvement of citywide incident response policies, playbooks, and standard operating procedures;
- Assist NYC agencies in maturing their cyber incident response programs through direct consultation and capability assessments;
- Maintain current knowledge of cyber threat campaigns, adversary tradecraft, and emerging vulnerabilities, and share that knowledge across the team;
- Participate in on-call rotation, which may require rotational weekday/weekend coverage;
- Handle special projects and initiatives as assigned.
Qualifications
- A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position;
- Significant experience performing security events and incident detection, handling, and response in an operational environment such as SOC, CSIRT, or CERT, including experience leading incidents;
- Demonstrated experience mentoring or providing technical leadership to junior analysts or responders;
- Advanced experience reviewing and analyzing security events from diverse monitoring and logging sources, including SIEM, EDR, and cloud-native telemetry;
- Deep knowledge of packet analysis and IDS/IPS technology;
- Proven experience conducting host, network, memory, and disk forensics in enterprise environments;
- Proven experience conducting incident response and forensics in cloud environments (AWS, Azure, and/or GCP);
- Experience conducting malware analysis, including static and dynamic analysis and reverse engineering;
- Strong understanding of intrusion analysis, attacker tradecraft, and frameworks such as MITRE ATT&CK and the Cyber Kill Chain;
- Experience designing and facilitating tabletop exercises or incident response training;
- Experience with website and web application security assessment or penetration testing.