Jobs and Careers
ED

Cybersecurity Operations Task Lead

Edgewater Federal Solutions
United Statesfull_timeVerifiedPosted 7 Aug 2024

About the role

Overview

Edgewater Federal Solutions is currently seeking a Cybersecurity Operations Task Lead to provide cybersecurity operations leadership, management, and support to the Cybersecurity Operations (CSO) Division comprised of Cyber Threat Intelligence (CTI), Cyber Threat Hunt (CTH), Red Team (RT), Detection Engineering (DET), 24x7x365 Cyber Security Operations Center (CSOC), Fusion Incident Response (IR), and Forensics specialists for Edgewater Federal government contracts.

 

Responsibilities

Primary Responsibilities:

    • Provide overall technical expertise and oversight, leadership, management, work assignment, organization, and administrative duties for a combined team of 30 cyber security specialists specializing in CTI, CTH, RT, DET, CSOC, Fusion IR, and Forensics, that together comprise the CSO Division.
    • Provide robust program management planning, oversight, metrics, and reporting for large division and enterprise-wide initiatives, audits, assessments, and capability maturity in various tools including Microsoft SharePoint, Excel, PowerPoint, Power Automate, and Power BI.
    • Ensure the complete, accurate, and timely delivery and/or maintenance of all contract Deliverables and ad hoc work products including threat briefings, artifacts such as strategy documentation, playbooks, incident tickets and reports, after action reports, shift change and daily mitigation reports, chain of custody forms, forensics reports, shift schedules, and select ad hoc reports and executive briefings as required.
    • Ensure the contract team supports the Client’s incident response (IR) capabilities including incident response policy, plan, process, procedures, guidelines for communications, team structure, relationship management between incident response teams, service creation or enhancement with scope definitions, on-going training needs and documentation creation and maintenance.
    • Ensure the contract team provides Tier-1 cybersecurity detection and response operational support to identify and respond to potentially malicious, misuse and abuse of anomalous activities across the Client’s operating environments, including initial detection, identification, triage, and mitigation of security related incidents impacting the confidentiality, integrity and availability of the Client’s network and systems.
    • Ensure the contract team provides Tier-1 cybersecurity detection and response operational support to identify and accurately categorize cyber security incidents, integrate, and utilize other NIH enterprise security capabilities, support threat mitigation techniques and incident response, minimize ticket/incident backlog in NIH ticketing systems, and notify appropriate authorities of incidents and their severity within established timeframes and guidelines.
    • Ensure the contract team provides Tier-2 and Tier-3 IR and cyber fusion operational support including Cyber Threat Intelligence (CTI), Cyber Threat Hunt (CTH), Red Team (RT), Detection Engineering (DET), Fusion Incident Response (IR), and Forensics. This also includes counterintelligence/insider threat support and research and development.
    • Ensure the contract team provides CTI services to the Client including proficient knowledge of the intelligence lifecycle, threat modeling, kill chain, MITRE ATT&CK Framework, etc. This also includes:
      • Providing CTI collection, monitoring, analysis, and reporting, operational support through expert level analysis with regards to APTs, indicators of compromise (IOCs), adversary infrastructure, and intelligence gathering.
      • Providing targeted attack detection and analysis, including the development of custom signatures and log queries and analytics for the identification of targeted attacks.
      • Ability to formulate and understand intelligence requirements provided by the Client’s intelligence consumers as well as ongoing collaboration with the Vulnerability Management team to address and mitigate vulnerabilities actively leveraged by malicious actors.
    • Ensure the contract team provides CTH services to the Client, including day-to-day cyber threat hunt focused on host-based investigations, deceptive mechanisms, and network forensics to detect and mitigate advanced cyber threats like Advanced Persistent Threats (APTs) and organized crime groups, among others.
    • Ensure the contract team provides Red Team services to the Client, including conducting RT engagements to simulate and emulate tradecraft and techniques employed by adversaries the Client is, or should be, concerned with to ensure policies, tools and team structure are well suited to defend against various adversaries.
    • Ensure the contract team provides Detection Engineering services to the Client including Security Information and Event Management (SIEM) with correlation algorithms f

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Edgewater Federal Solutions

View company profile →