Jobs and Careers
GE

SOC Lead Incident Responder

General Dynamics Information Technology
Washington, United Statesfull_timeVerifiedPosted 3 Jul 2024
💰 $204,360/yr($134,597/yr$204,360/yr)

About the role

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Suitability:

Public Trust/Other Required:

Job Family:

Cyber Security

Job Qualifications:

Skills:

Cyber Defense, Cybersecurity, Cyber Threat Intelligence

Certifications:

Experience:

5 + years of related experience

US Citizenship Required:

Yes

Job Description:

GDIT has an opportunity for a dynamic and collaborative Lead Incident Responder to join our team. The Lead Incident Responder will be a member of our team supporting the Administrative Office of the U.S. Courts (AOUSC), Information Technology Security Office (ITSO). As a team member, the Lead Incident Responder will work collaboratively with federal and contractor staff to ensure the SOC effectively meets or exceeds the security operations requirements of each shift in a timely and comprehensive manner.

The Lead Incident Responder provides advanced technical support to forensics and incident response teams during the initial response to any cyber threats against the AOUSC’s enterprise. The Lead Incident Responder will work as part of a team that participates in any investigations into potential and actual cyber events observed in the enterprise and serve in a leadership capacity (both executing and providing guidance for) to conduct analysis and evaluate findings to enhance the security posture of the enterprise. The Lead Incident Responder will assist in providing guidance to junior analysts in a technical and developmental capacity.

The ideal candidate will possess a deep understanding of cybersecurity threats, incident response procedures, and forensic analysis. This role is critical in leading the response to security incidents, coordinating with various teams, and improving our overall security posture.

HOW AN SOC LEAD INCIDENT RESPONDER WILL MAKE AN IMPACT:

  • Incident Response Leadership:
    • Lead the incident response team in identifying, analyzing, and responding to security incidents.
    • Develop and maintain incident response playbooks and procedures.
    • Ensure effective communication and coordination during incident handling.
  • Threat Detection and Analysis:
    • Monitor and analyze security alerts from various sources, including SIEM, IDS/IPS, and endpoint protection systems.
    • Conduct in-depth forensic analysis to determine the root cause and impact of security incidents.
    • Perform malware analysis and reverse engineering to understand attack mechanisms.
  • Incident Management:
    • Coordinate incident response efforts across different teams and stakeholders.
    • Document and report incidents, including the steps taken to mitigate and resolve them.
    • Conduct post-incident reviews and lessons-learned sessions to improve response strategies.
  • Security Enhancements:
    • Identify gaps in existing security controls and recommend improvements.
    • Stay current with the latest threat intelligence and incorporate it into incident response practices.
    • Develop and deliver training programs to enhance the skills of the incident response team.
  • Collaboration and Communication:
    • Work closely with other SOC team members, IT, and business units to ensure comprehensive incident response.
    • Communicate effectively with executive management, providing updates on incident status and impact.
    • Establish and maintain relationships with external partners and law enforcement as needed.

WHAT YOU’LL NEED TO SUCCEED:

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field. Advanced degree preferred.
  • Minimum of 5 years of experience in cybersecurity, with at least 2 years in a lead incident response role.
  • Proven experience in handling complex security incidents and conducting forensic investigations :
  • Strong knowledge of cybersecurity principles, threat landscapes, and attack vectors.
  • Proficiency with security technologies such as SIEM, IDS/IPS, EDR, and forensic tools.
  • Experience with scripting and automation to streamline incident response processes.
  • Familiarity with regulatory requirements and industry standards
  • Relevant certifications include CISSP, CISM, GCFA, GCIH, or equivalent.
  • Excellent leadership, communication, and interpersonal skills.
  • Strong analytical and problem-solving abilities.
  • Ability to work under pressure and manage mult

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

General Dynamics Information Technology

View company profile →