Cyber Security Incident Response - Professional
Freddie MacAbout the role
At Freddie Mac, our mission of Making Home Possible is what motivates us, and it’s at the core of everything we do. Since our charter in 1970, we have made home possible for more than 90 million families across the country. Join an organization where your work contributes to a greater purpose.
Position Overview:
Join Freddie Mac's Cyber Operations Security Incident Response Team (CSIRT) to enhance system security and reliability! The ideal candidate will possess strong analytical skills and a commitment to enhancing security measures. This role requires on-call rotation.
Our Impact:
We minimize information risk by responding to security incidents, investigating and mitigating threats. This position offers an opportunity to improve the Confidentiality, integrity, and availability of our systems.
Your Impact:
- Respond to and investigate security incidents.
- Mitigate threats and support recovery efforts.
- Conduct in-depth investigations and root cause analyses
Key Responsibilities
- Create security documentation and workflow diagrams.
- Mandatory on-call rotation for 24/7 incident response.
- Manage security incidents and assess risk impacts.
- Communicate incident details and deliver post-incident reports.
Technical Responsibilities
- Secure company resources across physical, virtual, Cloud, and SAAS infrastructures.
- Automate response workflows using scripting and SOAR platforms.
- Respond to threats and review SIEM use cases.
Leadership Responsibilities
- Develop and update CSIRT playbooks.
- Plan and track process improvements for post incident activities.
- Ensure 24/7/365 coverage, including evenings and weekends if needed
Communication and Collaboration
- Collaborate with team leads and refine response workflows.
- Build relationships across security teams.
- Collaborate on SOPs and runbooks.
- Participate in tabletop exercises
Qualifications:
- College degree or equivalent experience required
- 2-4 years in Information Technology, preferably Information Security.
- SANS GCIH certification Required
- 1+ years in security operations or related field.
- Knowledge of security principles and response strategies.
- Familiarity with SOAR platforms and cloud security practices.
- Strong communication skills for technical and non-technical audiences
Preferred Competencies and Certifications
- SANS GCED, GCLD, GCIA preferred.
- Additional certifications like Security+, CEH are advantageous
- Basic scripting and programming knowledge
- Familiarity with tools like Splunk, CrowdStrike, Proofpoint, and Swimlane<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s