Who we are:
MGT is a leading provider of technology and advisory solutions serving state, local, and education government agencies (SLED) across the United States. Through client partnerships, MGTs almost 1,200 employees impact communities for good by managing and securing critical networks, solving complex human capital and fiscal problems, elevating education systems, and advancing equity as a performance imperative. MGT partners with thousands of agencies as a trusted advisor delivering solutions that improve technology, operational, and economic performance to help communities thrive.
Founded in 1975, MGT initiated an ambitious restart in 2016, broadening the solutions portfolio to provide the most specialized solutions, tackling the most mission-critical problems that live at the top of the public agency leadership agenda. MGT drives over 20% compound annual organic growth and utilizes programmatic mergers and acquisitions to grow capabilities, attract top talent, and accelerate growth scale. Since 2020, MGT has successfully completed 13 acquisitions, driving over 60% compound annual inorganic growth.
Celebrating its 50th year in 2025, the firm attracts exceptional talent and empowers them to exceed client expectations as they navigate the dynamic demands of the clients we serve. Hear more about MGTs culture in the words of our employees.
Role & responsibilities:
- Perform incident response analysis uncovering attack vectors involving a variety, malware, data exposure, and phishing and social engineering methods.
- Participate in the remediation of incidents and responses that are generated from live threats against the enterprise.
- Recording and reporting all incidents per compliance, department policy and legislation.
- Creating and tracking network incidents and investigations through completion
- Serve as a point person for Incident Management, providing coordination and assignment of activity for all entities party to incident response event
- Monitor security events received through alerts from SIEM or other security tools
- Revise alerts escalated by end users
- Carry out Level 2 triage of incoming Incidents (initial IR assessment of the priority of the event, initial determination of incident nature to determine risk and damage or appropriate routing of security or privacy data request)
- Maintain assigned ticket queue
- As needed, serve as the incident response event point person and liaison to enterprise teams, responding to crisis or urgent situations aimed at mitigating, preparing for, responding to, and recovery systems. Will also coordinate resources, activities, and timelines during security incidents to ensure a unified structured response to incidents (I.e., data breaches, ransomware events, etc.)
- Review and recommend technical, process, and physical controls to counteract damage from breach events
- Supports/develops reports during and after incidents, which include all actions taken to properly mitigate, recover and return operations to normal operations
- Support forensic investigators and application security analysts in reactive and proactive Threat Hunting engagements, performing endpoint, network, and log analysis
- Responsible to support clients in deploying SIEM solution by installing agents on endpoints, servers and integrating the log sources.
- Managing the health of SIEM, EDR solution deployed for clients. Troubleshooting any issues identified within the SIEM and EDR platforms
Preferred candidate profile:
- 5+ years of relevant work experience
- Bachelors Degree or 2 additional years of experience
- Good to have Active Security Industry Certifications (Security+. CEH, CISSP, CSA, etc.) is plus
- Demonstrate proficiency in the Incident Response Process as well as the performance of threat hunting and SOC operations.
- IDS monitoring and analysis, analyze network traffic, log analysis, prioritize and differentiate between potential intrusion attempts and false alarms
- Good understanding of system log information and what it means, where to collect specific data/attributes as necessitated per Incident Event (host, network, cloud, etc)
- Strong understanding of enterprise networking (host based firewalls, anti-malware, hids, IDS/IPS, proxy, WAF), Windows and Unix/Linux systems operations, TCP / IP protocols, experience providing analysis and trending of security log data
- Experience creating and tracking investigations to resolution
- Experience with vulnerability scanning tools such as Tenable Nessus, Tenable.IO, Tenable.SC, Qualys Guard, etc.
- Experience with Endpoint security solutions, Antivirus Solutions, EDR Tools
- Advisory experience in compliance or regulatory frameworks (I.e. FISMA, PCI, GDPR, NIST, ISO)
- Solid understanding of application, database, authentication, and network security principles
- Understanding of system and application security, systems and network administration and operating system hardening techniques
- General cyber-attack stages, profiling techniques and techniques for detecting host and network-based intrusions
- Knowledge of evidence recovery techniques, preservation of evidence integrity, and collection of forensically sound collection of images, logs, and other critical components to discern possible mitigation/remediation of systems
- Ability to perform or direct malware analysis, Threat Hunting, incident response