Cyber Defense Forensics Lead

Tyto Athene, LLC

Ashburn (VA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A cybersecurity firm is seeking a Cyber Defense Forensics Lead in Ashburn, VA to lead critical cyber incident investigations. The role requires extensive experience in cybersecurity, especially in incident response and threat analysis. Candidates should have strong skills in forensics and mentoring junior analysts. A TS/SCI clearance is mandatory. This full-time position offers a chance to support law enforcement and enhance the firm's cyber defense capabilities.

Qualifications

  • Minimum of seven years of professional cybersecurity experience.
  • Expertise in incident response and threat analysis.
  • Strong understanding of CIA triad principles.

Responsibilities

  • Lead analysis and investigation of cybersecurity incidents.
  • Utilize security tools for analysis and triage of alerts.
  • Coordinate with law enforcement and external parties.

Skills

Incident response
Insider threat investigations
Forensics
Threat analysis
Cybersecurity monitoring
Evidence capturing
Mentoring junior team members

Education

CISSP - Certified Information Systems Security Professional
GCFA - GIAC Certified Forensic Analyst
GCFE - GIAC Certified Forensic Examiner
GNFA - GIAC Network Forensic Analyst

Tools

SIEM platforms
Endpoint threat detection tools
Insider threat detection tools
Host-based forensic tools
Intrusion detection and analysis capabilities

Job description

Cyber Defense Forensics Lead

Tyto Athene is searching for a Cyber Defense Forensics Lead to support a law enforcement customer in Ashburn, VA. You will play a critical role in leading in-depth analyses and responding to incidents from cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for other analysts, helping guide them through more complex and high-priority incidents.

Responsibilities
  • Lead cross-functional teams to perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize security tools to analyze, investigate, and triage security alerts
  • Coordinate the monitoring of our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Utilize advanced tools, such as digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Serve as the primary incident point of contact with law enforcement, third-party vendors, and other external parties
  • Coordinate tasking from Federal leadership
  • Conduct post-incident analysis and lessons learned to identify improvement opportunities
  • Develop or tune detection rules or signatures to improve the effectiveness of security monitoring and collaborate with engineering teams to implement them
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research on emerging threats and vulnerabilities to aid their prevention and mitigation
  • Assist in developing and implementing initiatives that will enhance the SOC’s performance (e.g., SOPs, playbooks, capability deployments)
  • Escalate SOC performance issues or risks to management
  • Provide guidance and mentorship to Tier 1 and Tier 2 SOC Analysts to enhance their skills and capabilities
Required Qualifications
  • Minimum of seven (7) years professional cybersecurity experience with strong expertise in incident response, insider threat investigations, forensics, and threat analysis.
  • Minimum of five (5) years hands-on security operations experience, with experience in the last two years including:
  • Host-based and network-based monitoring
  • Insider threat detection tools
  • Host-based forensic tools
  • SIEM platforms
  • Intrusion detection and analysis capabilities
  • Endpoint threat detection tools
  • Security operations ticketing tools
  • Proven experience identifying and analyzing anomalous security activities.
  • Demonstrated ability to create insider-threat dashboards, reports, and workflows.
  • Strong experience capturing evidence, documenting results, and escalating issues when necessary.
  • Experience mentoring and training junior team members.
  • Strong understanding of confidentiality, integrity, and availability (CIA triad) principles and best practices.
  • CISSP - Certified Information Systems Security Professional
  • GCFA - GIAC Certified Forensic Analyst
  • GCFE - GIAC Certified Forensic Examiner
  • GNFA - GIAC Network Forensic Analyst
Clearance
  • TS/SCI Clearance required
Seniority Level

Mid-Senior level

Employment Type

Full-time

Job Function

Information Technology

Industries

IT Services and IT Consulting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Lead
Senior Cyber Lead

Tyto Athene, LLC • Linthicum (MD)

On-site
USD 100,000 - 140,000
Health/Dental/Vision Insurance
401(k) match
Paid Time Off
+1
Digital Forensics Lead
Digital Forensics Lead

Agile Defense • Reston (VA)

On-site
USD 110,000 - 150,000
Digital Forensics and Incident Analyst (TS)
Digital Forensics and Incident Analyst (TS)

Agile Defense • Washington

On-site
USD 120,000 - 160,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicisresources • Boston (MA)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Chicago (IL)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Miami (FL)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Philadelphia

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Atlanta (GA)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • New York (NY)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Groupe Holdings B.V • United States

Remote
USD 100,000 - 120,000