Nightwing is seeking a Cyber Incident Manager to support a U.S. Government customer’s onsite incident response missions, providing rapid investigation and resolution of cyber‑attacks for civilian government agencies and critical asset owners.
Responsibilities
- Correlate incident data to identify specific trends in reported incidents.
- Recommend defense‑in‑depth principles and practices (e.g., layered defenses, security robustness).
- Perform computer network defense incident triage, determining scope, urgency, and potential impact.
- Research and compile known resolution steps or workarounds to mitigate potential incidents.
- Apply cybersecurity concepts to detect and defend intrusions in small and large‑scale IT networks, and conduct cursory analysis of log data.
- Monitor external data sources to maintain currency of threat conditions and assess their impact on the enterprise.
- Identify incident causes and determine key questions for external entities when assessing background and infection vectors.
- Receive and analyze network alerts from various enterprise sources, determining possible causes.
- Track and document incidents from initial detection through final resolution, coordinating information with other organizational components.
- Perform shift work as needed, triaging and researching incidents for indicators of compromise and escalating to specialized analysts.
Required Skills
- U.S. citizenship.
- Active TS/SCI clearance.
- Capability to obtain DHS suitability.
- 5+ years of directly relevant experience in cyber incident management or cybersecurity operations.
- Knowledge of incident response and handling methodologies.
- Familiarity with NIST SP 800‑62 (latest revision) and FISMA standards related to incident reporting.
- Ability to prioritize incidents, investigate tactics used in phishing campaigns, and recognize gaps in reporting.
- Knowledge of general attack stages (e.g., footprinting, scanning, enumeration, escalation, persistence, exploitation, cover‑up).
- Skill in recognizing and categorizing vulnerabilities and associated attacks.
- Knowledge of basic system administration and OS hardening techniques, CND policies, procedures, and regulations.
- Understanding of different operational threat environments (script kiddies, non‑nation‑state sponsored, nation‑state sponsored).
- Familiarity with system and application security threats and attack methods (e.g., buffer overflow, mobile code, XSS, PL/SQL injections, race conditions, covert channels, replay, return‑oriented attacks, malicious code).
Desired Skills
- Knowledge of different operational threat environments (script kiddies, non‑nation‑state sponsored, nation‑state sponsored).
- Familiarity with system and application security threats and attack methods (buffer overflow, mobile code, XSS, PL/SQL injections, race conditions, covert channels, replay, return‑oriented attacks, malicious code).
Required Education
BS in Incident Management, Operations Management, Cybersecurity, or related field. High‑school diploma with 7‑9 years of incident management or cybersecurity experience.
Desired Certifications
- GCIH, GCFA, GISP, GCED, CCFP, CISSP (or equivalent).
Location
Arlington, VA
Equal Opportunity Statement
Nightwing is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other federally protected class.