Incident Responder, Onsite

PowerToFly

Virginia (MN)

On-site

USD 113,000 - 188,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Deloitte is seeking an Incident Responder to join our Cyber team in the GPS practice. The role focuses on executing incident response across IoT/OT environments, coordinating end-to-end responses, malware triage, and reporting, with onsite work in Herndon, VA. A Secret clearance and 2+ years of security experience are required.

Applicants should show independence, strong communication, and the ability to mentor teammates in a fast-paced, collaborative setting.

Qualifications

  • Bachelor's degree.
  • Must be legally authorized to work in the United States without sponsorship.
  • Active Secret security clearance required.
  • Ability to work onsite up to 5 days a week in Herndon, VA.
  • 2+ years of experience in IT security events analysis for IT/IoT/OT.
  • Experience with Windows, OS X, Linux and basic Windows Active Directory.
  • Knowledge of TCP, UDP, ICMP, BGP, MPLS, DNS, DHCP, SMTP, HTTP/HTTPS.
  • Experience with security event logs and SIEM platforms.
  • Proficiency in PCAP data analysis.
  • Experience implementing mitigations in enterprise networks.

Responsibilities

  • Execute the client Incident Response Management Program per requirements.
  • Coordinate end-to-end responses to security events and incidents identified by the SOC.
  • Perform initial malware analysis and triage support.
  • Operate incident analysis tools and systems.
  • Adhere to reporting requirements for declared incidents.
  • Lead projects or workstreams and mentor others.

Skills

Incident response
SIEM
PCAP analysis
Team collaboration
Mentoring

Education

Bachelor's degree

Tools

SIEM platforms
PCAP tools
Windows/Linux OS
Active Directory basics

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work You'll Do
  • The Incident Responder will execute the client Incident Response Management Program in accordance with client requirements and in alignment with the six-phase Incident Response process: planning, identification and declaration, containment, eradication, recovery, and follow-up.
  • The Incident Responder will perform incident response activities related to Internet of Things (IoT) and Operational Technology (OT) devices, including coordinating and managing end-to-end responses to security events and incidents identified by the SOC or reported to the SOC; performing initial malware analysis and triage support; operating incident analysis tools and systems; and adhering to reporting requirements for all declared significant incidents.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlinesAbility to mentor and provide clear guidance to others
The Team

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.

Qualifications

Required:

  • Bachelor's degree
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
  • Active Secret security clearance required
  • Ability to work onsite up to 5 days a week in Herndon, VA.
  • 2+ years of experience within the following:
    • Analyzing information technology, IoT, and OT security events to discern legitimate security incidents from non-incidents. This includes identifying malicious code and activities present within computer systems and/or enterprise networks.
    • Working knowledge of various operating systems (e.g., Windows, OS X, Linux) commonly deployed in enterprise networks. A conceptual understanding of Windows Active Directory is also required.
    • Working knowledge of network communications and routing protocols (e.g., TCP, UDP, Internet Control Message Protocol (ICMP), Border Gateway Protocol (BGP), Multi-Protocol Label Switching (MPLS)), as well as common internet applications and standards (e.g., Simple Mail Transfer Protocol (SMTP), DNS, DHCP, SQL, Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS)).
    • Experience working with various event logging systems and proficiency in security event log analysis. Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also required.
    • Proficiency in utilizing various Packet Capture (PCAP) applications/engines and in the analysis of PCAP data.
    • Experience with the identification and implementation of countermeasures or mitigating controls for deployment in enterprise network environments.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $113,000 to $188,400.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Supply Chain & Industrial Control Subject Matter Expert I
Cyber Supply Chain & Industrial Control Subject Matter Expert I

PowerToFly • Virginia (IL)

On-site
USD 131,000 - 218,000
Cyber Senior Consultant - Technology Resilience
Cyber Senior Consultant - Technology Resilience

PowerToFly • California (MO)

On-site
USD 68,000 - 134,000
Onsite Incident Responder for IoT/OT Security
Onsite Incident Responder for IoT/OT Security

PowerToFly • Virginia (MN)

On-site
USD 113,000 - 188,000
Intelligence and Protection Technical Threat Analyst
Intelligence and Protection Technical Threat Analyst

PowerToFly • Maryland

On-site
USD 81,000 - 148,000
Incident Response Lead
Incident Response Lead

Leidos • Ashburn (VA)

On-site
USD 110,000 - 195,000
Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance)
Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance)

PowerToFly • Virginia (IL)

On-site
USD 138,000 - 230,000
Discretionary annual incentive program
Cyber - Physical Security - Senior Consultant
Cyber - Physical Security - Senior Consultant

PowerToFly • Arizona

On-site
USD 105,000 - 208,000
Discretionary annual incentive
Security Team Manager, Forensics and Investigations
Security Team Manager, Forensics and Investigations

PowerToFly • Virginia (IL)

On-site
USD 113,000 - 188,000
Cyber Security & Risk Strategy Consultant
Cyber Security & Risk Strategy Consultant

PowerToFly • Alabama

On-site
USD 83,000 - 163,000
Cyber Security & Risk Strategy Senior Consultant
Cyber Security & Risk Strategy Senior Consultant

PowerToFly • Alabama

On-site
USD 105,000 - 208,000