Information Security Engineer - Incident Response
- Rockville, MD, USA
Encompass (IT) Security Services is a full services technology service provider located in Bowie, MD. Our services range from enterprise planning and implementation to Cyber Security. Our clients include federal, state and local governments, non-profits and other corporate entities.
Encompass offers very competitive compensation packages which includes:
- Short-Term Disability
- Long-Term Disability
- 401K - 4% match with immediate vesting
- Direct Deposit
- Educational/Training/Certification Reimbursement
- Professional Membership Fee Reimbursement
This role will be primarily responsible for conducting incident handling tasks during different phases of Computer Security Incident Response (CSIR) - monitoring, research, analysis of security alerts and events.
- Coordinate and provide expert technical support to enterprise-wide technicians to resolve cyber defense incidents; Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
- Perform analysis of log files from a variety of sources to identify possible threats to network security.
- Validate security incidents & perform defense triage to include determining scope, urgency, and potential impact; identifying the specific vulnerability, and making recommendations for remediation.
- Perform real-time incident handling tasks (e.g., forensic collections, intrusion correlation and tracking, threat analysis, and direct system remediation).
- Analyze network alerts from various sources and determine possible causes of such alerts.
- Track and document cyber defense incidents from initial detection through final resolution.
- Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, security robustness).
- Serve as technical expert and liaison to law enforcement personnel and explain incident details as required; Coordinate with intelligence Engineers to correlate threat assessment data.
- Perform cyber defense trend analysis and reporting; Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain the currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise; Write and publish after-action reviews;
- Gather and analyze information for defining requirements, specifications and issues to support the development of new policies, standards, and procedures or update existing ones.
- Work with a team of diverse individuals and cross-functional teams to solve unique and complex problems with broad impact on the business.
- Provide clear updates to management on security incidents; Investigate, document, and report on forensic investigations.
- Minimum 4 years’ experience in Information Security is required along with a minimum of 2 years of hands-on experience in at least 3 of the following:
- Identifying incidents and performing cyber defense triage
- Incident handling in all phases of incident response
- Serving as a technical expert and liaison to explain incident details
- Documenting AARs and other incident related reports
- Log correlation from various sources
- Must have excellent attention to detail and analytical skills required
- Risk management processes (e.g., methods for assessing, mitigating and accepting risks).
- Cybersecurity principles, security models, organizational requirements (w.r.t. confidentiality, integrity, availability, authentication, non-repudiation), cyber threats, risks and vulnerabilities, cryptography and cryptographic key management concepts, host/network access control mechanisms (e.g., ACLs), network access, identity, & access management (e.g., PKIs), Computer networking concepts and protocols, and network security methodologies.
- Ethical hacking principles, general attack stages; Specific operational impacts of cybersecurity lapses; programming language structures and logic.
- Basic system administration, network, preventive and hardening techniques.
- Able to communicate, verbally and in writing, complex technical issues with simplicity & clarity.
- Able to exercise discretion and maintain confidentiality.
- Proficient in reporting and answering analytical questions.
- B.A or BS degree in Computer Science\Security or related discipline (Masters preferred).
- Industry standards such as GCIH or related GIAC (preferred but not required).
- Selected applicant may be subject to Public Trust clearance and may need to meet eligibility requirements for access to sensitive information.
All your information will be kept confidential according to EEO guidelines.
Get notified of other positions
Like us on Facebook.com/EncompassSecure
Follow us on Twitter @EncompassSecure