Logo for Intecon
SOC Cyber Defense Incident Responder (531) – Advanced
Intecon
Posted on 8/30/2024
Description
Overview: Location: United States - Schriever Space Force Base (SFB) in Colorado Springs, Colorado Job Type: Full-Time Salary Range: $50–150 per hour Job Posting Estimated Close Date: 8/30/2024 INTECON, LLC is seeking a highly motivated SOC Cyber Defense Incident Responder to join the Delta 6 Security Operations Center (SOC) team. This critical role involves monitoring and analyzing threats 24/7, participating in cyber incident response teams, and developing and validating cybersecurity tactics and procedures to protect the USSF space mission systems from evolving cyber threats. The position requires strong analytical skills, the ability to work under pressure, and adherence to strict security protocols. Must possess Top Secret/Sensitive Compartmented Information (TS/SCI) clearance level. Key Responsibilities: Monitor and Analyze Threats: Conduct 24/7/365 Threat and Intrusion Detection Monitoring and Analysis of all assigned mission systems, ensuring two DCO consoles are always monitored, as per the PWS requirements.Incident Response: Participate in cyber incident response teams (CIRTs), providing technical assistance in determining the nature and impact of cyber events/incidents and developing Courses of Action (COAs) for mitigation and/or remediation.Develop and Validate Cyber Tactics: Draft and validate Delta 6 SOC level DCO Tactics, Techniques, and Procedures (TTPs); Crew Aids, Standard Operating Procedures (SOPs), and Operational Instructions (OIs).Support Continuity of Operations: Participate in and support continuity of operations (COOP) activities up to three times annually, involving real-world and exercise scenarios that require relocating to conduct DCO activities, as outlined in the PWS.Exercise Planning and Participation: Assist with planning and participating in all exercises that require DCO involvement by the Delta 6 SOC, recommending system hardening techniques and signature deployments.Cyber Threat Hunting: Plan and conduct cyber threat hunting by leveraging threat intelligence, applying hunt techniques and methodologies on assigned mission systems to detect, track, and disrupt Advanced Persistent Threats (APTs).Documentation and Reporting: Develop Microsoft PowerPoint presentations and draft papers on Delta 6 Defensive Cyber Operations topics. Submit Weekly Activity Reports and Monthly Trend Analysis Reports detailing current lines of effort, task status, and findings from cyber defense activities.Policy and Compliance Updates: Monitor for relevant order releases during non-duty hours and notify Delta 6 Government personnel of orders requiring immediate attention and action. Ensure compliance with updated DOD Cybersecurity Services Evaluator Scoring Metrics (ESM) and CJCSM 6510.01B guidelines.Operational Communication: Ensure consistent, thorough, and complete shift change turnovers, including briefing active cyber events and incidents at each shift, updating cyber event and incident dashboards, and briefing planned or active DCO missions.Accreditation Support: Assist and support the government in maintaining DOD Tier 2 Cyber Security Service Provider (CSSP) accreditation, participating in accreditation inspection efforts and addressing post-accreditation findings. Qualifications: A BS degree in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science, from an ABET accredited or CAE designated institution fulfills the educational requirement. CySA+ or CFR or GCFA or GCIA or GDSA or GCIH or GICSP or CCEAdvanced certification as a Cyber Defense Incident Responder (NIST: PR-IR-001); additional certifications in cybersecurity fields such as CISSP or CISM are highly valued.At least 15 years in active cyber defense roles with a focus on incident response and threat monitoring in a security operations center environment.Proficiency in Security Incident and Event Management (SIEM) systems, Intrusion Detection and Prevention Systems (IDPS), protocol analyzers, and cybersecurity incident handling standards as per CJCSM 6510.01B and DODI 8530.01. Benefits: Comprehensive Group Health Plans (Medical, Dental, and Vision) coverage. Company-paid Short-Term and Long-Term Disability, Life, and AD&D Insurance. Flexible Spending Accounts and Supplemental Plans Available. Company-paid Training and Development Programs. Generous Paid Time Off, Holiday Pay, and Sick Leave. 401k Retirement Plan with Company Match. Critical Illness and Accident Insurance. Employee Assistance Program. About INTECON: INTECON (Integrity Consulting), founded in 1999, is a wholly owned subsidiary of Aspetto, Inc. Aspetto is a leading product and technology firm known for its strategic enterprise life-cycle support. With expertise in the acquisition, design, deployment, and sustainment of Federal and DoD tech and tactical systems, Aspetto has made a significant impact since its inception in 2008. As an 8(a), HUBZone, and ISO 9001:2015 certified company, and a three-time INC.5000 awardee, Aspetto offers an impressive range of capabilities, including Enterprise IT & Cloud-Based Technologies, Software Development & Cybersecurity, Data & Analytics, Intelligence & Professional Services, Logistics, and Tactical Equipment. Together, Aspetto and INTECON strive to drive innovation, preserve quality standards, and demonstrate an unwavering commitment to our nation's security. Our client-centric approach prioritizes innovative, responsive solutions that consistently exceed expectations. INTECON is proud to be an Equal Opportunity Employer committed to fostering diversity and inclusivity. We firmly uphold the principle of Equal Pay for Equal Work, without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, eligible veteran status, or any other protected characteristic. We welcome qualified applicants from all backgrounds and strive to create a workplace where everyone feels valued and respected.

More Similar Roles...

    Want more remote roles like this one sent to you?