Sr Cyber Def Incident Respondr

Location: OWINGS MILLS, MD, United States
Organization: Exelon Business Servcs Co, LLC
Job ID: 224453
Date Posted: Feb 7, 2020

Share: mail

Job Description

Description

PRIMARY PURPOSE OF POSITION:
Provides deep technical expertise to provide Level 2/3 Cyber Security Incident Handling, Response and Remediation.

Designs, develops and implement cyber security capabilities to investigate, identify and actively defend Exelon infrastructure against  Advanced Persitent Cyber Threats.Works closely with Incident Handling and Response Team Lead, Security Monitoring and Forensic Analysis teams to meet/exceed service levels.

MAJOR ACCOUNTABILITIES:
- Perform and document work activities relating to level 2/3 CyberSOC Incident Response, Active Defense Cyber investigations and identification of indicators of advanced malware and persistent threats. Perform activities required to manage service level agreements.
- Work closely with Cyber Defense Incident Response Team Lead, Digital Forensics & eDiscovery Team Lead, Security Monitoring Team Lead to coordinate activities and services.
- Support the identification, containment, eradication, & recovery of sophisticated level 2/3 incidents. Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents.  Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.  Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security.
Coordinate incident response functions.  Perform cyber defense incident triage, to include determining scope, urgency, and potential impact; identifying the specific vulnerability; and making recommendations that enable expeditious remediation.  Track and document cyber defense incidents from initial detection through final resolution.  Collect intrusion artifacts (e.g., source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise.
- Update Incident Management & trouble tickets, providing timely & accurate status updates of ongoing activities
- Recommend short & long term adjustments to controls for immediate & future identification, containment & remediation.  Coordinate with intelligence analysts to correlate threat assessment data. 
- Provide direction on tuning of signatures, rules, alerts, parsers, & custom scripts.
Contribute to IR process definition & development & maintenance of documented procedures & procedures, including process integration with managed security service providers, 3rd party vendors, internal IT organizations, & business units. Write and publish cyber defense techniques, guidance, and reports on incident findings to appropriate constituencies. Perform cyber defense trend analysis and reporting. 

Qualifications

POSITION SPECIFICATIONS 

Minimum:
- Bachelor’s Degree in Computer Science, Information Technology (IT), or a related discipline, and typically 5 to 8 years of solid, diverse experience in cyber security Incident Response, or equivalent combination of education and work experience.
- One or more of the following: GIAC Certified Intrusion Analyst – GCIA, GIAC Certified Incident Handler – GCIH
- Knowledge of data backup, types of backups (e.g., full, incremental), and recovery concepts and tools.
- Knowledge of how network services and protocols interact to provide network communications.
- Knowledge of incident categories, incident responses, and timelines for responses.
- Knowledge of incident response and handling methodologies.
- Knowledge of intrusion detection methodologies and techniques for detecting host and network-based intrusions via intrusion detection technologies.
- Knowledge of network protocols (e.g., Transmission Control Protocol/Internet Protocol [TCP/IP], Dynamic Host Configuration Protocol [DHCP]), and directory services (e.g., Domain Name System [DNS]).
- Knowledge of network traffic analysis methods.
- Knowledge of packet-level analysis.
- Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
- Knowledge of what constitutes a network attack and the relationship to both threats and vulnerabilities.
- Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution).
- Knowledge of basic system administration, network, and operating system hardening techniques.
- Knowledge of general attack stages (e.g., foot printing and scanning, enumeration, gaining access, escalation or privileges, maintaining access, network exploitation, covering tracks).
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Knowledge of an organization's information classification program and procedures for information compromise.
- Knowledge of OSI model and underlying network protocols (e.g., TCP/IP).

Preferred:
- Graduate degree in cyber security or related area of expertise.
- Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff.
- Direct experience in network security (SOC, SIRT, CSIRT) investigating targeted intrusions through complex network segments.
- CISSP or SSCP designation
- Demonstrated skill of identifying, capturing, containing, and reporting malware.
- Demonstrated skill in performing damage assessments.
- Skill in using security event correlation tools.
- Demonstrated knowledge of cyber defense policies, procedures, and regulations.

----


Share: mail

Similar Jobs

Manager - IT Strategy & Planning

BALTIMORE, MD, United States
Exelon Business Servcs Co, LLC

Sr. Manager - IT Strategy & Planning

BALTIMORE, MD, United States
Exelon Business Servcs Co, LLC

Senior Project Manager

BALTIMORE, MD, United States
Exelon Business Servcs Co, LLC

Sr Analyst - OMS IT

Baltimore, MD, United States
Exelon Business Servcs Co, LLC

Cyber Defense Analyst - Real Time

OWINGS MILLS, MD, United States
Exelon Business Servcs Co, LLC

Technical Analyst IT

Baltimore, MD, United States
Exelon Business Servcs Co, LLC

Sr Cyber Def Incident Respondr

OWINGS MILLS, MD, United States
Exelon Business Servcs Co, LLC

Lead Analyst IT - Service Portfolio Management

BALTIMORE, MD, United States
Exelon Business Servcs Co, LLC

Lead Analyst IT

MD, United States
Exelon Business Servcs Co, LLC

Technical Analyst IT - Real Time Infrastructure Projects

Baltimore, MD, United States
Exelon Business Servcs Co, LLC

Manager IT - Service Portfolio Management

BALTIMORE, MD, United States
Exelon Business Servcs Co, LLC

Lead Analyst IT - Oracle Integration Cloud (OIC)

WINDSOR MILL, MD, United States
Exelon Business Servcs Co, LLC

Lead Analyst IT - Oracle ( CX and CDM)

WINDSOR MILL, MD, United States
Exelon Business Servcs Co, LLC

Sr. Analyst IT - Customer Systems Analyst

Baltimore, MD, United States
Exelon Business Servcs Co, LLC

Frequent Job Searches

Recently Viewed Jobs

Most Recent Job Searches

Relevant Jobs

Personalize this site