Responsibilities:
• Lead and assist in incident response investigations through all phases (detection, containment, eradication, recovery, lessons learned) to ensure the confidentiality, integrity, and availability of the OA DCGS weapon system.
• Utilize ELK/Elastic Stack to perform log analysis, threat detection, and investigations; Create and maintain security incident reports and dashboards.
• Escalate and document internal/external security incidents through appropriate ticketing and reporting processing
• Design, implement, and maintain cybersecurity Standard Operating Procedures (SOPs) and incident response playbooks
• Maintain documentation of Incident Response (IR) processes and case notes; Ensure security testing and evaluations are completed and properly documented.
• Support proactive threat hunting and vulnerability assessments
• Analyze and correlate logs from varied data sources to identify patterns and anomalies
• Apply knowledge of Zero-Day vulnerabilities and Common Vulnerabilities and Exposures (CVEs) to incident handling and remediation
• Collaborate with cross-functional teams and external stakeholders as needed
• Provide guidance for securing information systems and support cyber vulnerability penetration assessments.