Job Title : Deputy Cyber Incident Response Team (CIRT) Manager
Location : Pensacola, FL - Hybrid
Duration : Contract
Clearance : Active TS with SCI Eligibility required.
Job Description :
The Deputy Cyber Incident Response Team (CIRT) Manager ensures exceptional service for managed services customers and helps drive employee engagement for CIRT staff members. They will help coordinate the daily activities of CIRT staff; orient, train, and mentor staff; monitor incident management queues; address client escalation issues; and interface with clients as needed. The CIRT Deputy Manager is expected to be process oriented and accountable for the overall success of the CIRT's Cyber Defense Mission.
Responsibilities include :
- Support managing CIRT team consisting of up to 30 cyber defense analysts providing cyber detection, incident response, and recovery coordination services to the customer.
- Lead activities and technical direction of CIRT staff to diagnose and resolve client enterprise cyber alerts
- Field escalated customer issues and resolve or refer to specialized experts as needed
- Monitor and report the status of tickets and other cyber defense tasks assigned to the CIRT and ensuring items are coordinated, logged, tracked, and resolved appropriately.
- Provide input on process improvements and contribute to the technology road map for the strategic plan.
- Perform metrics trend analysis and reporting; guide resultant process improvement.
- Communicate policies, expectations, and feedback to CIRT staff
- Facilitate a high-performance team environment and employee engagement
- Guide and coordinate projects requiring scheduling
- Contribute to the development, communication and implementation of policies, procedures, best practices, recommendations, and guidelines for standards.
- Conduct individual meetings with team members to address performance, training needs, set expectations, and facilitate a 2-way dialogue regarding the team members' experience
- Other duties as assigned and required.
Required Skills :
Must be a U.S. CitizenThis position requires an active Top Secret security clearance with SCI eligibility.Must be able to obtain Client suitability prior to starting employment.10+ years of directly relevant experienceComputer Emergency Response Team (CERT / CIRT) hands-on experienceCurrent experience with network intrusion detection and response operations (Protect, Defend, Respond and Sustain procedures)Hands-on experience in the detection, response, mitigation, and / or reporting of cyber attacks affecting client networksComputer network surveillance / monitoringKnowledge and understanding of network protocols, network devices, multiple operating systems, and secure architecturesFamiliar with System log analysis, computer evidence seizure, computer forensic analysis, and data recoveryExperience with current cyber threats and the associated tactics, techniques, and procedures used to infiltrate computer networksExcellent verbal and written communication skillsEfficient delegation and task prioritizationAbility to interview and select employees in accordance with company guidelines and EEOC commitmentsAbility to coordinate and facilitate staff trainingAbility to provide feedback, coach employee performance, and effectively implement disciplinary action as neededAbility to manage and resolve conflicts as they ariseDemonstrated ability to document processesThe ability to respond to crises efficiently and objectivelyProficiency with MS Office ApplicationsMust be able to work collaboratively across agencies and physical locationsDesired Skills :
Current experience with SplunkExperience supporting Client, Federal Civil, Intelligence and / or DoD CustomersComputer Forensics experienceMalware reverse engineering experienceExperience with Risk and Opportunity managementScripting experience (python, Perl etc.)Experience with process development and deploymentPrior experience with data visualization products such as Analyst NotebookPrior experience working in one of the following highly desired :DOD / FED Cyber Client organizationDCIO / MCIO, with Cyber Counterintelligence focusEducation : Bachelor's required