Talent.com
Senior Consultant, Cyber Incident Response

Senior Consultant, Cyber Incident Response

Control RisksWashington, DC, US
30+ days ago
Job type
  • Full-time
  • Permanent
  • Quick Apply
Job description

The Senior Consultant is responsible for delivering Incident Response support to our clients by helping them investigate and remediate the impacts of cyber attacks quickly and comprehensively. This role will report to the Associate Director of Cyber Response and work closely with the Cyber Crisis Management team. The successful candidate will have a strong technical skill set and a deep understanding of current and emerging threat actors.

Role tasks and responsibilities

Incident response

  • Overseeing cloud, host and network based investigations.
  • Ownership of the lifecycle of a cyber incident including identification, containment, eradication and recovery.
  • Define and execute investigative strategies to meet our clients needs including guiding more junior members of the team to help implement this strategy.
  • Lead technical scoping engagement, triage priorities, and recovery strategy for affected systems.
  • Perform log analysis from a variety of sources (e.g., individual host logs, network traffic logs) to identify threats.
  • Undertake evidence acquisition on a variety of assets and lead the investigation, identify the root cause / overall impact caused by the threat.
  • Advise our clients on how to eradicate the threats and rebuild securely utilizing the findings from your investigation.
  • Threat hunting using endpoint tooling and findings from your investigation to evaluate an attacker's spread through a system and network, anticipating and thwarting further attacker activity.
  • Perform live compromise assessments for organizations who suspect a compromise.
  • Detect and hunt unknown live, dormant, and custom malware in memory across multiple systems in an enterprise environment.
  • Demonstrate a deep understanding of both existing and emerging threat actors, as well as experience identifying rapidly changing tools, tactics and procedures of attackers.
  • Advise on the safe technical recovery of an organizations IT systems balancing the need to understand what has happened but speed up recovery.
  • This role has a requirement to be on call.

Client Management

  • To support with client relationship management facilitating where appropriate introduction and provision of additional technical Control Risks services.
  • Working closely with Cyber Response Management to ensure a cohesive go-to-market approach.
  • Ensure tooling and automation developed is customer friendly to deploy and use. Be responsible for any customer queries that arise from the use of the technology and automation.
  • Reporting

  • Provide situation reports and other significant case related material to the client and the Director of Cyber Response.
  • Provide documentation to the relevant consultants in sufficient time to allow review and feedback, before submitting to a client.
  • Report on the performance of the Technical Cyber Response work and forecast technical and resource requirements in the near and long term.
  • Ensure the output of tooling and automation is easily readable and presentable both during cases in situation reports but also within formal end of case reports.
  • Supporting the growth of the Cyber Response practice

  • Supporting the development of an ever-improving global technology stack to more rapidly and effectively respond to client incidents.
  • Refining Control Risks’ cyber response methodologies and approaches and tailoring the approach in changing market conditions.
  • Identifying potential new areas of growth and opportunity.
  • Requirements

  • Candidates must be legally authorized to work in the US on a permanent basis without sponsorship.
  • Candidates must possess unrestricted US work authorization.
  • Technical degree or demonstrated knowledge of common networks, software and hardware used in business environments
  • Experience in conducting log analysis and digital forensics following a cyber incident
  • Proven experience in responding to cyberattacks and information security related advisory
  • Proven experience working with technologies including : Windows systems, networking, and virtualization technologies
  • Demonstrable experience of operating within a commercial environment
  • Track record of developing consultative relationships with clients
  • Fluent in English (written and spoken)
  • Excellent presentation skills
  • Excellent analytical skills
  • This role has a requirement to be on call.
  • Preferred : Strong understanding of MITRE ATT&CK techniques / sub-techniques and the ability to articulate TTPs to clients in non-technical terms.
  • Preferred : Fluency in a second language.
  • Preferred : Qualifications or certifications such as : CREST Registered Intrusion Analyst (CRIA), Certified Network Intrusion Analyst (CCNIA), Certified Host Intrusion Analyst (CCHIA), SANS Advanced Incident Response, Threat Hunting, and Digital Forensics (FOR508) or Enterprise-Class Incident Response & Threat Hunting (FOR608), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) and full membership of ISACA.
  • The base salary range for this position is $115,000-$125,000 per year. Exact compensation offered may vary depending on job-related knowledge, skills, and experience.

    Control Risks is committed to a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

    Control Risks participates in the E-Verify program to confirm employment authorization of all newly hired employees. The E-Verify process is completed during new hire onboarding and completion of the Form I-9, Employment Eligibility Verification, at the start of employment. E-Verify is not used as a tool to pre-screen candidates. For more information on E-Verify, please visit www.uscis.gov.

    Benefits

  • Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarized in the full job offer.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasize the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.
  • Medical Benefits, Prescription Benefits, FSA, Dental Benefits, Vision Benefits, Life and AD&D, Voluntary Life and AD&D, Disability Benefits, Voluntary Benefits, 401 (K) Retirement, Nationwide Pet Insurance, Employee Assistance Program.
  • As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.
  • Create a job alert for this search

    Senior Consultant Incident Response • Washington, DC, US

    Related jobs
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management Concepts, Inc.Quantico, VA, US
    Full-time
    Quick Apply
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government'...Show moreLast updated: 10 days ago
    • Promoted
    Cyber Product Manager

    Cyber Product Manager

    IntelliGenesisColumbia, MD, US
    Full-time
    IntelliGenesis is looking for a Cyber Product Manager to lead the go-to-market strategy for CYBERSPAN®, our enterprise-grade Network Detection and Response (NDR) platform.This is...Show moreLast updated: 30+ days ago
    • Promoted
    Cybersecurity Architect

    Cybersecurity Architect

    VirtualVocationsAlexandria, Virginia, United States
    Full-time
    A company is looking for a Cybersecurity Architect to design and implement secure solutions across modern infrastructure. Key Responsibilities Architect secure environments for on-premises, cloud,...Show moreLast updated: 30+ days ago
    • Promoted
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management ConceptsQuantico, VA, United States
    Full-time
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government'...Show moreLast updated: 4 days ago
    • Promoted
    Senior Incident Response Analyst

    Senior Incident Response Analyst

    Edgewater Federal SolutionsBethesda, MD, United States
    Full-time
    Senior Incident Response Analyst.Edgewater Federal Solutions is currently seeking an experienced and highly skilled.Senior Incident Response Analyst. In this critical role, you will be responsible f...Show moreLast updated: 4 days ago
    • Promoted
    Incident Response Analyst

    Incident Response Analyst

    Booz Allen HamiltonMcLean, VA, United States
    Full-time +1
    Support the maturity of clients' Security Operations Center (SOC) related to cloud security capabilities.Oversee client engagements, including the building of an overall picture of the client's cur...Show moreLast updated: 2 days ago
    • Promoted
    Cybersecurity Reporting Specialist

    Cybersecurity Reporting Specialist

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Cybersecurity Reporting Specialist.Key Responsibilities Design, create, and maintain dynamic dashboards for cybersecurity metrics using tools like SharePoint and Power ...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Specialist

    Senior Security Specialist

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Senior Security Specialist - Incident Management.Key Responsibilities Monitor and analyze alerts from various security platforms Lead incident containment, eradication...Show moreLast updated: 2 days ago
    • Promoted
    • New!
    Monitoring Cyber Incident Response Team (CIRT) Analyst

    Monitoring Cyber Incident Response Team (CIRT) Analyst

    PeratonBeltsville, MD, United States
    Temporary
    Monitoring Cyber Incident Response Team (CIRT) Analyst.Peraton is seeking an experienced.Monitoring Cyber Incident Response Team (CIRT) Analyst. Peratons' Federal Strategic Cyber Mission program.Day...Show moreLast updated: 4 hours ago
    • Promoted
    ICS Incident Response Analyst

    ICS Incident Response Analyst

    GrammaTechArlington, VA, United States
    Full-time
    GrammaTech is a provider of software solutions and software research, development, and engineering services solving some of the world’s most complex security problems. GrammaTech is looking for an I...Show moreLast updated: 4 days ago
    Cyber Incident Manager / Incident Manager

    Cyber Incident Manager / Incident Manager

    Node.DigitalArlington, VA, US
    Full-time
    Quick Apply
    Cyber Incident Manager / Incident Manager.Must have an active Top Secret Security Clearance.Government customer to provide support for onsite incident response to civilian Government agencies and cr...Show moreLast updated: 30+ days ago
    • Promoted
    Director of Incident Management

    Director of Incident Management

    VirtualVocationsFairfax, Virginia, United States
    Full-time
    A company is looking for a Director, IDD Incident Management and Quality Outcomes, Performance-Based Contracting.Key Responsibilities Oversee the full lifecycle of incident management, including ...Show moreLast updated: 15 days ago
    • Promoted
    Senior Security Solutions Architect

    Senior Security Solutions Architect

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Senior Security Solutions Architect (Zero Trust & Cloud Security).Key Responsibilities Drive business development and presales efforts for Zscaler and Zero Trust securi...Show moreLast updated: 2 days ago
    • Promoted
    Senior Information Security Analyst

    Senior Information Security Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Senior Information Security Analyst in the Information Technology field.Key Responsibilities Lead complex incident response investigations and forensic analysis Conduc...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    SOC Incident Response Analyst I

    SOC Incident Response Analyst I

    General Dynamics Information TechnologyLanham, MD, United States
    Full-time
    Clearance Level Must Be Able to Obtain : .Incident Handling,Incident Response,Security Tools,Wireshark.We are seeking a motivated Incident Response SOC Analyst I to join our SOC team.In this entry-to...Show moreLast updated: 2 hours ago
    Senior Consultant - Cyber Assurance

    Senior Consultant - Cyber Assurance

    Control RisksWashington, DC, US
    Full-time +1
    Quick Apply
    This role may be based in NYC or Washington DC.We are seeking a highly skilled and motivated Senior Consultant to join our growing cybersecurity assurance team. In this role, you will lead and deliv...Show moreLast updated: 30+ days ago
    • Promoted
    XSOAR Consultant

    XSOAR Consultant

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Remote XSOAR Consultant (Automation).Key Responsibilities Collaborate with the technical lead to develop a log ingestion strategy Document a detailed step-by-step proc...Show moreLast updated: 30+ days ago
    • Promoted
    Tier 2 Cyber Incident Response Team (CIRT) Analyst

    Tier 2 Cyber Incident Response Team (CIRT) Analyst

    PeratonArlington, VA, United States
    Temporary
    Tier 2 Cyber Incident Response Team (CIRT) Analyst.Peraton is seeking an experienced.Tier 2 Cyber Incident Response Team (CIRT) Analyst. Peraton's Department of State (DoS) Diplomatic Security Cyber...Show moreLast updated: 30+ days ago