Seeking a cleared cybersecurity engineer to support a high-visibility IC program in the National Capital Region. Lead incident response operations, tune SIEM detections, and mentor junior analysts.
What you'll do
- Monitor, tune, and maintain SIEM platforms to detect anomalous activity and reduce false-positive alert fatigue across classified networks
- Lead end-to-end incident response efforts including triage, containment, eradication, and post-incident reporting for DoD and IC environments
- Develop and maintain Python scripts to automate threat hunting, log parsing, and security orchestration workflows
- Analyze network traffic, firewall logs, and endpoint telemetry to identify indicators of compromise and lateral movement
- Engineer and enforce network security controls including segmentation, access policies, and intrusion detection configurations
- Collaborate with mission owners and system administrators to assess vulnerabilities and implement risk-based remediation plans
- Produce clear, classified incident reports and briefings for senior government stakeholders and program leadership
Required skills
- SIEM
- Incident Response
- Network Security
- Python