This position is contingent upon a future opening with Gunnison. The Cyber Incident Management Lead will lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT). This role involves managing incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. The lead will also be responsible for reviewing, maintaining, and updating the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements. Key duties include directing incident response efforts (triage, containment, eradication, recovery, post-incident remediation), coordinating with internal and external stakeholders during incidents, and conducting annual incident response exercises. Additionally, the lead will perform incident information gathering, analysis, distribution, and notification, and develop incident reports and after-action reviews. The role also encompasses leading penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities, including developing associated documentation and coordinating testing processes. Integration of incident response and penetration testing with other security functions like vulnerability management and threat modeling is crucial. The lead will track and report on incident response and penetration testing metrics and support continuous improvement of cyber defense capabilities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior