ASRC Federal Holding Company logo

Cyber Defense Incident Responder - Overnight Shift

ASRC Federal Holding Company

  • Quantico, VA
  • 12 days ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Analysis Skillsunmatched
    • CCNA - Cisco Certified Network Associateunmatched
    • CSIH - Computer Security Incident Handlerunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Network Defense (CND)unmatched
    • Computer Securityunmatched
    • Cross-Functionalunmatched
    • DNS (Domain Name System)unmatched
    • Data Analysisunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • Establish Prioritiesunmatched
    • Firewallsunmatched
    • Forensic Scienceunmatched
    • GCFA - GIAC Certified Forensic Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Leadershipunmatched
    • Malwareunmatched
    • Malware Analysisunmatched
    • Management of Information Systems/Technology (MIS)unmatched
    • Network Securityunmatched
    • Physical Demandsunmatched
    • SSCP - Systems Security Certified Practitionerunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • Standard Operating Procedures (SOP)unmatched
    • Time Managementunmatched
    • Top Secret Clearanceunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched

    Description

    ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the overnight shift (2100 - 0700), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA - no telework is available for this role.The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.Position Description:The Cyber Incident Responder is a vital role responsible for executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).The Incident Responder will collaborate with cross-functional IT and security teams to:

    Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelinesCoordinate with JFHQ-DODIN on cyber incident reporting and remediationSupport insider threat response and investigationsContain and remediate compromised systems, accounts, and endpointsPreserve and document forensic evidence for incident case managementMaintain incident response playbooks and ensure high operational readiness during all covered hours

    Minimum Requirements:

    At least two (2) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.Active Top Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.Bachelor's degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.Must meet DoD 8570 certification requirements at time of hire - IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.Willingness and availability to work the overnight shift (2100 - 0700), including weekend and holiday rotations, fully on-site at Quantico, VA.

    Required Skills:

    Incident Detection & Triage: Monitor security alerts and events from SIEM, EDR, IDS/IPS, firewall, DNS, and ESS sources to rapidly detect, triage, and prioritize potential security incidents.Incident Response Lifecycle: Execute the full incident response lifecycle - preparation, detection and analysis, containment, eradication, recovery, and post-incident activity - in accordance with NIST SP 800-61.Containment & Eradication: Take decisive containment and eradication actions on compromised endpoints, accounts, and systems to limit incident impact.Cyber Task Management: Process and handle JFHQ-DODIN cyber-related tasks, orders, and incident reporting requirements to completion within required timelines.Investigation & Forensics: Identify evidence of illegal activity involving cybercrime offenses; examine computers potentially involved in crime or malware infection and preserve forensic evidence following chain-of-custody procedures.Malware Analysis: Use forensic tools and investigative methods to identify, isolate, and analyze specific electronic data associated with complex malware infections.Incident Documentation: Develop and maintain incident response playbooks, standard operating procedures (SOPs), and detailed incident case documentation.Reporting & Escalation: Provide timely incident reports and escalations to senior leadership and deliver daily/weekly/monthly summaries on incident trends and key indicators of network security.

    Work Environment and Physical Demands:

    This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.Must work the assigned Overnight shift (1900 - 0700) and support weekend and holiday coverage as scheduled consisting of Four 10-hour shifts per work week.Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.

    Numbers & Facts

    LocationQuantico, VA
    IndustryAerospace and Defense
    Company Size5,000 to 9,999 employees
    Year Founded2003
    Websitehttp://www.asrcfederal.com

    Benefits

    Military Leave, On Site Cafeteria, Parking, Prescription Drug Coverage, Professional Development, 401K, Employee Referral Program, Flexible Spending Accounts, Employee Events, Tuition Reimbursement, Work From Home, Life Insurance, Merchandise Discounts

    About Company

    ASRC Federal comprises a family of companies that provide mission-critical services to federal government agencies dedicated to defense, civil and intelligence support. Our customer-focused service delivery model and emphasis on operational excellence are foundational elements infused in all our companies. The reliability and quality of day-in, day-out service delivery from our family of companies ensure our customers that we keep our sights on their mission-critical priorities.

    Similar Jobs

    See more jobs