Cyber Incident Handler

4 months ago


Denver, United States ITmPowered, LLC Full time
Cyber Security Incident Handler (Principal) - Remote - KAISJP00211866

The Incident Handler uses incident response, investigative, and forensics skills to determine the extent of a breach, the containment measures required, and the overall response needed. This includes appropriate data collection, preservation, mitigation, remediation requirements, and security improvement plans. The Incident Handler will utilize forensic best practices and provide chain of custody service for criminal investigations (e.g., employee situations, fraud, etc.). The Incident Handler may work on different teams, depending upon the type of incident or pre-incident activity and the nature of the threat.

Essential Functions

  • Evaluates processes, services, drivers, libraries, binaries, scripts, memory, network traffic, file, email, and other artifacts for anomalies, security exploitation, and/or unauthorized access.
  • Identifies attack vectors, social engineering attempts, exploits, malicious code, C2 activity, and persistence mechanism.
  • Identify containment controls to halt attacks in progress against affected or exposed resources.
  • Identify mitigation controls to prevent attacks to vulnerable or exposed resources.
  • Performs analysis to determine scope, risk, and impact of breach or exposure.
  • Performs root cause analysis, develops remediation plans, and works with SMEs to ensure proper execution of corrective action plans.
  • Works with SMEs to determine mitigation strategies, and coordinates with affected business unit(s) to implement mitigating security controls.
  • Collects and preserves digital evidence in a forensically sound manner according to best practices.
  • Properly and thoroughly document incident findings, evidence, analysis steps, and create after action reports and recommendations.
  • Engages appropriate levels of management to affect improvements to the security posture of organization.
  • Provide input to security infrastructure design based on incident response experience.
  • Provide routine updates to Security Policies and Procedures
  • Focus on preserving uptime of the production environment and minimize the impact on medical services.
DESIRED SKILLS:
  • Broad knowledge of digital processing platforms, hardware, operating systems, applications and the ability to identify and troubleshoot failures in any of these areas.
  • Expert knowledge of Windows-based operating systems
  • Working knowledge of Linux/UNIX-based operating systems
  • Familiarity with Android and IOS platforms
  • Possesses binary and scripted malware behavioral analysis skills.
  • Possesses binary and scripted malware static analysis and reverse engineering skills and experience with binary disassembly and script analysis platforms.
  • Ability to troubleshoot through technical issues to properly triage reported events and incidents.
  • Ability to perform deep-dive analysis to determine root cause and full impact of incidents.
  • Knowledge and experience in security controls including EDR, forensics tools, anti-virus, intrusion prevention, authentication mechanisms, data collection and analysis tools, and Splunk SIEM
  • Excellent communication and documentation skills
  • Ability to produce reports for Sr. Management that properly articulate risk, exposure, corrective action plans.
  • Ability to speak publicly and lead diverse teams of SMEs & Operations Management through security incident.
  • Ability to respond quickly and accurately to any level of security incident.
  • Avoid unnecessary production impact caused by investigation activities, if avoidable
  • Properly manage elevated access within the environment
  • Ability to work in a team of professionals sharing workload and investigation assignments in a fast-paced and high-risk environment.
PREFERRED QUALIFICATIONS AND CERTIFICATIONS:
  • Masters degree in a related technical field and a minimum of 10+ years of equivalent work experience
  • 7+ years hands on experience with Enterprise forensic software and investigations.
  • 10+ years of experience in Cyber Security with a focus on Incident Response or Forensics
  • EnCE, GCFE, GCFA, GNFA, GDAT, GCIH, GREM, CISA, CISM, and/or similar certifications
QUALIFICATIONS: (A candidate should meet at least 13 of the below qualifications):
  • Master's degree in a related field and/or a minimum of 10+ years of equivalent work experience
  • A minimum of 15+ years of experience in Information Technology (IT)
  • EnCE, GCFE, GCFA, GNFA, GDAT, GCIH, GREM, CISA, CISM, and/or similar certifications
  • A thorough understanding of at least three desktop and server operating systems (Windows, Linux, Unix, OS X, Android, IOS) and related forensic artifacts.
  • Expert shell scripting skills in three or more languages
  • A thorough understanding of attacker/malware methodologies and common malicious changes
  • Experience with multiple forensics platforms, such as EnCase, FTK, Nuix, X-Ways, etc.
  • Possesses binary and scripted malware behavioral analysis skills.
  • Possesses binary and scripted malware static analysis and reverse engineering skills and experience with binary disassembly and script analysis platforms.
  • Possesses a thorough understanding of networking and the ability to decode and analyze network packet captures using relevant toolsets.
  • Possesses expert knowledge of security controls technologies at all layers (IAM, Network, Endpoint, SIEM/Log)
  • Possesses strong communication and writing skills and the ability to present investigative content and findings verbally and in reports to technical and non-technical audiences, including senior leadership, legal, compliance, business, and other teams.
  • Possesses the ability to develop, refine, and educate team members on new investigative targets, data sources, tools, methodologies, and processes.
  • Strong mentoring and leadership skills
  • Strong project management and overall incident management skills
LOGISTICS:
  • Work remotely anywhere in Domestic US. Preferred locations Colorado or Georgia.
  • COVID-19 Vaccine and Booster Required - OR must provide valid medical exemption from doctor in advance.
  • Must be able to successfully pass a 12-panel drug screen, 10-year background check, employment verification.
  • You will need to be a current US Citizen or valid Green Card holder. No need for visa now or in future. This role is not able to offer visa transfer or sponsorship now or in the future.
  • W2 only - No sub vendors. Sponsorship NOT available.
  • Must have direct contact information on resume (phone / email) to be considered.


  • Denver, United States Booz Allen Hamilton Full time

    Job Number: R0209963 Cloud Cyber Incident Response Analyst, Lead Key Role: Responds to and resolves cyber security incidents, participates in cyber incident response investigations requiring forensic, malware, and log analysis, and analyzes forensic images and triage datasets to identify indicators of compromise, lateral movement, and unauthorized access or...


  • Denver, United States Booz Allen Hamilton Full time

    Job Number: R0209963Cloud Cyber Incident Response Analyst, Lead Key Role: Responds to and resolves cyber security incidents, participates in cyber incident response investigations requiring forensic, malware, and log analysis, and analyzes forensic images and triage datasets to identify indicators of compromise, lateral movement, and unauthorized access or...


  • denver, United States Hamlyn Williams Full time

    The Cybersecurity team plays a pivotal role in driving the organization’s success by strategically balancing risk with business goals. We're at the forefront of shaping and enforcing security policies, ensuring the protection of critical assets while keeping pace with evolving business needs. Our team leads the charge in developing cutting-edge security...


  • Denver, United States Hamlyn Williams Full time

    The Cybersecurity team plays a pivotal role in driving the organization’s success by strategically balancing risk with business goals. We're at the forefront of shaping and enforcing security policies, ensuring the protection of critical assets while keeping pace with evolving business needs. Our team leads the charge in developing cutting-edge security...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented Cyber Security Analyst, Senior, to join our team in the Aurora, CO area.Responsibilities include, but are not limited to:Provides detection, identification, and reporting of possible cyber-attacks/intrusions, anomalous activities, and misuse activitiesCharacterizes and performs analysis of network...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented **Cyber Security Engineer, Detections** to join our team in **Denver, CO area** , to provide unparalleled support to our customer and to begin an exciting and rewarding career within ManTech. **Responsibilities include, but are not limited to:** + Support Cyber Operations Squadron (COS)...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented Cyber Security Engineer, Detections to join our team in Denver, CO area , to provide unparalleled support to our customer and to begin an exciting and rewarding career within ManTech. Responsibilities include, but are not limited to: Support Cyber Operations Squadron (COS) activities to publish...


  • Denver, Colorado, United States Cypfer Full time

    Job OverviewCYPFER is a leading first-responder cybersecurity organization with extensive experience in swift and effective incident response. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed industry standards.We collaborate with prominent global insurance carriers,...


  • denver, United States Apex Systems Full time

    Cloud SIEM EngineerLocations: Chicago, IL / Denver, CO / Washington, DC - 3X A WEEK ON-SITE$80/hour on W2W2 ONLYUnable to work C2CJoin our team as a Cloud SIEM Engineer and play a crucial role in enhancing our security posture. We seek a dedicated professional passionate about security and innovation to help protect our assets from evolving cyber threats.Key...


  • Denver, United States Apex Systems Full time

    Cloud SIEM EngineerLocations: Chicago, IL / Denver, CO / Washington, DC - 3X A WEEK ON-SITE$80/hour on W2W2 ONLYUnable to work C2CJoin our team as a Cloud SIEM Engineer and play a crucial role in enhancing our security posture. We seek a dedicated professional passionate about security and innovation to help protect our assets from evolving cyber threats.Key...


  • Denver, United States Konica Minolta Business Solutions Ltd Full time

    OverviewSenior Cybersecurity Engineer - Endpoint Detection and Response is expected to possess a high level of knowledge and experience in various security domains and technologies with a focus on advanced endpoint protection, detection and response. This resource will work closely with the defensive managed security services team to design, deploy, and...


  • Denver, United States AEG Full time

    In order to be considered for this role, after clicking "Apply Now" above and being redirected, you must fully complete the application process on the follow-up screen. Application Deadline May 24, 2024 The Role: The Concessions Supervisor position is responsible for supporting concessions service operations for Legends Hospitality at Ball Arena. Company...

  • Denver - Server

    5 months ago


    Denver, United States Happy Camper Full time

    Server Position Job Summary: Provide friendly and responsive service to create an exceptional experience for all of our guests by having extensive food and beverage knowledge, energetically interacting with guests, taking orders and effectively running multiple tables. You will need to be quick on your feet (literally and metaphorically) and have a polite...


  • Denver, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Network AdministrationJob Qualifications:Skills:Computer Networking, Microsoft Windows Server, Network Systems, TroubleshootingCertifications:Experience:1 +...


  • Denver, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphPublic Trust/Other Required:NoneJob Family:Network AdministrationJob Qualifications:Skills:Computer Networking, Microsoft Windows Server, Network Systems, TroubleshootingCertifications:NoneExperience:1 + years of...

  • Bartender - Denver

    4 months ago


    Denver, United States Happy Camper Full time

    We are the marinara-muddled minds behind Happy Camper, Homeslice, and Paradise Park. Our restaurants are wall to wall with lights, murals, and vignettes for the perfect gram. We are known for our art inspired spaces, delicious food and great vibes. Our brand is glued together by our company culture. Currently, we are looking for other folks who are...


  • Denver, United States Gana-A'Yoo, Limited - Antarctic Program Full time

    Gana-A'Yoo Services Corporation, GSC, is renowned for excellence in delivery, performance and customer satisfaction with a focus on Food Service, Janitorial Services and Administrative Services. GSC supports the National Science Foundation managed United States Antarctic Program as part of the Antarctic Support Contract (ASC) and we are currently seeking a...