Cyber Incident Response Operator
Job
IPSecure, Inc.
San Antonio, TX (In Person)
$85,000 Salary, Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
86
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Cyber Incident Response Operator IPSecure, Inc.•5.0 Lackland AFB, TX Job Details $75,000•$95,000 a year 1 day ago Benefits Paid holidays Health insurance Dental insurance Vision insurance 401(k) matching Qualifications Document review (document control) Report writing
TS/SCI IT
system monitoring Mid-level Threat detection & response Incident Investigation Counterintelligence Network monitoring Log analysis Incident response implementation IT security monitoring Full Job Description Cyber Incident Response Operator (IRO)•TS/SCI Level Clearance Required•Located in San Antonio, Texas Job Description The ability of the Cyber Incident Response Operator (IRO) is to complete its mission dependent upon accurate, timely and thorough event analysis in order to identify intruder or potential intruder activities utilizing host and network monitoring and system logs. The IRO shall correlate information gathered to provide effective methods to protect Air Force (AF) systems. Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity. Responsibilities When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned. Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity. Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‐intelligence agencies and activities if required. Participate and contribute to lessons learned meetings and briefings. Support planned and same‐day Incident Response deployments. Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval. Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008) Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‐intelligence agencies and activities if required. Generate end of mission reports (MISREPS) and provide pass‐on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate. Generate end of mission reports (MISREPS) and provide pass‐on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. Provide computer security‐related support to AF field units as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope ofAFIN SOC
operational requirements and mission execution. Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander. Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable. Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs. Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions. Basic Qualifications Active TS/SCI Level Clearance. Ability to gain the CSSP Incident Responder Certification (GCFA) Certification requirement within 120-days of hire date. Preferred Qualifications 3+ years of relevant technical, cyber security, and business work experience Benefits Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid legal plan and ID protection plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available. EEOC Statement IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.Similar jobs in San Antonio, TX
Confidential
San Antonio, TX
Posted1 day ago
Updated5 hours ago
Harrison County Board of Education
San Antonio, TX
Posted1 day ago
Updated5 hours ago
Similar jobs in Texas
Texas Woman's University
Denton, TX
Posted1 day ago
Updated5 hours ago