CERT Lead
Core
Lead a Computer Emergency Response Team (CERT) as a Digital Forensics and Incident Response (DFIR) practitioner to guide citywide cybersecurity incident response, malware analysis, and threat hunts for New York City agencies.
Role type
Senior IC Cybersecurity Incident Response Lead (DFIR)
Builds
Incident response capabilities, detection tools, and remediation strategies for high-profile cybersecurity incidents across City agencies.
Domain
Public sector cybersecurity / Digital Forensics and Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Malware analysis, digital forensics (memory, network, disk), incident response lifecycle management, cloud environment forensics (AWS, Azure, GCP), threat hunting, remediation strategy design, post-incident analysis, tabletop exercise design, team leadership and mentorship
Preferred skills
Cyber threat intelligence collaboration, countermeasure deployment, capability gap identification
Technologies
AWS, Azure, GCP
Responsibilities
Serve as the top-level technical escalation point for high-profile cybersecurity incidents; lead, mentor, and manage a team of six DFIR specialists; investigate incidents through log, file, and malware analysis; devise remediation strategies to contain and eradicate threats; design and participate in cyber tabletop exercises; continuously augment CERT capabilities to address evolving threats.
Seniority
Senior, hands-on IC with team leadership