Associate Solution Consultant – Security Incident Handler
Core
Security Incident Handler supporting a joint Security Operations Task Force and CSIRT for 24x7x365 monitoring and rapid incident response in a public sector environment.
Role type
Associate Solution Consultant (Security Incident Handler)
Builds
Production security monitoring, incident response, and forensic analysis for public sector clients
Domain
Cybersecurity, Public Sector Professional Services
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security monitoring, incident response, host and network forensics, threat detection, vulnerability identification, log analysis, system artifact analysis, regulatory reporting, client presentation, project management
Preferred skills
Linux administration, Python scripting, PowerShell, cloud services (AWS, Azure), virtualization (VMware, Nutanix), MITRE ATT&CK framework knowledge
Technologies
Trellix ePO, Endpoint Security (ENS), Trellix Detection & Response (EDR), Advanced Threat Defense (ATD), Threat Intelligence Exchange (TIE), Data Exchange Layer (DXL), Data Loss Prevention (DLP), SIEM, XDR, Email Gateway ATP, Network/Host IDSs, UEBA, WAFs, Firewalls, Active Directory, Syslog
Responsibilities
Respond to security incidents in production environments, conduct host and network forensics, identify and mitigate vulnerabilities, create technical DFIR and executive reports, interact with managers on cost/schedule monitoring, identify new client opportunities
Seniority
Associate, hands-on IC