Source description
About the role
Lead response activities for USCYBERCOM and DCDC directives, managing the lifecycle of Situational Awareness Reports (SAR) and ensuring all assets remain compliant with OPORDs, TASKORDs, IAVM notifications, and STIG requirements by published deadlines.
Conduct deep-dive forensic investigations into cybersecurity events (data loss, unauthorized access, network exploits) to determine nature and scope; identify corrective actions for containment, eradication, and recovery.
Perform thorough post-incident reviews to derive lessons learned, identify security gaps, and implement preventive measures to strengthen the program’s long-term defense posture.
Provide expert guidance on cybersecurity directives and risk management policies; review POA&Ms for technical clarity and sound judgment to ensure acceptable remediation timeframes for security controls.
Oversee enterprise-wide monitoring and logging across network infrastructure and endpoints to ensure the rapid detection and response to cyber incidents.
Maintain and evolve IR SOPs in strict accordance with CJCSM 6510.01B, NIST SP 800-61R2, and DOW regulations to ensure procedural alignment with industry best practices.
Translate technical findings into regular status reports for program leadership, DOW officials, and USCYBERCOM /DCDC repositories, detailing incident impact, effectiveness of response strategies, and lessons learned.
Drive the evolution of incident response capabilities by identifying weaknesses, recommending advanced technologies, and implementing enhanced processes to stay ahead of evolving cyber threats.
Support DOW CIO data collection by reviewing PPSM, CAP, SNAP, and GIAP requests against DISA guidelines; cross-train team members on emerging defense techniques and provide after- hours investigative support for critical incidents.
More at True Zero Technologies
Related open roles
Zero Trust Lead (R-00179)
New York · Washington DC · Hybrid
SIEM Analyst II (R-00173)
United States · Onsite
Cyber Security Analyst-Senior Level (R-00172)
United States · Onsite
ZScaler Engineer (R-00171)
Remote · United States
Mid Cyber Security Analyst-Intermediate Level (R-00169)
United States · Hybrid
Junior Cyber Security Analyst (R-00168)
United States · Hybrid
