AOUSC - Incident Response Analyst
Qualifications:
- Active Public Trust clearance
- B.S. Computer Science, Information Technology, or a related field
- 3+ years of experience in an IR role.
- 2+ years’ experience using Python and PowerShell scripts for decoding/decryption of obfuscated payloads.
- 2 years of experience in performing live triage, log correlation, detection rule refinement, to include usage of Velociraptor, Splunk ES and Sentinel.
- 1 year of experience in federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.
- Active SANS GCIH or GCIA certification