Point your AI agent at freehire and let it find you a job.

Get the CLI →

Senior Cybersecurity Incident Response Administrator

Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

The Senior Cybersecurity Incident Response Administrator manages Security Information and Event Management (SIEM) systems, including deployment, installation, infrastructure management, and event monitoring in accordance with Army Business System Log Data Policy and other DoD/Army requirements. This role creates SIEM dashboards for clear, concise visualization of security-related events, enabling near real-time detection of anomalies and investigation of threats.

This is a remote-eligible position. Local candidates in the Roanoke and Radford, Virginia area are encouraged to apply, and work may be performed locally for those who prefer an on-site or hybrid arrangement. The ideal candidate will bring deep cybersecurity incident response and SIEM engineering expertise, strong DoD cybersecurity compliance knowledge, and the ability to support mission-critical Army IT services across enterprise data centers and cloud-hosted environments

Key Responsibilities

  • Deploy, install, manage infrastructure, and monitor events within SIEM systems in accordance with Army Business System Log Data Policy and other DoD/Army requirements.
  • Create SIEM dashboards for visualization of security-related events and near real-time anomaly detection.
  • Monitor SIEM dashboards to detect threats and anomalies, investigate events, and escalate as necessary.
  • Assess and develop reporting requirements to support audits and security controls.
  • Provide Public Key Infrastructure (PKI) support and monitor DoD/Army web application security standards.
  • Review Army Cyber Tasking Orders (CTOs) and coordinate with Army Cyber Security Service Providers.
  • Participate in Software Assurance reviews and evaluate Information Systems Design Plans for compliance with security regulations, policies, and best practices.

Qualifications

Requirements:

  • Cybersecurity Certification (such as CISSP, ISSEP, Security+, CEH, or equivalent).
  • Bachelor's degree in Computer Science is preferred; equivalent years of cybersecurity and incident response experience will be considered in lieu of a degree.
  • Active DoD Secret Security Clearance.
  • 10 or more years' experience with Cybersecurity and Incident Response or related areas.
  • Extensive experience managing SIEM systems, including ingesting relevant data into the SIEM.
  • Proficiency in creating and managing SIEM dashboards for security event visualization.
  • Strong ability to monitor and investigate security events and anomalies.
  • Experience developing reporting requirements for audits and security controls.
  • Knowledge of Public Key Infrastructure (PKI) and managing SSL/TLS certificates.
  • Familiarity with DoD and Army web application security standards and best practices.
  • Ability to review and respond to Army Cyber Tasking Orders (CTOs).
  • Experience coordinating with Cyber Security Service Providers for audit logs and incident response.
  • Participation in Software Assurance reviews for application audit log validation.
  • Ability to review and evaluate Information Systems Design Plans and related documents for security compliance.

Preferred:

  • Bachelor's degree in Computer Science or equivalent years of experience.
  • Familiarity with Army enterprise monitoring tools and practices.
  • Strong analytical and problem-solving skills.
  • Excellent communication and coordination skills.
  • Experience with incident response activities.
  • Knowledge of engineering change proposals and configuration management.
  • Understanding of Continuity of Operations Plans and Communication Plans.
  • Experience with security regulations and best industry practices.
  • Ability to work effectively in a team environment and collaborate with various stakeholders.

Certifications:

CISSP, ISSEP, Security+, CEH, or equivalent Cybersecurity Certification

About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.

Pay Band Min

USD $87,320.00/Yr.

Pay Band Max

USD $135,160.00/Yr.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available