Cyber Security Supervisor - Incident Response

Exelon Corporation
Owings, MD
Jul 12, 2018
Jul 16, 2018
Full Time
Description PRIMARY PURPOSE OF POSITION Supervisees the Incident Handling & Response processes. Provides deep technical expertise to provide Level 2/3 Cyber Security Incident Handling, Response and Remediation. Designs, develops and implement cyber security capabilities to investigate, identify and actively defend Exelon infrastructure against Advanced Persistent Cyber Threats. Works closely with Manager, Cyber Defense Security Operations Center (SOC), Supervisor of Cyber Defense Forensics and other supervisors to meet/exceed service levels. MAJOR ACCOUNTABILITIES - Supervise incident handling & response activities. Perform and document work activities relating to level 2/3 CyberSOC Incident Response, Active Defense Cyber investigations and identification of indicators of advanced malware and persistent threats. Perform activities required to manage service level agreements. - Work closely with Supervisor of Cyber Defense Forensics and Supervisor of Cyber Defense Monitoring to coordinate activities and services. - Provide direction and support in the identification, containment, eradication, & recovery of sophisticated level 2/3 incidents. Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation. Perform analysis of log files from a variety of sources (eg, individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats to network security. - Coordinate incident response functions. Perform cyber defense incident triage, to include determining scope, urgency, and potential impact; identifying the specific vulnerability; and making recommendations that enable expeditious remediation. Track and document cyber defense incidents from initial detection through final resolution. Collect intrusion artifacts (eg, source code, malware, trojans) and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise. - Update Incident Management & trouble tickets, providing timely & accurate status updates of ongoing activities - Recommend short & long term adjustments to controls for immediate & future identification, containment & remediation. Coordinate with intelligence analysts to correlate threat assessment data. - Provide direction on tuning of signatures, rules, alerts, parsers, & custom scripts. - Contribute to IR process definition & development & maintenance of documented procedures & procedures, including process integration with managed security service providers, 3rd party vendors, internal IT organizations, & business units. Write and publish cyber defense techniques, guidance, and reports on incident findings to appropriate constituencies. Perform cyber defense trend analysis and reporting. POSITION SCOPE - Provides direction as a team supervisor. Provide computer security Incident Handling & Response services to Exelon by serving in a front-line role for information security incidents. Responds to disruptions within the pertinent domain to mitigate immediate and potential threats. Uses mitigation, preparedness, and response and recovery approaches to maximize survival of life, preservation of property, and information security. Investigates and analyzes relevant response activities and evaluates the effectiveness of and improvements to existing practices. Required Skills: Qualifications POSITION SPECIFICATIONS Minimum: - Bachelor's Degree in Computer Science, Information Technology (IT), or a related discipline, and typically 8 or more years of solid, diverse experience in cyber security Incident Response, or equivalent combination of education and work experience. - One or more of the following: GIAC Certified Intrusion Analyst - GCIA, GIAC Certified Incident Handler - GCIH - Knowledge of data backup, types of backups (eg, full, incremental), and recovery concepts and tools. - Knowledge of how network services and protocols interact to provide network communications. - Knowledge of incident categories, incident responses, and timelines for responses. - Knowledge of incident response and handling methodologies. - Knowledge of intrusion detection methodologies and techniques for detecting host and network-based intrusions via intrusion detection technologies. - Knowledge of network protocols (eg, Transmission Control Protocol/Internet Protocol [TCP/IP], Dynamic Host Configuration Protocol [DHCP]), and directory services (eg, Domain Name System [DNS]). - Knowledge of network traffic analysis methods. - Knowledge of packet-level analysis. - Knowledge of system and application security threats and vulnerabilities (eg, buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code). - Knowledge of what constitutes a network attack and the relationship to both threats and vulnerabilities. - Knowledge of different classes of attacks (eg, passive, active, insider, close-in, distribution). - Knowledge of basic system administration, network, and operating system hardening techniques. - Knowledge of general attack stages (eg, foot printing and scanning, enumeration, gaining access, escalation or privileges, maintaining access, network exploitation, covering tracks). - Knowledge of network security architecture concepts including topology, protocols, components, and principles (eg, application of defense-in-depth). - Knowledge of an organization's information classification program and procedures for information compromise. - Knowledge of OSI model and underlying network protocols (eg, TCP/IP). Preferred: - Graduate degree in cyber security or related area of expertise. - Ability to demonstrate analytical skills, technical knowledge, and practical application of cyber and information security principles to business leaders and technical staff. - Direct experience in network security (SOC, SIRT, CSIRT) investigating targeted intrusions through complex network segments. - CISSP or SSCP designation - Demonstrated skill of identifying, capturing, containing, and reporting malware. - Demonstrated skill in performing damage assessments. - Skill in using security event correlation tools. - Demonstrated knowledge of cyber defense policies, procedures, and regulations. - Prior supervisory experience

Similar jobs