Cyber Incident & Event Management

Capital One
Springfield, VA
Oct 13, 2020
Oct 19, 2020
Full Time
McLean 1 (19050), United States of America, McLean, Virginia Cyber Incident & Event Management Capital One s Cyber Incident and Event Management team supports the rapid and effective response to high impact cyber security events affecting Capital One-owned and managed technology assets. The associate in this role will work closely with other Cyber Operations teams, including the Capital One Cyber Security Operations Center (CSOC). When cyber incidents occur, the associate in this role will coordinate response activities to ensure effective remediation. This is an operational role which may include occasional non-standard working hours (nights/weekends). Responsibilities: Execute day-to-day incident management operations Use technology infrastructure and operational processes to enable a more effective incident management process Develop and distribute executive-level summaries of cyber incidents which impact Capital One assets Communicate technical cyber threat & incident response operations information across the company, to include the CISO and CIO Verify work is properly documented in the system of record Engage with associates across the Capital One enterprise Identify and track incident management performance measures to provide relevant performance trends over time Define quantifiable Key Performance Indicators (KPIs) to measure efficiency and success of Incident Response team activities Automate the production of interval based reports which provide KPI metrics Coordinate with various teams in clarifying security risks, roles and responsibilities related to ongoing Incident Response cases Provide support to operational and cybersecurity strategy development Maintain updated knowledge of best practices in cyber operations and incident response processes to identify and recommend new technologies or processes with the potential to enhance operations Develop, follow, and maintain playbooks which enable consistent work Identify and enhance processes where automation has the potential to improve efficiency Lead, mentor, and assist team members in their day-to-day execution Basic Qualifications: High School Diploma, GED or Equivalent Certification At least 2 years of experience with cyber incident response or cyber incident handling At least 1 year of experience with cyber threat analysis and cyber threat mitigation At least 1 of the following industry certifications (CEH, GCIA, GCIH, Security+, CySA+) Preferred Qualifications: Bachelor's Degree in fields such as Business, Information Systems, Emergency Management, and Engineering 2+ years of experience with emergency management (NIMS/ICS) 2+ years of experience analyzing information and data 2+ years of experience with technical troubleshooting 2+ years of experience with process management At this time, Capital One will not sponsor a new applicant for employment authorization for this position.