Senior Cybersecurity Incident Response Administrator

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Roanoke, VA, USA
In-Office or Remote
87K-135K Annually
Senior level
Artificial Intelligence • Information Technology • Software • Defense
The Role
Manages SIEM infrastructure, event monitoring, dashboards, threat investigation, incident response, audit reporting, and security compliance for Army and DoD systems. Supports PKI, SSL/TLS certificates, web application security standards, Cyber Tasking Orders, software assurance reviews, and coordination with cybersecurity service providers across data center and cloud environments.
Summary Generated by Built In
Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.


Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

The Senior Cybersecurity Incident Response Administrator manages Security Information and Event Management (SIEM) systems, including deployment, installation, infrastructure management, and event monitoring in accordance with Army Business System Log Data Policy and other DoD/Army requirements. This role creates SIEM dashboards for clear, concise visualization of security-related events, enabling near real-time detection of anomalies and investigation of threats.

This is a remote-eligible position. Local candidates in the Roanoke and Radford, Virginia area are encouraged to apply, and work may be performed locally for those who prefer an on-site or hybrid arrangement. The ideal candidate will bring deep cybersecurity incident response and SIEM engineering expertise, strong DoD cybersecurity compliance knowledge, and the ability to support mission-critical Army IT services across enterprise data centers and cloud-hosted environments


Key Responsibilities

  • Deploy, install, manage infrastructure, and monitor events within SIEM systems in accordance with Army Business System Log Data Policy and other DoD/Army requirements.
  • Create SIEM dashboards for visualization of security-related events and near real-time anomaly detection.
  • Monitor SIEM dashboards to detect threats and anomalies, investigate events, and escalate as necessary.
  • Assess and develop reporting requirements to support audits and security controls.
  • Provide Public Key Infrastructure (PKI) support and monitor DoD/Army web application security standards.
  • Review Army Cyber Tasking Orders (CTOs) and coordinate with Army Cyber Security Service Providers.
  • Participate in Software Assurance reviews and evaluate Information Systems Design Plans for compliance with security regulations, policies, and best practices.
Qualifications

Requirements:

  • Cybersecurity Certification (such as CISSP, ISSEP, Security+, CEH, or equivalent).
  • Bachelor's degree in Computer Science is preferred; equivalent years of cybersecurity and incident response experience will be considered in lieu of a degree.
  • Active DoD Secret Security Clearance.
  • 10 or more years' experience with Cybersecurity and Incident Response or related areas.
  • Extensive experience managing SIEM systems, including ingesting relevant data into the SIEM.
  • Proficiency in creating and managing SIEM dashboards for security event visualization.
  • Strong ability to monitor and investigate security events and anomalies.
  • Experience developing reporting requirements for audits and security controls.
  • Knowledge of Public Key Infrastructure (PKI) and managing SSL/TLS certificates.
  • Familiarity with DoD and Army web application security standards and best practices.
  • Ability to review and respond to Army Cyber Tasking Orders (CTOs).
  • Experience coordinating with Cyber Security Service Providers for audit logs and incident response.
  • Participation in Software Assurance reviews for application audit log validation.
  • Ability to review and evaluate Information Systems Design Plans and related documents for security compliance.

Preferred:

  • Bachelor's degree in Computer Science or equivalent years of experience.
  • Familiarity with Army enterprise monitoring tools and practices.
  • Strong analytical and problem-solving skills.
  • Excellent communication and coordination skills.
  • Experience with incident response activities.
  • Knowledge of engineering change proposals and configuration management.
  • Understanding of Continuity of Operations Plans and Communication Plans.
  • Experience with security regulations and best industry practices.
  • Ability to work effectively in a team environment and collaborate with various stakeholders.

Certifications:



CISSP, ISSEP, Security+, CEH, or equivalent Cybersecurity Certification

About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.

Pay Band MinUSD $87,320.00/Yr. Pay Band MaxUSD $135,160.00/Yr.

Skills Required

  • Cybersecurity certification such as CISSP, ISSEP, Security+, CEH, or equivalent
  • Bachelor's degree in Computer Science, or equivalent cybersecurity and incident response experience in lieu of a degree
  • Active DoD Secret security clearance
  • 10 or more years of experience in cybersecurity, incident response, or related areas
  • Extensive experience managing SIEM systems and ingesting relevant data
  • Proficiency creating and managing SIEM dashboards
  • Ability to monitor and investigate security events and anomalies
  • Experience developing reporting requirements for audits and security controls
  • Knowledge of PKI and SSL/TLS certificate management
  • Familiarity with DoD and Army web application security standards
  • Ability to review and respond to Army Cyber Tasking Orders
  • Experience coordinating with Cyber Security Service Providers
  • Participation in Software Assurance reviews for application audit log validation
  • Ability to evaluate Information Systems Design Plans for security compliance
  • Familiarity with Army enterprise monitoring tools and practices
  • Strong analytical and problem-solving skills
  • Excellent communication and coordination skills
  • Experience with incident response activities
  • Knowledge of engineering change proposals and configuration management
  • Understanding of Continuity of Operations Plans and Communication Plans
  • Experience with security regulations and industry best practices
  • Ability to collaborate effectively with stakeholders in a team environment
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,000 Employees
Year Founded: 1989

What We Do

Empower AI is a federal government technology contractor that uses artificial intelligence, machine learning, automation, and natural language processing to help agencies improve decision-making, workforce productivity, security, and mission outcomes. Formerly NCI, the Reston-based company provides AI and software solutions, engineering and integration, IT service management, infrastructure modernization, and mission-support services for civilian and defense agencies worldwide.

Similar Jobs

Cloudflare Logo Cloudflare

Principal Partner Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
5 Locations
4400 Employees
212K-336K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Operations Scheduling Specialist

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Wallops Island, VA, USA
40000 Employees
51K-87K Annually

Motive Logo Motive

Operations Manager

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
Remote
United States
4000 Employees

Motive Logo Motive

Consultant

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
Remote
United States
4000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account