Job Description
Insight Global is currently seeking an Incident Response Expert III to join a client in the federal cybersecurity and government services industry supporting DHS's Hunt and Incident Response Team (HIRT). This individual will serve as a subject matter expert for hunt and incident response operations, applying deep knowledge of threat actor tools, techniques, and procedures to complex investigations. Daily responsibilities include analyzing incident data, assessing victim environments, and recommending targeted mitigation and remediation actions. The role requires developing technical solutions independently, providing expert guidance to high-level incident response teams, and supporting containment and eradication missions. This individual will distill findings into executive summaries and detailed technical reports while documenting analysis in standardized knowledgebases. The role also supports process and procedure documentation and collaborates closely with internal stakeholders across geographically distributed teams.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
Active TS/SCI clearance with Ability to obtain DHS Suitability
Bachelor's and 7+ years of directly relevant cyber incident response experience
3+ years of experience evaluating and implementing new cyber response capabilities
Strong understanding of network architecture and network security
Hands-on experience performing cyber incident response activities
Ability to work independently with limited direction on complex problems
Strong written and verbal communication skills, including technical reporting
Ability to collaborate effectively across distributed teams and physical locations
Experience identifying attack classes, attack stages, and threat actor behaviors
Understanding of system and application security threats and vulnerabilities
Experience with proactive analysis of systems and networks
Proficiency with common operating systems (Linux/Unix, Windows)
Ability to travel domestically on short notice - Experience leading or mentoring technical teams
Knowledge of Computer Network Defense (CND) policies, procedures, and regulations
Experience supporting multiple threat environments, including nation-state actors
Strong understanding of adversarial tactics, techniques, and procedures (TTPs)
Network or system administration background
Experience with Identity and Access Management (IAM) tools
Ability to review and analyze Enterprise Architecture (EA) from a security perspective
Understanding of cyber defense-in-depth principles
Hands-on experience with host- and network-based intrusion detection
Experience performing event correlation and malicious activity analysis
DoD 8140.01 IAT Level II, IASAE II, CSSP Analyst or Incident Responder
GIAC certifications (GCIA, GCIH, GNFA preferred; GRID, GICSP, GCIP a plus)