Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
NSOC Incident Response Lead image - Rise Careers
Job details

NSOC Incident Response Lead

DescriptionLeidos is seeking an experienced Top Secret cleared Incident Response (IR) Lead to support a highly visible NSOC position. Reporting to the Leidos NSOC Lead, the NSOC Response Lead is responsible to independently lead teams of operators through the incident response lifecycle.The position may require occasional short-term travel to CONUS and OCONUS sites. This position may require an infrequent shift in workday schedule to support exercises occurring over weekends.Primary Responsibilities• Assesses, categorizes, recommends prioritization, develops, reports on, guides, and assumes responsibility for cyber-IR actions in accordance with NIST SP 800-61 Rev. 2.• Leads the IR team.• Conducts in-depth analysis on hosts and networks, forensic analysis, log analysis, and triage in support of IR.• Develops and builds security content, scripts, tools, or methods to enhance the incident investigation processes.• Recognize attacker and APT activity, tactics, and procedures as indicators of compromise (IOCs) that can be used to improve monitoring, analysis, and incident response processes.• Utilizes technologies such as host forensics tools, Endpoint Detection & Response tools, log analysis and full packet capture to perform hunt and investigative activity to examine endpoint and network-based data.• Populates dashboards with key metrics and processes and deliver technical presentations to various levels of customer leadership. Compiles and presents reports to senior leaders.• Works with stakeholders to implement remediation plans in response to incidents.• Ensures that the IR team has necessary personnel, resources, and skills.• Develops artifacts supporting Information Assurance and Risk Management Framework (RMF) processes.Basic Qualifications• Bachelor's degree and 12 – 15 years of prior relevant experience or Masters with 10 – 13 years of prior relevant experience. May possess a Doctorate in technical domain. Additional years of relevant experience will be considered in lieu of degree.• Top Secret clearance with ability to obtain and maintain TS/SCI.• Strong problem-solving abilities using analytic and qualitative reasoning.• Ability to independently prioritize and complete multiple tasks with little to no supervision.• Ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses.• Effective communication with customer leadership to disseminate timely updates of critical incidents with an emphasis on attention to detail and accurate reporting.• Experience organizing, directing, and managing operation support functions involving multiple, complex, and interrelated project tasks.• Advanced knowledge of the Incident Response Lifecycle and applicability to various types of incidents.• Ability to collaborate with technical staff and customers to identify, assess, and resolve complex security problems, issues, and risks to facilitate resolution and risk mitigation.• Experience creating processes, playbooks, and SOPs for tools and workflows. Relevant experience should be in the areas of incident detection and response, malware analysis, or computer forensics.• Ability to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.• Experience running cyber incident investigations with emphasis on attention to detail and adherence to defined escalation paths.• At least one current DoD 8140 certificationPreferred Qualifications• Experience with virtualized environments (VMware, Red Hat).• Experience working with cloud computing and infrastructure security (AWS, Azure, etc.) to IL6• Experience as a member of agile programs• Experience in Federal Government, DOD or Law Enforcement in CND, CIRT or SOC role• Knowledge of the Cyber Kill Chain and the MITRE ATT&CK framework• Knowledge of Structured Analytic TechniquesOriginal Posting Date:2024-12-20While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $112,450.00 - $203,275.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Leidos DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Leidos
Leidos CEO photo
Tom Bell
Approve of CEO

Average salary estimate

Estimate provided by employer
$163500 / ANNUAL (est.)
min
max
$103K
$224K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About NSOC Incident Response Lead, Leidos

If you're passionate about cybersecurity and have extensive experience in incident response, Leidos has an exciting opportunity for you as the NSOC Incident Response Lead in Hampton, VA. In this role, you'll be the driving force behind our incident response efforts, leading dedicated teams through the complexities of the incident response lifecycle. You’ll be reporting directly to the NSOC Lead and guiding your team with your expertise in analyzing, categorizing, and recommending prioritization strategies based on NIST guidelines. Your ability to conduct thorough forensic analyses and recognize attackers' tactics will make a significant impact on our security posture. We’re looking for someone who can not only assess incidents but also develop innovative scripts and tools to enhance our response capabilities. You'll collaborate closely with stakeholders to implement effective remediation plans and ensure our team has the right skills and resources to tackle challenges. As a key player in the NSOC, you'll compile important reports and dashboards, presenting findings to senior leadership, and influencing the security direction of our organization. We value your problem-solving skills and the ability to prioritize tasks independently. If you have a blend of experience in incident detection, response, and the ability to communicate effectively with technical and non-technical stakeholders, we want to hear from you. Your experience in directing complex operations and creating robust frameworks will help drive our success against cyber threats.

Frequently Asked Questions (FAQs) for NSOC Incident Response Lead Role at Leidos
What are the main responsibilities of the NSOC Incident Response Lead at Leidos?

The NSOC Incident Response Lead at Leidos is primarily responsible for guiding the incident response process, leading teams through the incident response lifecycle, conducting forensic analyses, and managing the assessment and prioritization of cyber incidents. This involves building security content, developing incident investigation tools, and collaborating with stakeholders to implement remediation strategies.

Join Rise to see the full answer
What qualifications do I need to become an NSOC Incident Response Lead at Leidos?

To qualify for the NSOC Incident Response Lead role at Leidos, you typically need a Bachelor's degree coupled with 12 to 15 years of relevant experience, or a Master's with 10 to 13 years. A Top Secret clearance is essential, and advanced knowledge of the Incident Response Lifecycle, excellent problem-solving skills, and experience in cyber incident investigations are highly valued.

Join Rise to see the full answer
What skills are essential for the NSOC Incident Response Lead position at Leidos?

Key skills for the NSOC Incident Response Lead at Leidos include strong analytical abilities, effective communication skills, expertise in incident detection and response, capability in scripting languages like Python or PowerShell, and familiarity with threat models such as the Cyber Kill Chain and MITRE ATT&CK framework.

Join Rise to see the full answer
Is there room for growth as an NSOC Incident Response Lead at Leidos?

Absolutely! Working as an NSOC Incident Response Lead at Leidos offers ample opportunities for professional growth. As you lead critical cyber initiatives and refine your skills, you'll be in a great position to advance into higher leadership roles or specialized areas within the cybersecurity domain.

Join Rise to see the full answer
What does the work environment look like for an NSOC Incident Response Lead at Leidos?

The work environment for the NSOC Incident Response Lead at Leidos is dynamic and collaborative, often involving teamwork with various departments to tackle complex cybersecurity challenges. You may also engage in occasional travel to support different sites. Flexibility in your workday may be required for exercises that could occur on weekends, reflecting our commitment to maintaining robust security protocols.

Join Rise to see the full answer
Common Interview Questions for NSOC Incident Response Lead
Can you explain your experience with the incident response lifecycle?

When answering, emphasize specific incidents you've managed, describe your role in each phase of the cycle, and highlight methodologies used, such as NIST SP 800-61.

Join Rise to see the full answer
How do you prioritize incidents based on severity?

Discuss criteria you use for prioritization, like impact, urgency, and potential data loss, and relate a past experience where you successfully managed this process.

Join Rise to see the full answer
What tools do you typically use for forensic analysis?

Be sure to mention specific tools and how you use them for data collection, analysis, and validation during investigations, like EDR solutions or log analysis tools.

Join Rise to see the full answer
How do you handle communication during a cybersecurity incident?

Talk about your approach to ensuring timely updates to stakeholders, emphasizing the importance of clear, concise communication and reporting methods you’ve used.

Join Rise to see the full answer
Describe a challenging incident response you led.

Share a detailed account of a challenging incident, outlining the steps you took, lessons learned, and how the outcome improved future responses.

Join Rise to see the full answer
What experience do you have in developing incident response playbooks?

Highlight your role in creating, updating, or utilizing playbooks, including details about collaborative efforts in developing effective standard operating procedures.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats?

Mention resources like industry publications, online forums, or professional networks you rely on for the latest threat intelligence and ongoing education.

Join Rise to see the full answer
Can you discuss a time you had to work with cloud security?

Provide an example of your experience with cloud services like AWS or Azure, detailing the security measures you implemented during an incident.

Join Rise to see the full answer
What scripting languages are you proficient in, and how have you used them?

Talk about specific scripts you’ve written to automate processes or improve incident response times, showcasing your technical skills.

Join Rise to see the full answer
Why do you want to work as an NSOC Incident Response Lead at Leidos?

Express your passion for cybersecurity and your desire to work for Leidos, emphasizing alignment with their values and your eagerness to contribute to their mission.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Leidos Hybrid Joint Base Pearl Harbor-Hickam, Hawaii
Posted 2 days ago
Photo of the Rise User
Posted 8 days ago
Posted 11 days ago
Photo of the Rise User
Humana Remote Springfield, IL
Posted 10 days ago
Photo of the Rise User
Leidos Hybrid Herndon, VA
Posted 8 days ago
Photo of the Rise User
Cast & Crew Remote United States (Remote)
Posted 8 days ago
Inclusive & Diverse
Diversity of Opinions
Mission Driven
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Mental Health Resources
Photo of the Rise User
Posted 3 days ago

Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. At Leidos, our mission is to make the world safer, healthier, and mor...

395 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 21, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!