Senior Cybersecurity Incident Response Administrator Security Clearance
Listed on 2026-01-07
-
IT/Tech
Cybersecurity, Information Security, Security Manager
Senior Cybersecurity Incident Response Administrator with Security Clearance
Join to apply for the Senior Cybersecurity Incident Response Administrator with Security Clearance role at Integral Federal, Inc.
Christiansburg, VA – $97,000.00 - $ – 3 days ago
OverviewThe Senior Cybersecurity Incident Response Administrator is responsible for managing Security Information and Event Management (SIEM) systems, including deploying, installing, managing infrastructure, and monitoring events in accordance with Army Business System Log Data Policy and other DoD/Army requirements for the U.S. Army Product Lead Acquisition, Logistics, and Technology Enterprise Systems and Services (PL ALTESS).
Responsibilities- Create SIEM dashboards to display clear and concise visualizations of security-related events, enabling the detection of anomalies and investigation of threats in near real‑time.
- Monitor SIEM dashboards to detect threats and anomalies, investigate events, and escalay as necessary.
- Assess and develop reporting requirements to support audits and security controls, provide Public Key Infrastructure (PKI) support, and monitor DoD and Army web application security standards and best practices.
- Review Army Cyber Tasking Orders (CTOs), coordinate with Army Cyber Security Service Providers, participate in SW Assurance reviews, and evaluate Information Systems Design Plans for compliance with relevant security regulations, policies, and best industry practices.
- Cybersecurity Certification (such as Certified Information Systems Security Professional (CISSP)/Information Systems Security Engineering Professional (ISSEP)/Security+/Certified Ethical Hacker (CEH/etc.).
- 10 or more years' experience with Cybersecurity and Incident Response or related areas.
- Extensive experience managing Security Information and Event Management (SIEM) systems, including getting relevant data into the SIEM.
- Proficiency in creating and managing SIEM dashboards for security event visualization.
- Strong ability to monitor and investigate security events and anomalies.
- Experience in developing reporting requirements for audits and security controls.
- Knowledge of Public Key Infrastructure (PKI) and managing SSL/TLS certificates.
- Familiarity with DoD and Army web application security standards and best practices.
- Ability to review and respond to Army Cyber Tasking Orders (CTOs).
- Experience coordinating with Cyber Security Service Providers for audit logs and incident response.
- Participation in SW Assurance reviews for application audit log validation.
- Ability to review and evaluate Information Systems Design Plans and related documents for security compliance.
- Active DoD Secret Security Clearance.
- Preferred:
Bachelor's degree in Computer Science or equivalent years of experience. - Familiarity with Army enterprise monitoring tools and practices.
- Strong analytical and problem‑solving skills.
- Excellent communication and coordination skills.
- Experience with incident response activities.
- Knowledge of engineering change proposals and configuration management.
- Understanding of Continuity of Operation Plans and Communication Plans.
- Experience with security regulations and best industry practices.
- Ability to work effectively in a team environment and collaborate with various stakeholders.
- Medical, Dental & Vision Insurance
- Flexible Spending Accounts
- Short‑Term and Long‑Term Disability Insurance
- Life Insurance
- Paid Time Off & Holidays
- Earned Bonuses & Awards
- Professional Training Reimbursement
- Paid Parking
- Employee Assistance Program
- Equal Opportunity Employer / Protected Veteran / Disability
- Seniority level:
Mid‑Senior level - Employment type:
Full‑time - Job function:
Engineering and Information Technology
Referrals increase your chances of interviewing at Integral Federal, Inc. by 2x.
Apply BELOW
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).