CronJobs

security jobs

SITEC - Cyber Defense Incident Responder - MacDill AFB

Peraton · MacDill AFB, FL, US

hybridunknown$66,000–$106,000Posted Sep 18, 2026

Apply on the employer site

About this role

## Responsibilities - Support the **Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 – Enterprise Operations and Maintenance (EOM)** at **MacDill AFB (Florida)**. - Serve as the **primary technical operator** for **detecting, investigating, containing, eradicating, and recovering** from confirmed security incidents across **enterprise, hybrid, and multi-cloud** environments. - Execute **rapid-response protocols** to: - Isolate active adversaries - Stop unauthorized lateral movement - Systematically mitigate active threats - Perform **immediate assessment and validation** of inbound escalations to determine **scope, impact, severity, and root cause**. - Take immediate response actions to: - Isolate compromised endpoints - Sever malicious network connections - Halt unauthorized lateral movement - Conduct **host-based and network digital forensics**, including: - Volatile memory analysis - Disk imaging - Artifact extraction to reconstruct adversary timelines - Remove adversary persistence and restore clean operations by: - Eliminating persistence mechanisms - Purging unauthorized credentials - Validating clean system baselines before returning services - Maintain **strict chain-of-custody** documentation. - Produce **Incident Summaries** and **After-Action Reports (AARs)**, including **root-cause findings** for the detection engineering team. - Perform **static and dynamic triage** of recovered malicious binaries/scripts to extract: - Hardcoded IOCs - Persistence mechanisms - Execution behavior - Identify, catalog, and remove adversary-created persistence artifacts (e.g., scheduled tasks, rogue services, modified registry keys, hidden backdoor accounts). ## Reporting & Coordination - Author comprehensive Incident Summaries and AARs covering: - Attack vectors - Impact timelines - Defensive breakdowns - Coordinate with **legal counsel, law enforcement, and regulatory compliance** to share **sanitized forensic evidence** and meet reporting timelines. ## Exercises, Playbooks, and Readiness - Design, facilitate, and participate in **scenario-based tabletop exercises (TTXs)** with leadership, IT operations, and mission stakeholders. - Author and continuously update **IR playbooks** for scenarios such as: - Ransomware - Supply chain compromise - Business email compromise - Maintain readiness of the **forensic toolkit** (e.g., triage scripts, collection images). - Query and analyze diverse telemetry streams across **SIEM** (and related sources).

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord