SITEC - Cyber Defense Incident Responder - MacDill AFB
Peraton · MacDill AFB, FL, US
About this role
## Responsibilities - Support the **Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 – Enterprise Operations and Maintenance (EOM)** at **MacDill AFB (Florida)**. - Serve as the **primary technical operator** for **detecting, investigating, containing, eradicating, and recovering** from confirmed security incidents across **enterprise, hybrid, and multi-cloud** environments. - Execute **rapid-response protocols** to: - Isolate active adversaries - Stop unauthorized lateral movement - Systematically mitigate active threats - Perform **immediate assessment and validation** of inbound escalations to determine **scope, impact, severity, and root cause**. - Take immediate response actions to: - Isolate compromised endpoints - Sever malicious network connections - Halt unauthorized lateral movement - Conduct **host-based and network digital forensics**, including: - Volatile memory analysis - Disk imaging - Artifact extraction to reconstruct adversary timelines - Remove adversary persistence and restore clean operations by: - Eliminating persistence mechanisms - Purging unauthorized credentials - Validating clean system baselines before returning services - Maintain **strict chain-of-custody** documentation. - Produce **Incident Summaries** and **After-Action Reports (AARs)**, including **root-cause findings** for the detection engineering team. - Perform **static and dynamic triage** of recovered malicious binaries/scripts to extract: - Hardcoded IOCs - Persistence mechanisms - Execution behavior - Identify, catalog, and remove adversary-created persistence artifacts (e.g., scheduled tasks, rogue services, modified registry keys, hidden backdoor accounts). ## Reporting & Coordination - Author comprehensive Incident Summaries and AARs covering: - Attack vectors - Impact timelines - Defensive breakdowns - Coordinate with **legal counsel, law enforcement, and regulatory compliance** to share **sanitized forensic evidence** and meet reporting timelines. ## Exercises, Playbooks, and Readiness - Design, facilitate, and participate in **scenario-based tabletop exercises (TTXs)** with leadership, IT operations, and mission stakeholders. - Author and continuously update **IR playbooks** for scenarios such as: - Ransomware - Supply chain compromise - Business email compromise - Maintain readiness of the **forensic toolkit** (e.g., triage scripts, collection images). - Query and analyze diverse telemetry streams across **SIEM** (and related sources).
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.