Cyber Security Incident Handler - Associate

Agile DefenseFort Huachuca, AZ
7d

About The Position

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. We are seeking a motivated and detail-oriented Associate Incident Handler to begin their career with our 24x7 security operations team. The ideal candidate will have a foundational understanding of cybersecurity principles and an eagerness to learn. In this role, you will be responsible for monitoring security alerts, performing initial event triage, and following established procedures to support incident response activities. You will work closely with intermediate & senior analysts to investigate and resolve security events, contributing directly to the protection of our organization. This is an excellent opportunity for an emerging cyber professional to gain hands-on experience, with a preference for candidates who have familiarity with Enterprise, military or Department of War (DOW) operational environment.

Requirements

  • Experience: 0-2 years of experience in IT, cybersecurity, or a related technical role. Internships or academic projects in cybersecurity are highly valued.
  • An associate’s degree in cyber security or related field can replace the experience requirements.
  • Core Knowledge: Foundational understanding of cybersecurity principles (e.g., CIA Triad), common network protocols (TCP/IP), and operating systems (Windows/Linux).
  • Tool Experience: Familiarity with the purpose of security tools such as SIEM and Endpoint Detection and Response (EDR) platforms.
  • Skills: Strong eagerness to learn, detail-oriented, with developing analytical and problem-solving abilities.
  • Communication: Good written and verbal communication skills, with the ability to clearly document actions and escalate issues.
  • Environment: Ability to work effectively in a structured, 24x7 shift-based operational environment and follow defined procedures meticulously.
  • Must be able to obtain and maintain a Secret security clearance.
  • Candidates must possess one of the following certifications prior to start date: · CompTia Security+, Certified Ethical Hacker (CEH), CYSA+

Nice To Haves

  • Military/DoD Experience: Familiarity with U.S. military policies, procedures, and organizational structures.
  • Cyber Security Controls: Foundational understanding of cybersecurity controls and the importance of adhering to security policies in a professional environment.
  • Network Analysis: Basic experience reviewing network activity logs and an understanding of common network protocols (e.g., DNS, HTTP, SMB).
  • Endpoint Security: Familiarity with reviewing security events from standard endpoint platforms (e.g., antivirus, host firewalls).
  • Tool Familiarity: Exposure to or academic experience with some of the following tools: · A SIEM platform (e.g., Splunk, Kibana, Sentinel) · MDE EDR platform and or KQL · ServiceNow or another ticketing system · Linux Command Line

Responsibilities

  • Alert Monitoring and Triage: Continuously monitor the security alert queue from SIEM, EDR, and other security tools, performing initial analysis to classify and prioritize events according to established procedures.
  • Initial Response and Escalation: Execute initial response steps based on documented playbooks for common security events. Accurately escalate qualified incidents to intermediate and senior handlers when necessary.
  • Incident Documentation: Meticulously document all analysis and actions taken in the incident management system, ensuring a clear and concise record of the initial response effort.
  • Following Defined Procedures: Adhere strictly to standard operating procedures (SOPs) for incident handling, containment, and reporting.
  • Team Collaboration: Assist senior team members in their investigation of more complex incidents by gathering data, running pre-defined queries, and performing assigned tasks.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Entry Level

Education Level

Associate degree

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service