Cyber Investigations Lead
Jobleads-US
We are seeking a Cyber Investigations Lead for an opportunity in Washington, DC. All applicants must have 5+ years of experience and an active Public Trust clearance. A CBP BI - High Trust is highly preferred
Job Description
The Contractor shall support CBP OPR CI in a wide range of systems engineering, administration, and cyber security and regulatory compliance services necessary to maintain and secure OPR information technology networks used in the detection and investigations of cybercrimes and CBP policy violations.The scope is to support CBP OPR CI in accordance with the Government's processes and procedures, to successfully perform tasks related to the following areas:
- Security Engineering Support (SES)
- Cyber Security Specialist / Information Systems Security Officer support
- Cyber Forensics Analyst Support
Security Engineering Support
- The Contractor shall provide Security Engineering and Sustainment (SES) support in the existing technologies (e.g., datacenter location(s)), transitional locations, and Cloud environments). Security Engineering and Sustainment support includes but is not limited to the following: Contractor personnel shall be responsible for advising and assisting with maintenance and engineering of the OPR IOD Cyber Forensic Enterprise Network (OCFEN) infrastructure to include hardware and software throughout its lifecycle to ensure adaptability. The Contractor shall utilize, by means of the CBP Internal Change Request processes and internal ticketing system, to identify priorities and service requests, take action, track and update and close tickets upon completion. The Contractor shall document all operating procedures / processes, and they should be available for activities that are likely to affect security or availability including: Change Management, Configuration types of critical equipment and Vulnerability Management (including patching). All changes must be approved by both senior engineering and IT security staff prior to execution.
Technology Evaluation
- Provide support to include but not limited to: cloud technology, internet servers, web-enabled database applications, network security, security engineering, data integrity, intrusion detection, firewall management, forensic and legal information security, virtual private networks, public key / infrastructure / digital signatures, encryption, network security architecture, and DHS Policy in developing and maintaining all required solutions.
- Collaborate with teams across the enterprise by supporting the implementation of IT services in the cloud and identifying security / technical requirements, potential problems or issues, and participate with agile software development teams.
- Assist the Government in analyzing / reviewing user needs and software requirements, specifications, and technical design documents to determine feasibility of design within time and cost constraints to develop solutions which provide automated compliance and security posture management from risks due to cyber threats and regulatory compliance issues.
- Assist the Government in performing prototype evaluations, including programs and software applications to ensure the desired information is produced and instructions are correct.
- Assist the Government in conducting integrated quality assurance testing for security functionality and resiliency on all developed solutions while tracking quality assurance metrics, such as defect dispositions and resolutions.
- Assist the Government in identifying any gaps in the OCFEN Cybersecurity baseline through a process of security engineering analysis and recommend defense functions (e.g., encryption, access control, identity management) to reduce exploitation opportunities of supply chain or other vulnerabilities for the CBP customer.
Cyber Forensics Analysis Support
- The Contractor shall provide support to Cyber Investigations (CI) in conjunction with OIT's CDF team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF SOPs. This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and/or remediation courses of action, and assessing risk posed by trusted insiders. The focus of this task is to process CBP email misuse 'egress' cases assigned to OPR in the CBP OPR Joint Intake Case Management System (JICMS), work with the OIT DLP tools to process incidents and assist with SOC Incidents / OPR investigations as needed.
- Support the Cyber Investigations through near real-time (when possible, based on tools) monitoring of the DLP solutions and other applicable tools.
- Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
- Support the design, development, and deployment of OPR's custom digital forensic builds for triaging, imaging, and advanced analysis.
- Support OIT, OI, OIG and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
- Support the Government in conducting enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis and cloud network designs for new forensic tools in support of CI or CDF and for deployment into production networks.
- Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis, assess technical gaps and conduct advanced research and development on forensic technologies and enterprise solutions.
- Support the Government in conducting formal digital forensic investigations and document findings in formal investigation reports.
- Perform Email hygiene activities in support of CBP investigations.
- Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
- Serve as Subject Matter Experts (SMEs) by supporting the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including but not limited to SBU, FOUO, LES, CONFIDENTIAL, SECRET and TOP SECRET information.
- Create and escalate cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
- Assist with authoring, updating, and modernizing OPR's IOD SOPs.
- Support the Government with managing the lifecycle of Cyber investigations from creation to closure in accordance with OPR's Policy and Procedures.
- Assist in static and dynamic file analysis to identify malware characteristics, intent, and origin.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber Investigations Lead in Washington DC vacancy
- ...ClearFocus Technologies seeks a Cyber Investigations Lead in Washington, DC. The role requires 5+ years of hands-on experience and an active Public Trust clearance; CBP BI - High Trust is highly preferred. You will guide cyber investigations, support CI operations,...Suggested
$104.8k - $192.3k
...The opportunityWe are seeking an experienced Manager to lead client engagements involving cyber incidents, data breaches, and information security... ...engagements following incident containment and forensic investigation.Direct the assessment and analysis of impacted data sets...SuggestedSummer holidayWork at officeFlexible hours- ...Job Description Dexian Government Solutions is seeking a Cyber Lead for a proposal effort supporting the F-35 Joint Program Office... ...government stakeholders. Review security alerts and coordinate investigation, escalation, containment, and recovery activities through...SuggestedContract workTemporary workWork at officeLocal area
- ...the UK. Job Description KeyLogic is actively seeking a Cyber Threat Intelligence (CTI) Lead to enable our operational counterparts advanced... ...contingent upon completing a program‑based background investigation. Responsibilities: Provide technical support on‑call...SuggestedFull timeMonday to Friday
$99k - $225k
Cyber Portfolio Manager, LeadThe Opportunity:As a cyber mission specialist, you understand... ...cyber landscape.In this role, you’ll lead cross‑functional teams as they evaluate... ...selected will be subject to a security investigation and may need to meet eligibility requirements...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- Position Summary Are you passionate about leading the frontline defense against today's most sophisticated cyber threats - both known and unknown? Do you want... ..., escalation management, and complex incident investigation, mitigation, and remediation - Own engagement...Local areaVisa sponsorship
- ...Description: We are seeking a highly skilled and mission-focused SOC Lead to oversee the daily operations of the Security Operations... ...CFR 707.4, will be conducted by the employer and a background investigation by the Federal government may be required to obtain an access...Contract workFor contractorsShift work
$156k - $195k
...OnTrac is hiring a Senior Manager of IT & Cyber Security ! Are you eager to join a... ...in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery... ...daily SOC/ARC monitoring, alert triage, investigations, and incident response; manage analysts,...Contract workTemporary workImmediate startRemote workFlexible hoursShift work$154.05k - $278.48k
...Description Leidos has an exciting opportunity for Cyber Security Engineer—Technical Lead in our Intel Security Sector's Analysis Solutions Business Area . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission...Local areaImmediate startFlexible hours$207k - $230k
...confident, responsible, organization-wide use of AI, including our Cyber and Daybreak capabilities. Our work combines strategic... ...environments. About the role We are seeking a Cyber Enablement Lead to help government cyber professionals turn Daybreak’s...Work at officeLocal areaRelocation packageFlexible hours- ...OpenAI, Inc. is seeking a Cyber Enablement Lead to empower government cyber professionals by turning Daybreak capabilities into practical, mission-focused workflows and stronger defenses. This role combines technical credibility with hands-on training, executive briefings...
- ...impact. # Oversees daily security monitoring, alert triage, investigation, containment, remediation, recovery coordination, vulnerability... ..., capacity needs, upgrades, and operational readiness. # Leads or supports security and network initiatives, implementation planning...Remote work
- ...Job Description Job Description Cyber Incident Manager Location: Washington Dc... ...is seeking a Cyber Incident Manager to lead onsite incident response operations for... ...response capability that provides immediate investigation, containment, and recovery support to...Immediate startShift work
- ...support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation...Contract workImmediate startShift work
- ...programs. You will help shape messaging, coordinate with congressional, executive, and defense stakeholders, and translate complex cyber policy into clear communications. The role requires a Bachelor's in a technical or communications field, 7+ years in strategic communications...Work at office
- A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...
- The Tatitlek Corporation seeks a Commercial Engagement Executive to drive tech partnerships and market strategy for defense, DoD programs, cybersecurity and electronic warfare. You will collaborate with government partners and private sector vendors, assess needs, source...
- Nightwing is seeking a Technical Engagement Network (TEN) Lab Manager to join the IT support services desk in the customer environment. You will act as the first level Help Desk for the TEN Lab’s systems, assist with user setup, respond to requests, and manage tickets and...
- A cybersecurity and intelligence firm is seeking a Cyber Eviction Analyst to support critical incident response missions. The role requires extensive expertise in threat actor tools, incident mitigation, and collaborative problem-solving. Ideal candidates will possess at...
$104.8k - $192.3k
...opportunity We are seeking an experienced Manager to lead client engagements involving cyber incidents, data breaches, and information security... ...engagements following incident containment and forensic investigation. Direct the assessment and analysis of impacted...Summer holidayWork at officeFlexible hours- ...Communications Advisor to provide onsite support at the Pentagon. This role involves supporting the Assistant Secretary of War for Cyber Policy and developing strategic communications for defense-related programs. The ideal candidate will have over 7 years of experience...
- General Dynamics Information Technology, Inc. is seeking a National Cyber Communications Specialist to produce operational cyber communications for federal and private-sector audiences. You will write alerts and advisories from analyst output, ensuring accuracy, scope,...
- A cybersecurity firm in Arlington, Virginia is seeking a Cyber Action Officer to support incident response efforts for government clients experiencing cyber-attacks. Responsibilities include managing cyber incidents, coordinating reports, and collaborating with partners...
- Noblis is seeking a security professional to advance cyber defense programs for federal missions. You will evaluate capabilities, lead improvements, and design incident response playbooks within an agile framework. The role emphasizes cross‑functional collaboration, data...Remote job
- ...support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation...Contract workLocal areaImmediate startFlexible hoursShift work
$134.5k - $265.1k
Position Summary Data Privacy ManagerAs a Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery, design, and implementation of privacy technology solutions that help organizations address regulatory requirements, strengthen data governance...Local area- ...candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Cyber Engagement Scheduling Team Lead Location:National Capital Region Security Clearance: Secret Duties and Responsibilities The Cyber...Full timeFor contractorsShift work
$150k - $160k
...the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows. Leads risk assessment and advisory activities for emerging technologies (AI/ML, cloud, RPA), translating technical exposures into business...Contract workTemporary workWork at officeFlexible hours$112k - $179k
Peraton is hiring a TASO Team Lead to oversee advanced cyber defense missions in Arlington, VA. This role encompasses threat hunting, malware analysis, and incident response, leading technical operations while managing a skilled team. Candidates must have a Bachelor’s...- ARETUM Holdings LLC seeks a Cyber Partner Coordinator Manager to lead stakeholder engagement and coordination across government, industry, and partners in support of national cybersecurity planning. This role combines strategic planning, stakeholder engagement, research...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Investigations Lead. Be the first to apply!
Related searches
- cyber security lead Washington DC
- director - cyber security Washington DC
- cybersecurity manager Washington DC
- cyber insurance Washington DC
- cyber forensics Washington DC
- cyber threat intelligence analyst Washington DC
- cyber Washington DC
- cyber sales Washington DC
- cyber security project manager
- cyber security lead



