View all jobs

Cyber Investigations Lead

  • Washington, DC

 

We are seeking a Cyber Investigations Lead for an opportunity in Washington, DC. All applicants must have  5+ years of experience and an active Public Trust clearance. A CBP BI - High Trust is highly preferred

Job Description

The Contractor shall support CBP OPR CI in a wide range of systems engineering, administration, and cyber security and regulatory compliance services necessary to maintain and secure OPR information technology networks used in the detection and investigations of cybercrimes and CBP policy violations.
The scope is to support CBP OPR CI in accordance with the Government's processes and procedures, to successfully perform tasks related to the following areas:
  • Security Engineering Support (SES)
  • Cyber Security Specialist / Information Systems Security Officer support
  • Cyber Forensics Analyst Support

Security Engineering Support

  • The Contractor shall provide Security Engineering and Sustainment (SES) support in the existing technologies (e.g., datacenter location(s)), transitional locations, and Cloud environments). Security Engineering and Sustainment support includes but is not limited to the following: Contractor personnel shall be responsible for advising and assisting with maintenance and engineering of the OPR IOD Cyber Forensic Enterprise Network (OCFEN) infrastructure to include hardware and software throughout its lifecycle to ensure adaptability. The Contractor shall utilize, by means of the CBP Internal Change Request processes and internal ticketing system, to identify priorities and service requests, take action, track and update and close tickets upon completion. The Contractor shall document all operating procedures / processes, and they should be available for activities that are likely to affect security or availability including: Change Management, Configuration types of critical equipment and Vulnerability Management (including patching). All changes must be approved by both senior engineering and IT security staff prior to execution.

Technology Evaluation

  • Provide support to include but not limited to: cloud technology, internet servers, web-enabled database applications, network security, security engineering, data integrity, intrusion detection, firewall management, forensic and legal information security, virtual private networks, public key / infrastructure / digital signatures, encryption, network security architecture, and DHS Policy in developing and maintaining all required solutions.
  • Collaborate with teams across the enterprise by supporting the implementation of IT services in the cloud and identifying security / technical requirements, potential problems or issues, and participate with agile software development teams.
  • Assist the Government in analyzing / reviewing user needs and software requirements, specifications, and technical design documents to determine feasibility of design within time and cost constraints to develop solutions which provide automated compliance and security posture management from risks due to cyber threats and regulatory compliance issues.
  • Assist the Government in performing prototype evaluations, including programs and software applications to ensure the desired information is produced and instructions are correct.
  • Assist the Government in conducting integrated quality assurance testing for security functionality and resiliency on all developed solutions while tracking quality assurance metrics, such as defect dispositions and resolutions.
  • Assist the Government in identifying any gaps in the OCFEN Cybersecurity baseline through a process of security engineering analysis and recommend defense functions (e.g., encryption, access control, identity management) to reduce exploitation opportunities of supply chain or other vulnerabilities for the CBP customer.

Cyber Forensics Analysis Support

  • The Contractor shall provide support to Cyber Investigations (CI) in conjunction with OIT's CDF team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF SOPs. This support includes monitoring activities, conducting threat analysis, investigating policy violations, identifying mitigation and/or remediation courses of action, and assessing risk posed by trusted insiders. The focus of this task is to process CBP email misuse 'egress' cases assigned to OPR in the CBP OPR Joint Intake Case Management System (JICMS), work with the OIT DLP tools to process incidents and assist with SOC Incidents / OPR investigations as needed.
  • Support the Cyber Investigations through near real-time (when possible, based on tools) monitoring of the DLP solutions and other applicable tools.
  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
  • Support the design, development, and deployment of OPR's custom digital forensic builds for triaging, imaging, and advanced analysis.
  • Support OIT, OI, OIG and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
  • Support the Government in conducting enterprise and individual system(s) endpoint (e.g., Windows, Linux, Mac, and Cloud systems) and network based digital forensic analysis and cloud network designs for new forensic tools in support of CI or CDF and for deployment into production networks.
  • Leverage commercially available and open-source forensic tools to efficiently perform forensic analysis, assess technical gaps and conduct advanced research and development on forensic technologies and enterprise solutions.
  • Support the Government in conducting formal digital forensic investigations and document findings in formal investigation reports.
  • Perform Email hygiene activities in support of CBP investigations.
  • Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to reconstitution.
  • Serve as Subject Matter Experts (SMEs) by supporting the preservation of evidence, which includes a deep understanding of proper chain of custody and proper storage, handling, and transmission procedures for various data sets including but not limited to SBU, FOUO, LES, CONFIDENTIAL, SECRET and TOP SECRET information.
  • Create and escalate cases via ticket management system to proper law enforcement entities in compliance with CBP policy and SOPs.
  • Assist with authoring, updating, and modernizing OPR's IOD SOPs.
  • Support the Government with managing the lifecycle of Cyber investigations from creation to closure in accordance with OPR's Policy and Procedures.
  • Assist in static and dynamic file analysis to identify malware characteristics, intent, and origin.