Subject Matter Expert II
Job description
About the role
Cyber Incident Manager
ARSIEM Corporation establishes a dedicated operational presence in Arlington, Virginia, to serve United States Government clients. We seek a Cyber Incident Manager to deliver immediate on-site response for civilian agencies and critical asset owners. This professional will manage the complete lifecycle of cyber events, ensuring continuity of essential services during compromise.
The position represents a full-time engagement offering a total compensation of one hundred thirty thousand dollars. Successful candidates join a team that provides current technical solutions while creating opportunities for individual career advancement. Professionals in this role will directly influence client outcomes and contribute to national cyber resilience.
The Cyber Incident Manager coordinates complex digital emergencies from initial detection through case closure. This role assumes ownership of the entire event timeline for government systems. You will work closely with agency clients to stabilize environments and maintain critical operational status. The position requires decisive action under pressure while balancing technical accuracy and client communication.
Incident response coordination forms the core responsibility. You will translate technical events into actionable plans for diverse stakeholders. The role demands independence in managing multiple concurrent cases with strict delivery requirements. Every action contributes to organizational learning and strengthens future response capabilities.
Primary Responsibilities
You will map incoming reports and structure case details to achieve rapid comprehension of situations. This initial assessment phase determines the appropriate response strategy and resource allocation. Organized information flow enables swift decision-making throughout the incident lifecycle.
Designing containment measures and temporary remediation steps represents a critical early priority. These actions must prevent further intrusion while preserving digital evidence integrity. You will implement controls that limit damage without disrupting essential government functions.
Coordination with technical engineering teams ensures response actions align with client priorities and operational constraints. You will serve as the central communication hub during active incidents. This coordination extends to external partners and supporting organizations when necessary.
Explaining attack patterns and recovery procedures to non-technical officials requires clear and precise language. You will translate complex technical concepts into accessible information for decision-makers. This communication function supports informed choices during critical periods.
Documenting each stage of the response creates a clear record for current and future teams. Your guidance ensures consistent methodology across incidents. This practice supports organizational improvement and compliance requirements.
Tracking system changes over time allows for adjustment of response tactics as new data emerges. You will analyze evolving situations and modify approaches accordingly. This dynamic management is essential for resolving complex incidents.
Establishing formal handoff points with partner organizations maintains momentum and clarity of responsibility. These transitions ensure continuous progress without disruption to response activities. You will manage these interfaces to prevent delays or confusion.
Confirming that response results meet contractual specifications and client expectations is a final verification step. This assessment guarantees that service level requirements are satisfied. Closure occurs only after all objectives are validated.
Requirements
Holding current eligibility for a government security clearance is mandatory for this position. You must possess a minimum of three years of hands-on cyber incident handling experience. This background should include real-world response scenarios across multiple event types.
You must operate independently while managing multiple cases and adhering to strict timelines. This capability requires strong personal organization and judgment. Experience with standard investigation methodologies is essential.
Knowledge of evidence preservation rules and chain-of-custody procedures is required. You will handle sensitive digital information with appropriate care. Professional discretion guides all interactions with case data.
Precise communication with both officials and technical teams is necessary under stressful conditions. You will maintain clarity and focus during high-pressure scenarios. This skill ensures accurate information exchange and reduces error potential.
Preferred Qualifications
Familiarity with specific agency reporting procedures and compliance frameworks provides distinct advantages. This knowledge streamlines interactions with regulated environments. It demonstrates understanding of the government operational context.
Tools and Competencies
Effective performance requires proficiency with Microsoft 365 Defender and Microsoft Sentinel platforms. Experience with ServiceNow and Jira supports efficient case management and workflow tracking. Capability with PowerShell enables automation and data collection during investigations.
Important Notes
You must verify all application details Information presented here serves as a general overview of the position. Specific instructions and forms reside on the designated application website.