Security Operations and Incident Response Lead
U.S. General Services Administration (GSA) — United States
Posted: 2026-09-29
Job Description
• Serve as Cyber Incident Commander for serious IT security incidents within the U.S. General Services Administration.
• Lead the combined Incident Response/Security Operations Center, threat-hunting team, incident handling, digital forensics, monitoring, and security alerting programs.
• Use and monitor data loss prevention tools including Zscaler and Cloudlock, while automating repetitive security processes.
• Provide security consulting and threat-hunt support across cloud, BYOD, VDI, mobile, remote access, Active Directory, virtualization, Zero Trust, and identity and access management initiatives.
• Advise on secure network restructuring, sensitive government data protection, security-risk remediation, automation, integrations, and deployment of new security toolsets.