Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Cyber Defense Incident Responder On-site - TS/SCI

$175k - $180k

S2i2, Inc

Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington, VA On-site Salary Range $175,000 to $180,000 Certification Required DoD 8570 / DoD 8140 IAT Level II One of the following: Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent Application Deadline August 31, 2026 Description The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands‑on technical work while guiding and directing senior and mid‑level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks. Duties And Responsibilities - Lead a small team of advanced and mid‑level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.

  • Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.
  • Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern‑matching detection tools.
  • Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.
  • Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.
  • Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.
  • Provide critical support to the NOSC and coordinate team schedules to ensure on‑call coverage for after‑hours, weekends, and holidays.
  • Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.
  • Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).
  • Ensure that all written communication (reports, briefings, and alerts) is professional, high‑quality, free of errors, and clearly delivers actionable intelligence.
Minimum Qualifications And Requirements - Bachelor's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.
  • Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.
  • Demonstrated leadership skills, preferably in a formal leadership role.
  • Scripting experience.
  • TS/SCI clearance is required.
Knowledge, Skills, And Abilities - Advanced technical expertise in threat hunting, deep‑drive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.
  • Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.
  • Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid‑level and senior information security professionals during active cyber operations and crisis response.
  • Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.
  • Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.
  • Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).
  • Technical mentorship: experience teaching, mentoring, and guiding junior and mid‑level analysts in advanced digital forensics and malware analysis techniques.
  • Advanced forensics: deep technical understanding of host and network‑based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.
  • Malware and script analysis: high‑level skill in reverse‑engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.
  • Superior research capabilities: exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.
  • Executive communication: excellent written and verbal communication skills, capable of producing high‑quality, error‑free incident reports and briefings suitable for government leadership.
  • Technical translation: ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non‑technical decision‑makers.
  • Project and case management: proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.
  • Crisis management: ability to take ownership during high‑stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.
  • Collaboration: well‑developed problem‑solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.
  • Attention to detail: excellent organizational skills with acute attention to detail, critical for maintaining chain‑of‑custody, accurate incident logging, and operating within strict SAP compliance frameworks.
About S2i2 S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family‑like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company. We Are Proud To Include Support to achieve professional certifications and degrees Leadership that is accessible to all employees Regular company updates Client networking social engagements Monthly team‑building activities (past examples: Top Golf) Supporting our community - including veterans All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. #J-18808-Ljbffr S2i2, Inc

Vacancy posted 11 hours ago
Similar jobs that could be interesting for youBased on the Lead Cyber Defense Incident Responder On-site - TS/SCI in Arlington, VA vacancy
  • S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA on-site to lead a skilled team defending TS/SCI and SAP environments. The role demands hands-on threat detection, threat intelligence, and advanced incident response capabilities in highly secure... 
    Cyber
    Website

    S2i2, Inc

    Arlington, VA
    3 days ago
  • S2i2 in Arlington, VA is seeking a Lead Cyber Defense Incident Responder (Advanced) to lead a small team of senior...  ...and mid‑level analysts. This on‑site role involves hands‑on threat detection...  ...highly secure government enclaves (TS/SCI/SAP). The ideal candidate has TS/SCI... 
    Cyber
    Website

    S2i2, Inc

    Arlington, VA
    11 hours ago
  • S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA. The role requires hands-on threat hunting, incident response leadership, and direct engagement with government clients operating TS/SCI and SAP networks. The ideal candidate has extensive experience... 
    Cyber

    S2i2, Inc

    Arlington, VA
    2 days ago
  •  ...Analyst to support enterprise cyber defense in the Washington, D.C. metro...  ...and process gaps, support incident-response, and translate complex...  ...recommendations. The role requires on-site work within 50 miles of...  ...and the candidate must hold TS/SCI with CI Poly. #J-18808-... 
    Cyber
    Website

    OPS TECH ALLIANCE LLC

    Mc Lean, VA
    3 days ago
  • $100k - $125k

     ...cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA....  ...strong analytical skills and an active TS/SCI clearance. Candidates should have over 8...  ...opportunity to work on critical national security missions. #J-18808-Ljbffr Argo Cyber Systems
    Cyber
    Website

    ARGO Cyber Systems

    Arlington, VA
    11 hours ago
  • $111k - $122k

     ...career at the company leading workforce...  ...Computer Security Incident Response AnalystThis...  ...you to be on-site in Northern Virginia...  ...Response Analyst will respond to and investigate cyber security events...  ...Top Secret/SCI security clearance...  ...position requires a USA TS/SCI with... 
    Cyber
    Website
    Full time
    Work experience placement
    Local area

    Salesforce

    Herndon, VA
    1 day ago
  •  ...opportunity to support national defense. Your work will help keep...  ...Collaborate with engineering, cyber, and operations teams to validate...  ...Ensure high availability, site resilience, and optimized performance...  ...Security+ CE, etc.) Active TS/SCI clearance with a favorable... 
    Cyber
    Website

    General Dynamics

    Washington DC
    3 days ago
  • $104k - $166k

     ...hire an experienced Incident Response Analyst (ICS...  ...' Federal Strategic Cyber group. Location: On‑site in Arlington,...  ...This role involves responding to cyber incidents across...  ...Ability to obtain a TS/SCI for continued employment...  .... As the world’s leading mission capability integrator... 
    Cyber
    Website
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton Corporation

    Arlington, VA
    2 days ago
  •  ...to support our nation's defense. Make an impact by...  ...skilled and multi-faceted Cyber Analyst Principal for a...  ...to report full time on site in McLean, VA. The...  ...Manager (ISSM), and Cyber Lead in ensuring the...  ...possess a current and active TS/SCI with Polygraph. ● Certifications... 
    Cyber
    Website
    Full time
    Contract work

    General Dynamics Information Technology

    McLean, VA
    more than 2 months ago
  •  ...personal impact as a Cyber Security Project...  .... Be the change, lead our change – join...  ..., analyzing, and responding to security incidents across enterprise...  ...with cyber defense teams to mitigate...  ...Clearance Level : TS/SCI with active polygraph...  ...VA - On Customer Site GDIT IS YOUR... 
    Cyber
    Website

    General Dynamics Information Technology

    McLean, VA
    more than 2 months ago
  • cFocus Software seeks a Lead Information System Security Officer (ISSO) to join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications... 
    Website
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • $101.38k - $152.06k

     ...with us. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia...  ...to Senior SOC Analysts or SOC Leads. Document and communicate incident findings...  ...locally to NTT DATA offices or client sites. This ensures we can provide timely... 
    Cyber
    Website
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA North America

    Arlington, VA
    2 days ago
  • $170k - $180k

     ...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our...  ...’s (CISA) Joint Cyber Defense Collaborative (JCDC). The...  ...to plan, share, and respond to cyber threats in real time...  ...Top Secret Clearance and SCI eligibleOn-site 3-5 days per week in Arlington... 
    Cyber
    Website
    Work at office
    3 days per week

    ECS Federal

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm is seeking a Cloud Forensics Analyst to support onsite incident response to cyber-attacks. The role involves acquiring and analyzing computer artifacts, conducting...  ...in cyber forensics and hold an active TS/SCI clearance. The position offers... 
    Cyber

    Nightwing

    Arlington, VA
    4 days ago
  • Nightwing in Arlington, VA seeks a Cyber Action Officer to support a U.S. Government client. You will manage cyber incidents, produce official reports, coordinate with stakeholders...  ...operations experience and an active TS/SCI clearance. Candidates should be able to obtain... 
    Cyber

    Nightwing

    Arlington, VA
    3 days ago
  • $90k - $130k

     ...Clearance Requirement: TS/SCI Clearance Required...  ...remediation plans; support incident response activities...  ...novel attack chains, and defensive gaps discovered during...  ...(GCIH)GIAC Industrial Cyber Security Professional...  ...) or CyberSec First Responder (CFR)Certified Information... 
    Cyber
    Website
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    11 hours ago
  • cFocus Software seeks a Chief Engineer/Lead Architect to join our program supporting the Defense Intelligence Agency (DIA). This position is on site; in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications: Active... 
    Website
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • $120k - $165k

     ...Pentagon) Clearance Required: TS/SCI minimum (US Citizen) Employment...  ...support of the Department of Defense (DoD), Intelligence Community,...  ...Analytics is seeking a Principal Cyber Systems Engineer, SME to...  ...technological superiority. You will lead the evaluation of innovative... 
    Cyber
    Website
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    3 days ago
  • $174.25k - $235.75k

     ...Possess: Top Secret SCI + Polygraph...  ...Management (KM/CM) Lead at GDIT. You’ll apply...  ...variety of sources. TS/SCI with Polygraph...  ...Location: At Customer Site – Herndon area...  ...the U.S. government, defense and intelligence community...  ...in AI, cloud, cyber and software development... 
    Cyber
    Website
    Full time
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Herndon, VA
    6 days ago
  • $174.25k - $235.75k

     ...Possess: Top Secret SCI + Polygraph...  ...Management (KM/CM) Lead at GDIT. You'll apply...  ...variety of sources. TS/SCI with Polygraph...  ...Location: At Customer Site - Herndon area...  ...the U.S. government, defense and intelligence community...  ...in AI, cloud, cyber and software development... 
    Cyber
    Website
    Full time
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Herndon, VA
    3 days ago
  • cFocus Software seeks a Lead Agile Coach/Release Train Engineer (RTE) to join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications... 
    Website
    Full time

    cFocus Software Incorporated

    Washington DC
    more than 2 months ago
  • $73.45k - $132.78k

     ...Administrator in our INTEL SECTOR- Cyber & Analytics Business Area...  ...maintenance of a company site in Alexandria.Primary...  ...systems and will respond to hardware and software incidents impacting local users. She...  ...Clearance Required: Must have TS/SCI with Polygraph.Preferred Qualifications... 
    Cyber
    Website
    Full time
    Work at office
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Alexandria, VA
    4 days ago
  •  ...Arlington, VA to support U.S. Government missions related to cyber incident response. This role demands a minimum of 12 years in systems engineering and active TS/SCI clearance. The position involves leading technology mapping and workflow development while... 
    Cyber

    Nightwing

    Arlington, VA
    16 hours ago
  •  ...advanced full-spectrum cyber, data operations, systems...  ...operations, cyber defense and resiliency, vulnerability...  ...to provide onsite incident response to civilian Government...  ...Must have an active TS/SCI clearance Must be able...  ..., mobile code, cross‑site scripting, PL/SQL and... 
    Cyber
    Website
    Contract work
    Immediate start
    Shift work
    Night shift
    Weekend work

    Nightwing

    Arlington, VA
    4 days ago
  •  ...Automated Test Engineer   –   TS/SCI   Xcelerate Solutions has...  ...is primarily conducted on-site at our client location in Bethesda...  ...Description Xcelerate is a leading defense and national security company...  ..., Digital Solutions, Cyber Security, and Strategic Consulting... 
    Cyber
    Website
    Contract work
    Remote work
    Flexible hours

    Xcelerate Solutions

    Bethesda, MD
    16 days ago
  •  ...impact as a Task Order Lead supporting customer activities...  ...a premier provider of cyber security services to...  ...includes patch, asset, incident, configuration,...  ...Security Clearance Level : TS/SCI with active polygraph...  ...McLean, VA - On Customer Site GDIT IS YOUR PLACE... 
    Cyber
    Website

    General Dynamics Information Technology

    McLean, VA
    a month ago
  •  ...evaluation, implementation, and operation of leading security Cyber defense tools and technologies and apply in-...  ...Management Framework ~ Top Secret/SCI clearance with the ability to obtain a...  ...Experience with performing site surveys, data gathering, and research... 
    Cyber
    Website
    Temporary work
    Relocation package

    ENS Solutions, LLC

    Washington DC
    more than 2 months ago
  • $125k - $150k

     ...critical services to the Department of Defense, federal agencies, and commercial...  ...candidate must have an active "TS/SCI" clearance to be considered. Location - On-Site at Fort Belvoir - This is not a...  ...Provide CI (Counterintelligence) Cyber support to a government agency at... 
    Cyber
    Website
    For contractors
    Flexible hours

    Dawson

    Alexandria, VA
    1 day ago
  • A leading digital automation company is seeking an experienced Incident Manager to gather and analyze cyber threat intelligence. Key responsibilities include identifying emerging threats...  ...minimum of 2 years' experience, active TS/SCI clearance, and strong analytical skills... 
    Cyber

    Node.Digital LLC

    Arlington, VA
    1 day ago
  • $89.6k - $204k

     ...(Entry Level to SME) TS/SCI with Poly REQUIRED...  ...foundational builder of daily cyber defenses. CGI Federal is...  ...system documentation. • Incident Support: Assist senior...  ...Framework (RMF): Lead the RMF process from system...  ...to be directed to our site that is dedicated to... 
    Cyber
    Website
    Work at office
    Local area
    Arlington, VA
    7 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Cyber Defense Incident Responder On-site - TS/SCI. Be the first to apply!