Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Defense Incident Responder (Advanced)

Chenega Corporation

Req ID: 40973

Summary

Cyber Defense Incident Responder (Advanced)

Arlington, VA

Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employers core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!

The Cyber Defense Incident Responder (Advanced) position requires a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detections. The ideal candidate will have extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.

Responsibilities

  • Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.

  • Serve as the primary technical point of contact for complex threat hunting issues, and mentor new ID team members to grow their skills and operational abilities.

  • Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.

  • Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict classified network protocols.

  • Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.

  • Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.

  • Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.

  • Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.

  • Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).

  • Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence.

  • Other duties as assigned

Qualifications

  • High school diploma or GED equivalent required

  • Bachelors degree in computer science, Digital Forensics, or related major with an emphasis on Security preferred

  • 6+ years experience in Threat Hunting, Security Research, or Incident Response

  • Demonstrated leadership skills, preferably in a formal leadership role

  • Scripting experience

  • IAT Level II Certification required

  • TS/SCI clearance required

Preferred Qualifications:

  • Successfully pass background and drug screening

Knowledge, Skills, and Abilities:

  • Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.

  • Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.

  • Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.

  • Government/Client Service Experience: Extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.

  • Security Engineering & Architecture: Knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.

  • Adversary Emulation: Skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).

  • Technical Mentorship: Experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.

  • Advanced Forensics: Deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.

  • Malware & Script Analysis: High-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.

  • Superior Research Capabilities: Exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.

  • Executive Communication: Excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership.

  • Technical Translation: Ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers.

  • Project & Case Management: Proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.

  • Crisis Management: Ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.

  • Collaboration: Well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.

  • Attention to Detail: Excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks.

How youll grow

At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe theres always room to learn.

We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.

Benefits

At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.

Learn more about what working at Chenega MIOS can mean for you.

Chenega MIOSs culture

Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.

Corporate citizenship

Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.

Learn more about Chenegas impact on the world.

Chenega MIOS News-

Tips from your Talent Acquisition Team

We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:

Chenega MIOS web site -

Glassdoor -

LinkedIn -

Facebook -

Chenega Corporation and family of companies is an EOE.

Equal Opportunity Employer/Veterans/Disabled

Native preference under PL 93-638.

We participate in the E-Verify Employment Verification Program

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Defense Incident Responder (Advanced) in Arlington, VA vacancy
  •  ...Summary The Cyber Defense Incident Responder (Advanced) performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence... 
    Cyber
    Work at office
    Weekend work

    S2i2 Inc

    Arlington, VA
    1 day ago
  • $65k - $74.1k

    A leading consulting firm in Washington DC is looking for an experienced Cyber Defense Incident Handler. You will respond to incidents, support detection and analysis of cyber threats, and maintain knowledge of security protocols. Candidates should have a bachelor's degree... 
    Cyber

    Maximus

    Washington DC
    3 days ago
  • $99k - $225k

     ...Analyst, you’re in the middle of the action, responding to and mitigating threats in real time. You’re the first line of cyber defense for our organization and your guidance on...  ...Respond to and resolve cybersecurity incidents and proactively prevent recurrence. Monitor... 
    Cyber
    Local area

    Booz Allen Hamilton

    Arlington, VA
    4 days ago
  •  ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure the safety of information systems assets and to protect...  ...environment or enclave.\Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs)... 
    Cyber
    Shift work

    IC-CAP, LLC

    Washington DC
    3 days ago
  •  ...Everforth ECS is seeking a Mid. Cyber Incident Coordinator to work out of...  ...Agency's (CISA) Joint Cyber Defense Collaborative (JCDC). The...  ...to plan, share, and respond to cyber threats in real time...  ...processes, and procedures for advancing Threat Hunting and Incident... 
    Cyber
    Work at office
    3 days per week

    ECS Limited

    Arlington, VA
    3 days ago
  •  ...STI provides critical, advanced technical support to the DHS Hunt and Incident Response Team (HIRT). We...  ...act as the front-line defense for Government agencies...  ...Position Summary As a  Cyber Eviction Analyst (SME)...  ...Analyst/CSSP Incident Responder DoD 8140.01 CEH,... 
    Cyber

    Solutions Technology, Inc / STI Health & Wellness

    Arlington, VA
    1 day ago
  • cFocus Software seeks a n Incident Responder to support the Administrative Offices of the United...  ...the U.S. Courts (AOUSC) by delivering advanced cybersecurity incident response and threat...  ..., and mitigating sophisticated cyber threats while strengthening detection capabilities... 
    Cyber
    Work at office
    Remote work

    cFocus Software Incorporated

    Washington DC
    3 days ago
  •  ...Everforth ECS is seeking a Senior Cyber Incident Analyst to work in our...  ...Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC). The JCDC...  ...to plan, share, and respond to cyber threats in real time...  ...implement technical solutions to advance Threat Hunting, Incident Management... 
    Cyber
    Work at office
    Local area
    3 days per week

    ECS

    Arlington, VA
    3 days ago
  • A cybersecurity services provider is seeking an Incident Responder to support the Administrative Offices of the United States Courts in Washington, DC. This role involves incident response and threat hunting, requiring a minimum of 5 years of experience across cloud and... 
    Cyber

    cFocus Software Incorporated

    Washington DC
    3 days ago
  • $65k

     ...Band 4 Job-Specific Essential Duties and Responsibilities: Respond to cyber incidents, including handling SOC IR phone calls and emails from...  ...Bachelor's degree with 1-3 years of experience in cyber defense incident handling (or equivalent experience). 1+ years of... 
    Cyber

    Maximus

    Washington DC
    3 days ago
  •  ...Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research...  ...customer to provide support for onsite incident response to civilian Government... 
    Cyber
    Contract work
    Immediate start
    Shift work

    Nightwing

    Arlington, VA
    4 days ago
  •  ...Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research...  ...customer to provide support for onsite incident response to civilian Government... 
    Cyber
    Contract work
    Immediate start
    Shift work
    Night shift
    Weekend work

    Nightwing

    Arlington, VA
    5 days ago
  • $116.9k - $243.1k

     ...technology and ingenuity for clients across defense, national security, public safety,...  ...manage 24x7x365 front‑line defense against cyber incidents. You will oversee the full lifecycle of...  ...Lead CIRT operations in advanced incident response Manage all SOC investigations... 
    Cyber
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    1 day ago
  •  ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement...  ...resilience against evolving cyber threats. This position requires deep technical...  ...recovery. Direct investigations of advanced threats, including APTs, ransomware,... 
    Cyber
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    1 day ago
  •  ...years of experience or equivalent qualifications. Responsibilities include applying Risk Management Framework principles and managing incident responses. The role anticipates some remote work and offers opportunities contingent upon contract award. #J-18808-Ljbffr Saic
    Cyber
    Remote job
    Contract work

    Saic

    Arlington, VA
    4 days ago
  • A leading defense contractor is seeking an experienced Senior Manager Program Manager to oversee the Advanced Programs team. The candidate will lead cross-functional teams in developing...  ...Research and Development, embedded cyber security, and RF technologies. The position... 
    Cyber
    Contract work
    For contractors
    Flexible hours

    Lockheed Martin

    Arlington, VA
    2 days ago
  • SOS International LLC in Washington, DC is seeking a Security Analyst - Forensics/Malware Analysis to support cyber defense and incident response activities. The ideal candidate will have five years of security-related experience, a Bachelor's Degree, and relevant cybersecurity... 
    Cyber
    Full time
    Afternoon shift

    SOS International LLC

    Washington DC
    2 days ago
  • A technology solutions company in Arlington, VA, is seeking a Cyber Network Defense Analyst to provide front-line response for digital forensics and incident response. The candidate will monitor network activity, analyze for evidence of suspicious behavior, and develop... 
    Cyber

    ARSIEM

    Arlington, VA
    3 days ago
  • · Supporting the management of cyber incidents through the incident response lifecycle. · Creating and maintaining routine reporting of cyber...  ...hardening, cyber hygiene techniques, and cybersecurity defense policies, procedures, and regulations. Required Skills: · Must... 
    Cyber

    Base One Technologies

    Arlington, VA
    5 days ago
  •  ...identify, protect, detect, respond to, and recover from cyberattacks...  ...solutions that improve cyber defense of critical assets and systems...  ...sharing of threats and incidents, through established networks...  ...provide equal employment and advancement opportunities to all individuals... 
    Cyber

    Marathon TS

    Washington DC
    2 days ago
  •  ...Cyber Network Defense Analysts (CNDA) Our Partner provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution...  ...CSSP Analyst/CSSP Incident Responder, CEH SANS GIAC GNFA preferred... 
    Cyber
    Immediate start
    Remote work

    NewGen Technologies (Maryland)

    Arlington, VA
    2 days ago
  •  ...a leader in delivering advanced analytic, data engineering...  ...of the Department of Defense (DoD), Intelligence...  ...highly skilled Senior Cyber Threat Analyst to join...  ...electronic infrastructure. Respond to computer security breaches, malware incidents, and other... 
    Cyber
    Full time
    Local area

    Praescient Analytics

    Arlington, VA
    2 days ago
  •  ...Incident Response Expert III (Cyber Eviction Analysts) The DHS's Hunt and Incident...  ...Argo Cyber provides HIRT advanced technical assistance, proactive...  ...of Computer Network Defense policies, procedures and...  ...CSSP Analyst/CSSP Incident Responder - DoD 8140.01 CEH, CSSP... 
    Cyber
    Local area
    Immediate start

    Argo Cyber Systems

    Arlington, VA
    5 days ago
  •  ...Nightwing provides technically advanced full-spectrum cyber, data operations, systems...  ...space operations, cyber defense and resiliency,...  ...markets. The DHS's Hunt and Incident Response Team (HIRT) secures...  ...CSSP Analyst/CSSP Incident Responder DoD 8140.01 CEH, CSSP Analyst... 
    Cyber
    Immediate start

    Nightwing

    Arlington, VA
    a month ago
  •  ...Cyber Network Defense Analysts (CNDA) Our partner provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution...  ...exfiltration Investigate and respond to incidents and attacks... 
    Cyber
    Immediate start
    Remote work

    NewGen Technologies (Maryland)

    Arlington, VA
    2 days ago
  •  ...Nightwing provides technically advanced full-spectrum cyber, data operations, systems...  ...space operations, cyber defense and resiliency,...  ...provide support for onsite incident response to civilian Government...  ...CSSP Analyst/CSSP Incident Responder - DoD 8140.01 CEH, CSSP... 
    Cyber
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    2 days ago
  • $227k

     ...network segments from advanced threats. Administer...  ...packet data to detect and respond to threats. Support...  ...Performing threat analysis, incident response, or...  ...to a deep knowledge of Defense and Civilian missions to...  ...Details Job Family IT, Cyber Security, Network Systems... 
    Cyber
    Local area
    Remote work
    Flexible hours

    Koniag Government Services

    Washington DC
    4 days ago
  • $128.1k - $239.6k

     ...Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and...  ...opportunity The Active Defense team is responsible for four...  ..., intrusion analysis, incident response, malware analysis...  ...Enabled by data, AI and advanced technology, EY teams help... 
    Cyber
    Summer holiday
    Local area
    Remote work
    Flexible hours
    Night shift
    Weekend work

    EY

    Washington DC
    5 days ago
  •  ...supporting mission-critical defense and intelligence...  ...application dependencies. Respond to and resolve critical network incidents within designated...  ...years of experience in cyber operations, cybersecurity...  ...SAFe Agile framework. Advanced Proficiency With: Network... 
    Cyber
    Full time
    Local area

    CGI

    Washington DC
    4 days ago
  •  ...infrastructure. May respond to cybersecurity incidents, ensuring appropriate controls...  ...Perform Cybersecurity Defense Analysis. Conduct Incident...  ...Analysis. Conduct Cyber Investigations. Knowledge...  ...integrator focused on advancing the power of technology and... 
    Cyber
    Contract work
    Summer work
    Remote work

    Science Applications International Corporation

    Arlington, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Defense Incident Responder (Advanced). Be the first to apply!