Incident Response Team Lead
$155k - $180kAgile Defense
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests.
Requisition #: 1435
Job Title: Incident Response Team Lead
Location: Reston, VA
Clearance Level: TS (SCI Eligible)
Active Certified Information System Security Professional (CISSP)
SUMMARY
Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers. To support this vital mission, Agile Defense staff are on the forefront of providing Advanced CSOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. To ensure the integrity, security and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, technical analysis and incident response lifecycle. A strong work ethic, diligent time and attendance, written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.
JOB DUTIES AND RESPONSIBILITIES
Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions. Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation. Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.
QUALIFICATIONS Required Certifications
Certified Information System Security Professional (CISSP) and
One or more of the following certifications:
GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or
Other Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1.
Education, Background, and Years of Experience
Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security (or eight (8) years of relevant work experience in lieu of a degree).
ADDITIONAL SKILLS & QUALIFICATIONS
Required Skills
Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle.
Candidates must also exhibit proficient use of cyber tools, including but not limited to Security Information and Event Management (SIEM), network analysis, live response, endpoint detection and response tools, Intrusion Prevention / Detections Systems (IPS / IDS) and CSOC ticketing platforms.
Preferred Skills
One or more of the following GFCA, GPEN, GREM, GFNA, GIAC
Familiarity with Cloud environments
WORKING CONDITIONS
Environmental Conditions
Hybrid onsite in Reston, VA
Strength Demands
Physical Requirements $155,000 - $180,000 a year Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests.
Requisition #: 1435
Job Title: Incident Response Team Lead
Location: Reston, VA
Clearance Level: TS (SCI Eligible)
Active Certified Information System Security Professional (CISSP)
SUMMARY
Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers. To support this vital mission, Agile Defense staff are on the forefront of providing Advanced CSOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. To ensure the integrity, security and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, technical analysis and incident response lifecycle. A strong work ethic, diligent time and attendance, written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.
JOB DUTIES AND RESPONSIBILITIES
Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions. Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation. Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.
QUALIFICATIONS Required Certifications
Certified Information System Security Professional (CISSP) and
One or more of the following certifications:
GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or
Other Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1.
Education, Background, and Years of Experience
Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security (or eight (8) years of relevant work experience in lieu of a degree).
ADDITIONAL SKILLS & QUALIFICATIONS
Required Skills
Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle.
Candidates must also exhibit proficient use of cyber tools, including but not limited to Security Information and Event Management (SIEM), network analysis, live response, endpoint detection and response tools, Intrusion Prevention / Detections Systems (IPS / IDS) and CSOC ticketing platforms.
Preferred Skills
One or more of the following GFCA, GPEN, GREM, GFNA, GIAC
Familiarity with Cloud environments
WORKING CONDITIONS
Environmental Conditions
Hybrid onsite in Reston, VA
Strength Demands
Physical Requirements $155,000 - $180,000 a year Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Incident Response Team Lead in Reston, VA vacancy
- ...and securing critical operations across the globe, keeping our country safe and secure. Job Description Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls Church, VA Clearance: Active SECRET (must be maintained) At GDIT, we are...SuggestedFull timeContract workWork experience placementShift work
- ...Agile Defense, LLC is seeking an experienced Cyber Incident Response Team Lead to support a 24/7/365 CSOC program. The role leads investigations, forensic analyses (host, cloud, network) and develops countermeasures to protect critical assets across USG customers. The...Suggested
- ...IT Operations Manager. The role involves overseeing computer systems and networks, planning technological operations, and leading incident response efforts. Ideal candidates will have over ten years of senior-level networking experience and the capability to manage complex...Suggested
$186.64k - $292.69k
...guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms... ...partners. As the Director, Security Operations and Incident Response, you will lead the enterprise cyber defense function responsible for detecting...SuggestedFull timeWork at officeRemote workWorldwideNight shift- ...our exciting organization, please visit us at are seeking a Cybersecurity Incident and Application Lead to join our team and support our client. The ideal candidate is a strong incident response and application security professional who remains calm under pressure and...SuggestedTemporary workFor contractorsWork experience placementWork at officeRemote work2 days per week
- ...MANTECH seeks a motivated, career and customer-oriented Incident Technician Lead to join our team in Chantilly, VA . In this role, you will lead a team of Enterprise IT Support Technicians responsible for overseeing, managing and coordinating the resolution of IT...Temporary workFor contractorsWork at officeLocal areaFlexible hours
$95k - $145k
...Services - CWS /Full-time /HybridCWS seeks an Incident Support Manager to direct incident... ...incident management operations, ensuring timely response and resolution of network disruptions... ...restoration efforts.Coordinate response teams during major outages or critical events.Ensure...Full timeContract workLocal areaNight shift$155k - $220k
...Responsibilities & Qualifications We are seeking an Incident Support Manager to join our team supporting a national law enforcement agency NOC. This team provides support services for Network(s) Management, Operations, and Maintenance for all Network(s) infrastructure...Full timeContract workTemporary workWork at officeLocal areaRemote workMonday to FridayShift workNight shiftDay shift$16 per hour
...Team Lead At Sky Zone, our mission is to enrich lives through the power of boundless... ...Food & Beverage/Facilities gaining real responsibility, leadership experience, and the skills... ...Enforce all safety policies and complete incident reports when necessary. Ensure all...Full timePart timeWork at officeAll shiftsFlexible hoursShift workWeekend workAfternoon shift- A leading technology company in Fairfax, Virginia seeks a Support Lead (SRE) to oversee support operations and enhance system reliability. You will manage a team of engineers, optimize performance, and implement automation tools. Ideal candidates should have a strong background...
- ...databases, and other technologies. Responsibilities Contributes to the planning... ...'s concepts and principles. Leads and directs the work of other... ...may be provided through a team of subordinate supervisors... ..., monitor, and report on the incident remediation efforts. Responsible...Contract workFor contractorsRemote work
$23 - $26 per hour
...supervisor of Security Officers, Lead Officers, and other company... ...to outline tasks and responsibilities. ~ Meets with client representatives... ...Ability to be an effective team member. Ability to... ...clients, observe and report incidents, and direct others. Frequent...Local areaFlexible hoursShift workNight shiftAfternoon shift$99k - $134k
...environment with competitive benefits and the ability to grow your career.The Technical Support Team Lead works to ensure timely, effective support to customers. They are primarily responsible for the tactical management of contact center queues and cases, working to ensure...Work at officeMonday to FridayFlexible hoursNight shiftWeekend work- DescriptionWe are seeking a new Supervisory Team Lead - Recruiting! This position is responsible for leading a team of recruiters while implementing talent acquisition programs that drive recruiting effectiveness across Tyler. This role leverages industry expertise, operating...
$40 - $45 per hour
...environment. The Desktop Support Manager will lead a team of approximately 8-10 desktop... ...performing many of the same technical responsibilities as their team while providing leadership... ...technologies, participating in major incident response, maintaining desktop standards...Full timeContract workTemporary workLocal area- ...Full-Time Ground Infrastructure Lead An aerospace client is... ...mobility will be available to the responsible individual, including... ...closely with the engineering team and product teams to incorporate... ...configuration management, on-call/incident processes, and continuous...Full timeRemote work
- ...Job Description Job Description Remarketing Team Lead We are PEAC Solutions—large enough to finance the globe, yet small enough... ...next chapter could start here. The Remarketing Team Lead is responsible for leading the day-to-day operations of the Remarketing team...Temporary workWork at officeLocal areaFlexible hours
- ...Description Overview ***** This position is contingent upon contract award ***** SOSi is seeking a Team Lead to support a 24/7/365 program, who will be responsible for managing day-to-day shift. The Team Lead will play a key role in ensuring smooth workflow by...Full timeContract workSecond jobWorldwideShift workNight shiftDay shift
- ...Customer Support Lead Leads enterprise IT support operations... ...service desk operations, incident and request management, and user... ...and satisfaction. Key Responsibilities Lead daily operations... ...service desk and end-user support teams. Oversee incident, problem...Contract workWork at office
$75.2k - $158.1k
...Proposal Compliance Specialist & Color Team Review LeadJob Category: Business Development... ...Specialist & Color Team Review Lead supports Proposal Operations by leading... ...teams through compliance audits and reviews.Responsibilities:• Lead Compliance Reviews across proposals...Contract workWork experience placementLocal areaFlexible hours- ...Reference26-11969Position Title: Lead Executive Technology... ...collaboration, and hybrid engagement. Responsibilities:Executive Technology... ...executive trust at all times Team Operations & Service Excellence... ...excellence and accountability• Lead incident response for executive-...Permanent employmentContract workLive inWork at office
- ...Service Desk Lead ID 2025-3177 Job Locations... ...across Tier 1 and Tier 2 support teams, driving service quality, SLA... ...The Service Desk Lead is responsible for workforce scheduling, queue... ...customer satisfaction metrics, incident trend analysis, and continuous...Full timeFor contractorsLocal areaRemote workShift work
- ...Job Description Come join our team! At Unlimited Technology, we... ...and networks of the world's leading brands and critical infrastructure... ...Lead Security Technician- Responsible for managing all aspects of... ...driving record and report any incidents or near misses to management...Full timeFor contractorsFor subcontractorLocal areaImmediate start
$140k
...Job Description Analyst1 is an industry-leading cybersecurity solution provider that... ...Support Engineering, you will lead the team responsible for ensuring Analyst1 is operational in... ...integrations. Past performance in SOC, CTI, Incident Response, or other related cyber...Civilian ContractorFull timeRemote workFlexible hours- ...Senior Agent, Global EUC in McLean, Virginia. This role involves support for business services and applications at SES, handling incidents, and creating knowledge articles. The ideal candidate will possess strong problem-solving skills, an Associate's Degree or relevant...
- ...Position Overview The Customer Experience Coordinator is responsible for managing escalated customer concerns received through Spotless... ...~ Perform other duties as assigned to support the team and the needs of the business Education and Experience...Full timePart timeWork at officeLocal area
$120.8k - $265.8k
...Application Support Manager to lead enterprise-wide technical... ...manage distributed technical teams delivering mission-critical services... ...operations worldwide.Responsibilities: Provide strategic leadership... ...comprehensive monitoring, alerting, and incident response procedures to ensure...Permanent employmentContract workWork experience placementImmediate startWorldwideOverseasFlexible hours- ...Retail Customer Service Lead (Key Holder) PetSmart does Anything for Pets – JOIN OUR TEAM! Our associates are the heart of Team PetSmart. Together, we're... ...achieving targeted results. This role has shared responsibility for the oversight of the safety of people and...Hourly payWeekly payMinimum wageFull timeLocal areaImmediate startWeekend workAfternoon shift
- ...cyber professional to join our team and support our mission... ...vulnerability management, detection and response support services.... ...mentoring to junior team members. Leading cybersecurity oversight,... ...intelligence, event analysis, and incident response. Organizing and...Temporary workImmediate startShift work
- ...where each child can thrive. By encouraging responsibility, problem-solving, and age-appropriate... ...accurate attendance, daily reports, incident reports, and classroom documentation using... ...Positive attitude, flexibility, and a team-player mindset with a willingness to jump...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Team Lead. Be the first to apply!
Related searches



