Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Defense & Incident Responder

$101.38k - $152.06k

NTT Data

Req ID: 382076

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US).

Job Summary:

The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps.

Job Duties: 

  1. Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
    1. Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).
    2. Validate alerts to reduce false positives and prioritize based on severity and potential impact.
  2. Perform initial triage and analysis of security events to determine scope, severity, and urgency.
    1. Examine log data, network telemetry, and endpoint information to identify possible malicious activity.
    2. Correlate event details with internal and external threat intelligence.
  3. Execute incident response actions in accordance with established procedures.
    1. Contain affected systems, remove malicious artifacts, and assist in system recovery.
    2. Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.
  4. Document and communicate incident findings to support resolution and improvement efforts.
    1. Prepare incident tickets, timelines, and investigative notes.
    2. Contribute to after-action reviews (AARs) and post-incident reporting.
    3. Create incident tickets
    4. Upload supporting evidence, draw sound conclusions and upload artifacts
    5. Communicate effectively, providing clear, accurate, and concise information
    6. Exercise sound analytical skills to derive correct conclusions associated with incident investigations.
  5. Maintain SOC processes, tools, and playbooks to ensure effective incident handling.
    1. Recommend refinements to SOPs and escalation procedures.
    2. Identify opportunities to streamline analysis workflows and improve detection capabilities.
  6. Participate in training, exercises, and knowledge-sharing to strengthen response readiness.
    1. Support red, blue, or purple team exercises when directed.
    2. Share lessons learned and best practices with SOC team members.
  7. Stay informed on current and emerging cyber threats relevant to the organization’s environment.
    1. Track evolving tactics, techniques, and procedures (TTPs) of threat actors.
    2. Incorporate relevant intelligence into incident analysis and response.

Basic Qualifications: 

  • Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science. 
    • Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
  • Minimum 6 years experience in Information Technology (IT) and/or Information Security (IS). 
  • DoD 8140 certification for respective area or the ability to obtain certification within six (6) months of onboarding. 
  • Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested.

Preferred Qualifications:

  • DCWF Role 511 - Cyber Defense Analyst / 531 – Cyber Defense Incident Responder advanced & intermediate certifications:
    • Cisco: CBROPS
    • CompTIA: CySA+, Cloud+, PenTest+, Security+
    • EC-Council: CEH
    • GIAC: GCFA, GCIA, GICSP, GMON, GRID, CED, GDSA, GSEC
    • ISC2: CCSP

NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this role is $101,376 - $152,064. Actual compensation will depend on a number of factors, including the candidate’s relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits. 

About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, 

NTT DATA endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at .  This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .

Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Cyber Defense & Incident Responder in Arlington, VA vacancy
  • NTT DATA seeks a Cyber Defense & Incident Responder to monitor, analyze, and respond to cybersecurity incidents in Arlington, VA. The role emphasizes incident triage, investigation, containment, and recovery to minimize impact and restore operations. Responsibilities include... 
    Cyber

    NTT DATA

    Arlington, VA
    2 days ago
  •  ...Cyber Defense & Incident Responder (SOC Analyst) 100% work on site - no remote work Secret clearance with the ability to acquire a TS Locations near the Pentagon or Mayfield VA Customer DEA Intermediate SOC Analyst 6 years with Bachelor The Cyber Defense... 
    Cyber
    Remote work

    Gormat

    Arlington, VA
    3 days ago
  • S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA. The role requires hands-on threat hunting, incident response leadership, and direct engagement with government clients operating TS/SCI and SAP networks. The ideal candidate has extensive experience... 
    Cyber

    S2i2, Inc

    Arlington, VA
    3 days ago
  • S2i2 in Arlington, VA is seeking a Lead Cyber Defense Incident Responder (Advanced) to lead a small team of senior and mid‑level analysts. This on‑site role involves hands‑on threat detection, threat intelligence research, and directing incident defense for highly secure... 
    Cyber

    S2i2 Inc

    Arlington, VA
    1 day ago
  • Responsibilities Respond to and resolve cybersecurity incidents and proactively prevent reoccurrence of these incidents Monitor the operation of systems and networks to ensure business continuity Review the latest alerts to determine relevancy and urgency Perform scans... 
    Cyber

    Jobtailor

    Arlington, VA
    5 days ago
  • $101.38k - $152.06k

     ...Cyber Defense & Incident Responder NTT DATA Services is seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US). Job Summary: The Cyber Defense & Incident Responder is responsible for monitoring, analyzing... 
    Cyber
    Temporary work
    Work at office
    Remote work
    Flexible hours

    Sierra Systems, An Ntt Data Company

    Arlington, VA
    4 days ago
  • $101.38k - $152.06k

     ...strives to hire exceptional, innovative and passionate individuals who want to grow with us. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US). Job Summary The Cyber Defense & Incident... 
    Cyber
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA North America

    Arlington, VA
    3 days ago
  • $91.1k - $170.4k

     ...Information Security (InfoSec) - InfoSec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information...  ...opportunity The Cyber & Investigative Services (CIS) Junior Incident Coordinator will exercise strong incident management... 
    Cyber
    Summer holiday
    Remote work
    Flexible hours

    EY

    Washington DC
    1 day ago
  • $175k - $180k

    Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington, VA On-site Salary Range $175,000 to $180,000 Certification Required DoD 8570 / DoD 8140 IAT Level II One of the following: Security+ CE, CCNA-Security, CySA+, GICSP,... 
    Cyber
    Weekend work

    S2i2, Inc

    Arlington, VA
    1 day ago
  •  ...States (Arlington, VA) seeks a security program professional to manage incident response, monitoring, and risk analysis for federal agencies. The role emphasizes rapid containment, proactive defense, and coordination with government and vendor teams. You will deliver CIO... 
    Cyber

    Jobtailor

    Arlington, VA
    5 days ago
  • NTT DATA North America is seeking a Cyber Defense & Incident Responder in Arlington, Virginia to monitor, analyze, and respond to cybersecurity incidents. You will triage, investigate, contain, and assist in recovery, using SIEM, EDR, and threat intelligence to determine... 
    Cyber

    NTT DATA North America

    Arlington, VA
    3 days ago
  • $170k - $180k

     ...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington, VA...  ...Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC). The JCDC is CISA’...  ...as they continue to plan, share, and respond to cyber threats in real time to support... 
    Cyber
    Work at office
    3 days per week

    ECS Federal

    Arlington, VA
    2 days ago
  •  ...Connectors is seeking a seasoned Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The...  ...hunters, ISSOs, and system owners to minimize impact and strengthen cyber defenses. U.S. #J-18808-Ljbffr Digital Global Connectors
    Cyber

    Digital Global Connectors

    Mc Lean, VA
    5 days ago
  • Cybersecurity Analyst, Incident Responder Location: Bethesda, MD (Hybrid; On-site as Required) Clearance...  ...experience responding to sophisticated cyber threats, and the ability to perform...  .... Recommend remediation and long-term defensive improvements. Digital Forensic Triage... 
    Cyber
    Full time
    Work at office

    Digital Global Connectors

    Mc Lean, VA
    1 day ago
  • $102.5k - $188.9k

    Position Summary Our Deloitte Cyber team understands the unique...  ...who can identify, analyze, and respond to exploitation activity before...  ..., you will support cyber defense efforts by analyzing threat activity, investigating incidents, assessing vulnerabilities, and... 
    Cyber
    Work at office

    Deloitte

    Rosslyn, VA
    1 day ago
  • $57.2k - $109.4k

     ...ingenuity for clients across defense, national security, public safety...  ...The Work The Cybersecurity Incident Response Junior Analyst and...  ...response lifecycles, common cyber‑attacks, and federal incident...  ...responsibilities: Actively monitor and respond to cybersecurity incidents... 
    Cyber
    Work experience placement
    Live in
    Work at office
    Local area
    Shift work

    Accenture Federal Services

    Arlington, VA
    5 days ago
  • $104k - $166k

    Peraton is seeking a Cyber Incident Response Analyst in Arlington, VA. This role involves responding to cybersecurity incidents across industrial control systems and critical infrastructure. The ideal candidate will leverage their expertise to provide actionable recommendations... 
    Cyber

    Peraton

    Arlington, VA
    4 days ago
  • General Dynamics Information Technology in Arlington, VA seeks an experienced Incident Responder to perform hands-on cyber incident response across critical infrastructure and government partners. You will handle high‑value intrusions, drive containment and eradication... 
    Cyber
    Remote work

    General Dynamics Information Technology

    Arlington, VA
    4 days ago
  • $107.9k - $195.05k

    Incident ResponderLocation: Suitland, MDClearance: Active TS/SCILeidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence...  ...maritime intelligence networks against cyber threats. You will respond to and... 
    Cyber
    Full time
    Work at office

    Leidos

    Suitland, MD
    17 hours ago
  • Omniscius Consulting is seeking an experienced security professional in Washington, DC to lead incident response, triage threats, and coordinate containment and recovery. The role includes tuning SIEM dashboards, generating detailed findings, and documenting security posture... 
    Cyber

    Omniscius Consulting

    Washington DC
    3 days ago
  • GDIT is seeking an Incident Responder to provide hands-on cyber incident response across critical infrastructure and government agencies. The role supports on-site and remote deployments, surging during high-tempo events, with responsibilities spanning containment, eradication... 
    Cyber
    Remote work

    Socket.dev

    Arlington, VA
    1 day ago
  •  ...Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You will assess...  ...capabilities, identify operational risks and process gaps, support incident-response, and translate complex cyber information into... 
    Cyber

    OPS TECH ALLIANCE LLC

    Mc Lean, VA
    4 days ago
  • True Zero Technologies in Washington, DC is seeking a seasoned cybersecurity professional to lead incident response efforts as part of our commitment to quality outcomes. You will manage reports, conduct forensic investigations, and support compliance. The ideal candidate... 
    Cyber

    Truezerotech

    Washington DC
    4 days ago
  • Position Summary The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment... 
    Cyber
    Local area
    Remote work

    General Dynamics Information Technology

    Arlington, VA
    4 days ago
  • bcmcllc is seeking a Cloud Solutions Architect to design and optimize secure cloud-based engagement kits for cyber incident response. You will be responsible for creating scalable, high-performance solutions that enable rapid deployment across diverse mission scenarios... 
    Cyber

    bcmcllc

    Arlington, VA
    5 days ago
  •  ...Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder...  ...to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise, strong... 
    Cyber
    Contract work
    Flexible hours

    Evolver

    Washington DC
    2 days ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...S. Government customer to provide onsite incident response to civilian Government agencies... 
    Cyber
    Contract work
    Immediate start
    Shift work
    Night shift
    Weekend work

    Nightwing

    Arlington, VA
    5 days ago
  • $86.4k

     ...is the top investigator in the Cyber Fusion Center, capable of working any kind of incident, leading investigations, and ensuring...  .... The Senior Cyber Incident Responder interfaces with other internal...  ...to enterprise-wide cyber defense technicians to resolve cyber defense... 
    Cyber
    For contractors
    Work at office
    Local area
    Remote work

    Highmark Health

    Washington DC
    4 days ago
  •  ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and...  ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat... 
    Cyber
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    1 day ago
  • A leading cybersecurity firm in Virginia is seeking a Cyber Eviction Lead to enhance incident response capabilities. The ideal candidate will have a strong background in cyber defense, experience in responding to complex incidents, and relevant certifications. Responsibilities... 
    Cyber

    Nightwing

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Defense & Incident Responder. Be the first to apply!