Cyber Defense & Incident Responder
$101.38k - $152.06kNTT Data
Req ID: 382076
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US).
Job Summary:
The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps.
Job Duties:
- Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
- Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).
- Validate alerts to reduce false positives and prioritize based on severity and potential impact.
- Perform initial triage and analysis of security events to determine scope, severity, and urgency.
- Examine log data, network telemetry, and endpoint information to identify possible malicious activity.
- Correlate event details with internal and external threat intelligence.
- Execute incident response actions in accordance with established procedures.
- Contain affected systems, remove malicious artifacts, and assist in system recovery.
- Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.
- Document and communicate incident findings to support resolution and improvement efforts.
- Prepare incident tickets, timelines, and investigative notes.
- Contribute to after-action reviews (AARs) and post-incident reporting.
- Create incident tickets
- Upload supporting evidence, draw sound conclusions and upload artifacts
- Communicate effectively, providing clear, accurate, and concise information
- Exercise sound analytical skills to derive correct conclusions associated with incident investigations.
- Maintain SOC processes, tools, and playbooks to ensure effective incident handling.
- Recommend refinements to SOPs and escalation procedures.
- Identify opportunities to streamline analysis workflows and improve detection capabilities.
- Participate in training, exercises, and knowledge-sharing to strengthen response readiness.
- Support red, blue, or purple team exercises when directed.
- Share lessons learned and best practices with SOC team members.
- Stay informed on current and emerging cyber threats relevant to the organization’s environment.
- Track evolving tactics, techniques, and procedures (TTPs) of threat actors.
- Incorporate relevant intelligence into incident analysis and response.
Basic Qualifications:
- Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science.
- Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
- Minimum 6 years experience in Information Technology (IT) and/or Information Security (IS).
- DoD 8140 certification for respective area or the ability to obtain certification within six (6) months of onboarding.
- Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested.
Preferred Qualifications:
- DCWF Role 511 - Cyber Defense Analyst / 531 – Cyber Defense Incident Responder advanced & intermediate certifications:
- Cisco: CBROPS
- CompTIA: CySA+, Cloud+, PenTest+, Security+
- EC-Council: CEH
- GIAC: GCFA, GCIA, GICSP, GMON, GRID, CED, GDSA, GSEC
- ISC2: CCSP
NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this role is $101,376 - $152,064. Actual compensation will depend on a number of factors, including the candidate’s relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.
About NTT DATA
NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form,
NTT DATA endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .
- ...Pentagon or Mayfield VA ~ Customer DEA ~ Intermediate SOC Analyst ~6 years with Bachelor Position Summary The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to cybersecurity incidents in accordance with established...CyberRemote work
$175k - $180k
...Job Description Job Description Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington, VA On-site Salary Range $175,000 to $180,000 Certification Required DoD 8570 / DoD 8140 IAT Level II...CyberWeekend work$60k - $100k
...should have a minimum of 4 years in cybersecurity operations and a bachelor's degree in a related field. The role involves leading incident response efforts, documenting actions, and collaborating with technical teams to enhance security across multiple environments....Cyber$120k - $170k
...Job Description Job Description Overview We are seeking a Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst to support our Prime Contract with the Defense Threat Reduction Agency at Fort Belvoir. This position requires an active Top-Secret Clearance...CyberFull timeContract workTemporary workWork at officeLocal areaShift workWeekend workAfternoon shift- ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and... ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat...CyberContract workFor contractorsWork at officeLocal area
- ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client.... ...improvement to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,...CyberContract workFlexible hours
- ...intersect. Our single focus has been delivering cyber solutions to effectively manage risk &... ...for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in... ...will help monitor, detect, investigate, and respond to cybersecurity threats affecting a large...Cyber
- ...dedicated to supporting mission‑critical defense and intelligence initiatives. We... ..., and application dependencies. Respond to and resolve critical network incidents within designated resolution... ...Minimum of 4 years of experience in cyber operations, cybersecurity, or a related...CyberPermanent employmentFull timeLocal area
- ...Description Job Description Title: Incident Manager III Description: Solutions... ...and critical asset owners who experience cyber-attacks, providing immediate investigation... ...in reported incidents Recommending defense in depth principles and practices (i.e.,...CyberFor contractorsImmediate startShift work
$100k - $126.5k
...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic... ...counsel in independently responding to allegations of fraud,... ...horses, choosing appropriate defenses and response tactics for each... ...to clients on the adequacy of cyber security controls in accordance...CyberWork at officeWork from home3 days per week- ...Description Job Description Title: Incident Manager III Description: Solutions... ...and critical asset owners who experience cyber-attacks, providing immediate investigation... ...hygiene techniques, and cybersecurity defense policies, procedures, and regulations...CyberFor contractorsImmediate start
$110k - $130k
...customers across the Department of Defense and Intelligence Community.... ...advanced engineering, cyber, and intelligence solutions that... ...implement solutions associated with incident tickets and requirements.... ...Center (ITOC) personnel. Respond to after-hours outages when deemed...CyberFull timeContract workRemote workAfternoon shift$155k - $180k
...About Agile Defense At Agile Defense we know that action defines the outcome and... .... Requisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA... ...Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an...CyberWork experience placement$130k - $152.5k
...them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct... ...breach detection, threat analysis, incident response and malware analysis;... ...guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity...CyberWork at officeLocal areaWork from home3 days per week- ...technically advanced full-spectrum cyber, data operations, systems... ...space operations, cyber defense and resiliency, vulnerability... ...based engagement kits for cyber incident response and threat hunting operations... ...and using the lab and responds to users’ needs in a timely...CyberContract workLocal area
$125k - $150k
...bridge the gap between Department of Defense and Federal Government acquisition programs... ...are seeking an experienced Senior Cyber Security Engineer (CSE3) to support... ...vulnerability assessments, and respond to security incidents. This role combines IT expertise with...CyberContract workTemporary workFor contractorsFor subcontractorWork at officeLocal areaRemote workFlexible hours- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous... ...customer to provide support for onsite incident response to civilian Government agencies...CyberContract workImmediate start
- ...technically advanced full-spectrum cyber, data operations, systems... ...space operations, cyber defense and resiliency, vulnerability... ...based engagement kits for cyber incident response and threat hunting operations... ...monitoring solutions* Respond to service outages and...CyberContract workLocal area
- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous... ...customer to provide support for onsite incident response to civilian Government agencies...CyberContract workLocal areaImmediate start
- ...States CHAOS Industries is redefining modern defense with a multi‑product portfolio that gives... ...defend the organization against evolving cyber threats. This role will support day‑to‑... ...& Qualifications Security Monitoring & Incident Response Monitor and triage security alerts...Cyber
- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous... ...customer to provide support for onsite incident response to civilian Government agencies...CyberContract workImmediate start
- Job Overview A law firm seeks a Cyber Incident Response Associate Attorney in Washington, DC. This role involves managing cybersecurity incidents... ...notices of data breaches to individuals and regulators. Respond to regulatory investigations arising from data breaches....CyberFlexible hours
- Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships...CyberWork at officeRemote work
$135k - $143k
...Cybersecurity Analyst leads in the proactive defense of the organization's information systems... ...operations, risk mitigation, incident response, and security architecture, ensuring... ...including SIEM, ZTS, EDR, IDS/IPS, and other cyber management platforms, optimizing their effectiveness...CyberFull timeContract workCasual workRemote workFlexible hours- ...technology and services integrators in the defense and government services industry. We... ...Experience : 10+ years managing enterprise IT/cyber programs, including SOC operations; DHS... ...certification related to security and/or incident response (e.g., Certified Ethical Hacker...CyberFull timeContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous... ...customer to provide support for onsite incident response to civilian Government agencies...CyberContract work
- ...the Cybersecurity & Technology Controls Incident Management & Response team, you will serve... ...mitigate impacts. Act as the frontline defense for cybersecurity incidents, ensuring... ...operating systems, network fundamentals, cyber tools, and cloud architecture. High-level...Cyber
- ...United States (U.S.) Army C5ISR Center to develop advances within cyber defense research; advanced detection methods; sensor structure, data... .... Review information, documentation, and reporting of incidents and events from other CSSP teams, as well as third parties, and...Cyber
- ...Location: On-Site in Arlington, VA Department: Cyber Security Services Reports To: Management... ..., providing services to military, defense, and critical infrastructure industries.... ...measures and procedures, including reporting incidents to the AO and appropriate reporting...CyberFull timeWork at officeLocal area
- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous... ...S. Government customer to provide onsite incident response to civilian Government agencies...CyberContract workImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Defense & Incident Responder. Be the first to apply!
- cyber Arlington, VA
- cyber forensics Arlington, VA
- missile defense Arlington, VA
- insurance defense paralegal Arlington, VA
- insurance defense Arlington, VA
- defense contract Arlington, VA
- insurance defense attorney Arlington, VA
- defense logistics Arlington, VA
- criminal defense Arlington, VA
- defense Arlington, VA




