Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Defense & Incident Responder

$101.38k - $152.06k

NTT Data

Req ID: 382076

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US).

Job Summary:

The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps.

Job Duties: 

  1. Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
    1. Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).
    2. Validate alerts to reduce false positives and prioritize based on severity and potential impact.
  2. Perform initial triage and analysis of security events to determine scope, severity, and urgency.
    1. Examine log data, network telemetry, and endpoint information to identify possible malicious activity.
    2. Correlate event details with internal and external threat intelligence.
  3. Execute incident response actions in accordance with established procedures.
    1. Contain affected systems, remove malicious artifacts, and assist in system recovery.
    2. Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.
  4. Document and communicate incident findings to support resolution and improvement efforts.
    1. Prepare incident tickets, timelines, and investigative notes.
    2. Contribute to after-action reviews (AARs) and post-incident reporting.
    3. Create incident tickets
    4. Upload supporting evidence, draw sound conclusions and upload artifacts
    5. Communicate effectively, providing clear, accurate, and concise information
    6. Exercise sound analytical skills to derive correct conclusions associated with incident investigations.
  5. Maintain SOC processes, tools, and playbooks to ensure effective incident handling.
    1. Recommend refinements to SOPs and escalation procedures.
    2. Identify opportunities to streamline analysis workflows and improve detection capabilities.
  6. Participate in training, exercises, and knowledge-sharing to strengthen response readiness.
    1. Support red, blue, or purple team exercises when directed.
    2. Share lessons learned and best practices with SOC team members.
  7. Stay informed on current and emerging cyber threats relevant to the organization’s environment.
    1. Track evolving tactics, techniques, and procedures (TTPs) of threat actors.
    2. Incorporate relevant intelligence into incident analysis and response.

Basic Qualifications: 

  • Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science. 
    • Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
  • Minimum 6 years experience in Information Technology (IT) and/or Information Security (IS). 
  • DoD 8140 certification for respective area or the ability to obtain certification within six (6) months of onboarding. 
  • Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested.

Preferred Qualifications:

  • DCWF Role 511 - Cyber Defense Analyst / 531 – Cyber Defense Incident Responder advanced & intermediate certifications:
    • Cisco: CBROPS
    • CompTIA: CySA+, Cloud+, PenTest+, Security+
    • EC-Council: CEH
    • GIAC: GCFA, GCIA, GICSP, GMON, GRID, CED, GDSA, GSEC
    • ISC2: CCSP

NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this role is $101,376 - $152,064. Actual compensation will depend on a number of factors, including the candidate’s relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits. 

About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, 

NTT DATA endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at .  This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cyber Defense & Incident Responder in Arlington, VA vacancy
  •  ...Pentagon or Mayfield VA ~ Customer DEA ~ Intermediate SOC Analyst ~6 years with Bachelor Position Summary The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to cybersecurity incidents in accordance with established... 
    Cyber
    Remote work

    Gormat

    Arlington, VA
    12 days ago
  • $175k - $180k

     ...Job Description Job Description Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington, VA On-site Salary Range $175,000 to $180,000 Certification Required DoD 8570 / DoD 8140 IAT Level II... 
    Cyber
    Weekend work

    S2i2 Inc

    Arlington, VA
    24 days ago
  • $60k - $100k

     ...should have a minimum of 4 years in cybersecurity operations and a bachelor's degree in a related field. The role involves leading incident response efforts, documenting actions, and collaborating with technical teams to enhance security across multiple environments.... 
    Cyber

    MAXIMUS

    Washington DC
    1 day ago
  • $120k - $170k

     ...Job Description Job Description Overview We are seeking a Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst to support our Prime Contract with the Defense Threat Reduction Agency at Fort Belvoir. This position requires an active Top-Secret Clearance... 
    Cyber
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Shift work
    Weekend work
    Afternoon shift

    TekSynap

    Fort Belvoir, VA
    17 days ago
  •  ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and...  ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat... 
    Cyber
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    3 days ago
  •  ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client....  ...improvement to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,... 
    Cyber
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    3 days ago
  •  ...intersect. Our single focus has been delivering cyber solutions to effectively manage risk &...  ...for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in...  ...will help monitor, detect, investigate, and respond to cybersecurity threats affecting a large... 
    Cyber

    TDI (Tetrad Digital Integrity)

    Arlington, VA
    3 days ago
  •  ...dedicated to supporting mission‑critical defense and intelligence initiatives. We...  ..., and application dependencies. Respond to and resolve critical network incidents within designated resolution...  ...Minimum of 4 years of experience in cyber operations, cybersecurity, or a related... 
    Cyber
    Permanent employment
    Full time
    Local area

    CGI Njoyn

    Washington DC
    3 days ago
  •  ...Description Job Description Title: Incident Manager III Description:   Solutions...  ...and critical asset owners who experience cyber-attacks, providing immediate investigation...  ...in reported incidents Recommending defense in depth principles and practices (i.e.,... 
    Cyber
    For contractors
    Immediate start
    Shift work

    Solutions³ LLC

    Arlington, VA
    21 days ago
  • $100k - $126.5k

     ...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic...  ...counsel in independently responding to allegations of fraud,...  ...horses, choosing appropriate defenses and response tactics for each...  ...to clients on the adequacy of cyber security controls in accordance... 
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    1 day ago
  •  ...Description Job Description Title: Incident Manager III Description:   Solutions...  ...and critical asset owners who experience cyber-attacks, providing immediate investigation...  ...hygiene techniques, and cybersecurity defense policies, procedures, and regulations... 
    Cyber
    For contractors
    Immediate start

    Solutions³ LLC

    Arlington, VA
    8 days ago
  • $110k - $130k

     ...customers across the Department of Defense and Intelligence Community....  ...advanced engineering, cyber, and intelligence solutions that...  ...implement solutions associated with incident tickets and requirements....  ...Center (ITOC) personnel. Respond to after-hours outages when deemed... 
    Cyber
    Full time
    Contract work
    Remote work
    Afternoon shift

    Ennoble First, Inc.

    Washington DC
    1 day ago
  • $155k - $180k

     ...About Agile Defense At Agile Defense we know that action defines the outcome and...  .... Requisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA...  ...Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an... 
    Cyber
    Work experience placement

    Agile Defense

    Reston, VA
    1 day ago
  • $130k - $152.5k

     ...them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct...  ...breach detection, threat analysis, incident response and malware analysis;...  ...guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity... 
    Cyber
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    4 hours ago
  •  ...technically advanced full-spectrum cyber, data operations, systems...  ...space operations, cyber defense and resiliency, vulnerability...  ...based engagement kits for cyber incident response and threat hunting operations...  ...and using the lab and responds to users’ needs in a timely... 
    Cyber
    Contract work
    Local area

    Nightwing Group

    Arlington, VA
    2 days ago
  • $125k - $150k

     ...bridge the gap between Department of Defense and Federal Government acquisition programs...  ...are seeking an experienced Senior Cyber Security Engineer (CSE3) to support...  ...vulnerability assessments, and respond to security incidents. This role combines IT expertise with... 
    Cyber
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area
    Remote work
    Flexible hours

    Decision Technologies, Inc.

    Washington DC
    1 day ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...customer to provide support for onsite incident response to civilian Government agencies... 
    Cyber
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    27 days ago
  •  ...technically advanced full-spectrum cyber, data operations, systems...  ...space operations, cyber defense and resiliency, vulnerability...  ...based engagement kits for cyber incident response and threat hunting operations...  ...monitoring solutions* Respond to service outages and... 
    Cyber
    Contract work
    Local area

    Nightwing Group

    Arlington, VA
    1 day ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...customer to provide support for onsite incident response to civilian Government agencies... 
    Cyber
    Contract work
    Local area
    Immediate start

    Nightwing

    Arlington, VA
    27 days ago
  •  ...States CHAOS Industries is redefining modern defense with a multi‑product portfolio that gives...  ...defend the organization against evolving cyber threats. This role will support day‑to‑...  ...& Qualifications Security Monitoring & Incident Response Monitor and triage security alerts... 
    Cyber

    CHAOS Industries

    Washington DC
    3 days ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...customer to provide support for onsite incident response to civilian Government agencies... 
    Cyber
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    27 days ago
  • Job Overview A law firm seeks a Cyber Incident Response Associate Attorney in Washington, DC. This role involves managing cybersecurity incidents...  ...notices of data breaches to individuals and regulators. Respond to regulatory investigations arising from data breaches.... 
    Cyber
    Flexible hours

    BCG Attorney Search

    Washington DC
    4 days ago
  • Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships... 
    Cyber
    Work at office
    Remote work

    Phase2 Technology

    Mc Lean, VA
    4 days ago
  • $135k - $143k

     ...Cybersecurity Analyst leads in the proactive defense of the organization's information systems...  ...operations, risk mitigation, incident response, and security architecture, ensuring...  ...including SIEM, ZTS, EDR, IDS/IPS, and other cyber management platforms, optimizing their effectiveness... 
    Cyber
    Full time
    Contract work
    Casual work
    Remote work
    Flexible hours

    Gunnison Consulting Group Inc

    Washington DC
    1 day ago
  •  ...technology and services integrators in the defense and government services industry. We...  ...Experience : 10+ years managing enterprise IT/cyber programs, including SOC operations; DHS...  ...certification related to security and/or incident response (e.g., Certified Ethical Hacker... 
    Cyber
    Full time
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOS International LLC

    Washington DC
    4 days ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...customer to provide support for onsite incident response to civilian Government agencies... 
    Cyber
    Contract work

    Nightwing

    Arlington, VA
    24 days ago
  •  ...the Cybersecurity & Technology Controls Incident Management & Response team, you will serve...  ...mitigate impacts. Act as the frontline defense for cybersecurity incidents, ensuring...  ...operating systems, network fundamentals, cyber tools, and cloud architecture. High-level... 
    Cyber

    J.P. Morgan

    Washington DC
    8 days ago
  •  ...United States (U.S.) Army C5ISR Center to develop advances within cyber defense research; advanced detection methods; sensor structure, data...  .... Review information, documentation, and reporting of incidents and events from other CSSP teams, as well as third parties, and... 
    Cyber

    Integral Services Company

    McLean, VA
    5 days ago
  •  ...Location: On-Site in Arlington, VA Department: Cyber Security Services Reports To: Management...  ..., providing services to military, defense, and critical infrastructure industries....  ...measures and procedures, including reporting incidents to the AO and appropriate reporting... 
    Cyber
    Full time
    Work at office
    Local area

    Apavo Corporation

    Arlington, VA
    1 day ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous...  ...S. Government customer to provide onsite incident response to civilian Government agencies... 
    Cyber
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Defense & Incident Responder. Be the first to apply!