Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Response Team (CIRT) Lead

$136k - $184k

Gdit

Job Qualifications: Cyber Incident Response, Cyber Operations, Cyber Risks, Data Security, Leadership Job Description: Type of Requisition: Regular Clearance Level Must Currently Possess: Secret Clearance Level Must Be Able To Obtain: Secret Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Skills: Job Qualifications: Cyber Incident Response, Cyber Operations, Cyber Risks, Data Security, Leadership Certifications: None Experience: 5 + years of related experience US Citizenship Required: Yes Job Description: Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls Church, VA Clearance: Active SECRET (must be maintained) At GDIT, we are passionate about securing and supporting some of the most challenging government, defense, and intelligence missions. As part of our team, your work will have meaning and impact, helping to make today safer and tomorrow smarter. Join a culture that values autonomy, collaboration, and delivering your best every day. GDIT has an opening for a Cyber Incident Response Team (CIRT) Lead supporting the Army National Guard (ARNG). This position is part of an IT Service Management contract that includes the operation, modernization, expansion, and evolution of the ARNG’s global IT services. These services span networking, compute, storage, infrastructure, cybersecurity, applications, hosting, and program management. The program operates within the ITIL framework to deliver high-quality IT services to the ARNG, and this leadership role is critical to ensuring the security and success of that mission.

HOW A CIRT LEAD WILL MAKE AN IMPACT

As the CIRT Lead, you will combine hands-on incident response expertise with team leadership responsibilities to guide analysts and coordinate complex cyber operations in support of ARNG. Lead and Manage the CIRT Team Provide day-to-day leadership of CIRT analysts, including tasking, prioritization, and oversight of incident response activities. Mentor, coach, and develop team members, including feedback, informal performance guidance, and support for career development. Ensure consistent adherence to incident response procedures, quality standards, and timelines. Coordinate shift coverage, on-call rotations, and escalation paths to meet mission requirements. Serve as the primary point of contact for CIRT-related activities with ARNG stakeholders and other GDIT teams. Incident Response Operations Lead triage of cyber incidents, determining scope, urgency, impact, and recommended courses of action. Guide and, when necessary, perform collection and analysis of network/host artifacts (logs, images, packet captures) to identify root cause and operational impact. Oversee real-time cyber defense incident handling, ensuring rapid, coordinated response and remediation. Direct proactive identification of vulnerabilities and recommend mitigations to reduce risk. Demonstrate and validate effectiveness of defenses through coordination with Red Team activities and investigations. Ensure cyber defense incidents are managed, documented, and tracked from detection through resolution, with clear, concise reporting. Process, Documentation, and Training Maintain and improve Incident Response tactics, techniques, procedures (TTPs), and training documentation. Plan and oversee the delivery of incident response training courses (at least four per calendar year), delegating instruction and ensuring quality content. Support efforts to maintain the customer’s CSSP accreditation, including documentation, technical writing, and audit support. Drive continuous improvement in incident response workflows, tools usage, and reporting. Stakeholder Communication and Collaboration Provide timely briefings and written reports to ARNG leadership and other stakeholders on incident status, trends, and lessons learned. Participate in and often lead cross-functional meetings to improve cybersecurity posture across the environment. Coordinate closely with engineering, operations, and other cyber defense teams to ensure alignment and effective mitigation of threats. Support on-call and after-hours activities as needed, and ensure the team is prepared to respond to time-sensitive events under tight deadlines.

WHAT YOU’LL NEED TO SUCCEED

Education / Equivalent Training Bachelor’s degree in information technology, computer science, or a related technical discipline; or an equivalent combination of education, technical certifications/training, and relevant work experience. Required Experience 5+ years of practical experience in a cybersecurity, engineering, T&E, or A&A-related field. Demonstrated prior experience with cyber incident response on DoW networks and digital forensics. Experience in a lead or senior role guiding incident response activities or mentoring junior analysts is strongly preferred. Technical And Leadership Skills Proficiency in collecting and analyzing logs, system images, and other artifacts to investigate and resolve cybersecurity incidents. Strong understanding of cybersecurity concepts, mitigation strategies, root cause analysis, and Red Team operations. Familiarity with current cyber defense tools and technologies (e.g., SIEM, IDS/IPS, endpoint protection, packet capture tools). Excellent oral and written communication skills for both technical and non-technical audiences, including incident reports and briefings. Strong organizational skills for multitasking, meeting deadlines, and managing team workload. Ability to work independently and lead a team in fast-paced environments, solving complex problems under pressure. Collaborative mindset, strong customer service orientation, and ability to build trust and credibility with customers and team members. Dependability, punctuality, responsiveness to management, and attention to detail. Certification Requirements Must possess the appropriate baseline certification(s) to achieve at least DoWD 8570.01-M IAT Level II (e.g., CompTIA Security+ CE) prior to start. Must obtain an additional computing environment certification within six months of hire based on position designation (e.g., CEH, CCNA-Security, CND, etc.). When DoW 8140 requirements are implemented on the program/contract, employees must conform to 8140 certification standards. Security Clearance Active SECRET security clearance required and must be maintained.

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do. Growth: AI-powered career tools that identify career steps and learning opportunities. Support: An internal mobility team focused on helping you achieve your career goals. Rewards: Comprehensive benefits and wellness packages, 401(k) with company match, competitive pay, and paid time off. Community: Award-winning culture of innovation and a military-friendly workplace.

OWN YOUR OPPORTUNITY

Explore a leadership role in cyber incident response at GDIT and you’ll find opportunities to guide mission-critical work while growing alongside colleagues who share your passion for the mission and delivering results. The likely salary range for this position is $136,000 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Onsite Work Location: USA VA Falls Church Additional Work Locations: Total Rewards At GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process: As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work: We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans #J-18808-Ljbffr General Dynamics Information Technology

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber Incident Response Team (CIRT) Lead in Falls Church, VA vacancy
  • Requisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified Information...  ...(CISSP) SUMMARY Agile Defense is seeking an experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity... 
    Cyber
    Work experience placement

    Agile Defense

    Reston, VA
    5 days ago
  • General Dynamics Information Technology in Falls Church, VA, is seeking a Cyber Incident Response Team (CIRT) Lead to drive incident response operations for ARNG IT services. The role combines hands-on cybersecurity with team leadership to mentor analysts and coordinate... 
    Cyber
    Full time

    General Dynamics Information Technology

    Falls Church, VA
    3 days ago
  • Accenture Federal Services in Arlington, VA is seeking a Cybersecurity Incident Response Junior Analyst and Triage Analyst to join the CIRT team within the CISO organization. You will monitor, triage, and respond to alerts from SIEM and security sensors, and work with incident... 
    Cyber

    Accenture Federal Services

    Arlington, VA
    4 days ago
  • Accenture Federal Services in Arlington, VA is seeking a Cybersecurity Incident Response Triage Analyst to join the CIRT team within the CISO organization. You will monitor alerts from SIEM and security sensors, triage events, coordinate with incident response teams, and... 
    Cyber

    Accenture-Federal-Services-2

    Arlington, VA
    1 day ago
  • A dynamic Woman Owned Small Business is seeking a Senior Incident Response Coordinator for their Program Management and Cyber Support Services project in Arlington, Virginia. The role entails coordinating cyber incident responses, managing stakeholder communications, and... 
    Cyber

    Zantech

    Arlington, VA
    4 days ago
  •  ...seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses on forensic investigations and...  ...Candidates should possess at least 8 years of experience in cyber forensic investigations, with specific knowledge of forensic... 
    Cyber

    bcmcllc

    Arlington, VA
    3 days ago
  • $53.9k - $120.1k

    Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity...  ...role will work in the CIRT team in the CISO organization....  ...under analysis and triage team lead to perform in-depth...  ...response lifecycles, common cyber-attacks, insider-threat indicators... 
    Cyber
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture Federal Services Careers Marketplace

    Arlington, VA
    3 days ago
  • $57.2k - $109.4k

    Cybersecurity Incident Response Triage Analyst Arlington, VA The Work The...  ...Analyst role will work in the CIRT team in the CISO organization....  ...the analysis and triage team lead to relate, scope, and triage...  ...response lifecycles, common cyber-attacks, and federal incident... 
    Cyber
    Work experience placement
    Live in
    Work at office
    Local area
    Shift work

    Accenture Federal Services Careers Marketplace

    Arlington, VA
    7 days ago
  •  ...Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships... 
    Cyber
    Work at office
    Remote work

    Phase2 Technology

    McLean, VA
    3 days ago
  • $100k - $120k

    Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 
    Cyber

    Bering Straits Native Corporation

    Washington DC
    4 days ago
  •  ...Nightwing in Arlington, VA is looking for a Solutions Architect to provide onsite incident response support for U.S. Government agencies facing cyber-attacks. The candidate will lead technology mapping and workflow development, requiring strong skills in systems engineering... 
    Cyber

    Nightwing

    Arlington, VA
    14 hours ago
  •  ...VA is seeking a Cybersecurity Analyst / Incident Response Coordinator to oversee incident...  ...security program. This role combines hands-on cyber and incident lifecycle management. You will lead security operations, coordinate a team, and produce leadership reports while maintaining... 
    Cyber

    Oxley Enterprises, Inc.

    Alexandria, VA
    4 days ago
  •  ...bcmcllc is looking for a Solutions Architect to support U.S. Government mission by providing incident response related to cyber-attacks. This position demands extensive experience in systems engineering, along with capabilities in cybersecurity and technical analytics... 
    Cyber

    bcmcllc

    Arlington, VA
    14 hours ago
  • $138k - $209k

    AIS (Applied Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats effectively. The candidate will develop strategies, frameworks, and ensure adherence to security protocols, working closely... 
    Cyber

    AIS (Applied Information Sciences)

    Alexandria, VA
    3 days ago
  • A leading cybersecurity firm in Virginia is seeking a Cyber Eviction Lead to enhance incident response capabilities. The ideal candidate will have a strong background in cyber defense...  ..., collaborating with internal teams, and developing mitigation strategies. This... 
    Cyber

    Nightwing

    Arlington, VA
    9 hours ago
  •  ...Virginia, is seeking a cybersecurity professional with expertise in cyber incident management. The ideal candidate will have over 5 years of relevant experience and be knowledgeable in incident response methodologies. The position requires familiarity with NIST 800-62,... 
    Cyber

    Raytheon Technologies

    Arlington, VA
    1 day ago
  • $140k - $150k

     ...DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office /...  ...join our advanced security operations team which is a specialized group focused on...  ...incident reportingDeep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model... 
    Cyber
    Work at office
    Remote work

    ECS Federal

    Washington DC
    2 days ago
  • Nightwing Group is seeking a Cyber Eviction Lead in the Arlington, VA area for hybrid work. The...  .... citizenship, and 8+ years in cyber incident response plus strong written and verbal...  ...on hunt and incident response, guide teams, assess attacks, and produce detailed... 
    Cyber

    Nightwing Group

    Arlington, VA
    1 day ago
  •  ...A leading social media company is seeking a Lead Cyber Security Operations Center Analyst to oversee incident responses and investigations. This role involves leading a team of analysts, developing detection strategies, and ensuring the safety of user data on the platform... 
    Cyber

    TikTok

    Washington DC
    22 hours ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world. The Cyber Incident Response Analyst will work... 
    Cyber
    Shift work
    Night shift
    Day shift
    Afternoon shift

    ManTech

    McLean, VA
    2 days ago
  • A cybersecurity and intelligence firm is seeking a Cyber Eviction Analyst to support critical incident response missions. The role requires extensive expertise in threat actor tools, incident mitigation, and collaborative problem-solving. Ideal candidates will possess... 
    Cyber

    Nightwing Group

    Arlington, VA
    1 day ago
  •  ...Analyst to provide vital support for onsite incident response to U.S. Government agencies experiencing cyber-attacks. The role involves leading use case identification, gathering...  ...coverage and an attractive 401k plan. Join a team committed to delivering innovative solutions... 
    Cyber

    bcmcllc

    Arlington, VA
    4 days ago
  • Nightwing is seeking a Cyber Incident Manager based in Arlington, VA, to support U.S. Government agencies in mitigating cyber-attacks. The...  ...in cyber incident management, knowledge of incident response methodologies, and a valid TS/SCI clearance. Responsibilities... 
    Cyber

    Nightwing

    Arlington, VA
    4 days ago
  •  ...cybersecurity company in Arlington, VA, is seeking experienced Network Forensics Cybersecurity Analysts to support incident response missions for government clients facing cyber threats. The ideal candidate has at least 8 years of experience in network investigations, solid... 
    Cyber

    Nightwing

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm is seeking a Network Forensics Analyst to support critical incident response missions. Candidates must have 8+ years of experience in network investigations...  .... The role involves coordinating teams, analyzing network traffic for anomalous... 
    Cyber

    Nightwing

    Arlington, VA
    1 day ago
  • BCMC is seeking a Cyber Incident Response Expert to support the DHS Hunt and Incident Response Team (HIRT). The role involves advanced host and network analysis, incident containment, and rapid on-site response for government agencies and critical infrastructure owners.... 
    Cyber

    bcmcllc

    Arlington, VA
    1 day ago
  • myBridge Corporation is seeking an Incident Response Specialist to join our Cybersecurity Operations team. You will detect, investigate, and respond to cybersecurity incidents affecting enterprise systems and networks, and help recover from attacks to minimize impact.... 
    Cyber

    Mybridge

    Arlington, VA
    4 days ago
  • A cybersecurity firm in Arlington, Virginia is seeking a Cyber Action Officer to support incident response efforts for government clients experiencing cyber-attacks. Responsibilities include managing cyber incidents, coordinating reports, and collaborating with partners... 
    Cyber

    Nightwing

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm is seeking a Cloud Forensics Analyst to support onsite incident response to cyber-attacks. The role involves acquiring and analyzing computer artifacts, conducting forensic investigations, and developing mitigation strategies. Candidates should... 
    Cyber

    Nightwing

    Arlington, VA
    4 days ago
  • A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding... 
    Cyber

    Nightwing

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Response Team (CIRT) Lead. Be the first to apply!