Lead Cyber Defense Incident Responder TS/SCI
S2i2 Inc
Job Description
Job Description
Job TitleLead Cyber Defense Incident ResponderClearanceTS/SCI (active, required)LocationArlington, VA On-siteSalary Range$165,000 to $170,000Certification RequiredDoD 8570 / DoD 8140 IAT Level IIOne of the following: Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalentApplication DeadlineSeptember 30, 2026 Description:The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.Duties and ResponsibilitiesLead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence.Minimum Qualifications and RequirementsBachelor 's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.Demonstrated leadership skills, preferably in a formal leadership role.Scripting experience.TS/SCI clearance is required.Knowledge, Skills, and AbilitiesAdvanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).Technical mentorship: experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.Advanced forensics: deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.Malware and script analysis: high-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.Superior research capabilities: exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.Executive communication: excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership.Technical translation: ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers.Project and case management: proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.Crisis management: ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.Collaboration: well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.Attention to detail: excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks. About S2i2S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company.We are proud to include:Support to achieve professional certifications and degreesLeadership that is accessible to all employeesRegular company updatesClient networking social engagementsMonthly team-building activities (past examples: Top Golf)Supporting our community - including veteransAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
- S2i2, Inc. is seeking a Lead Cyber Defense Incident Responder in Arlington, VA. This highly experienced role combines hands-on technical work with leadership of a security analytics team operating in TS/SCI and SAP environments. Expect threat hunting, malware research,...Cyber
- Leidos is seeking a Cyber Security Analyst to defend DoD networks... ...handling monitoring, detection, incident response, and vulnerability... .... In Fort Belvoir, VA, you’ll lead investigations through the Incident... ...reports. The role requires TS/SCI and baseline certifications, with...Cyber
- S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA to manage advanced threat detection and incident response for government clients within TS/SCI and SAP environments. The role requires hands-on technical work, leadership of a security analytics team...Cyber
- ...Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You... ...risks and process gaps, support incident-response, and translate complex cyber information... ...McLean, VA and the candidate must hold TS/SCI with CI Poly. #J-18808-Ljbffr Ops Tech...Cyber
$100k - $125k
...cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA.... ...strong analytical skills and an active TS/SCI clearance. Candidates should have over 8... ...opportunity to work on critical national security missions. #J-18808-Ljbffr Argo Cyber SystemsCyber- ...Technology (GDIT) seeks a Cyber Security Analyst Senior to join the Cyber Network Defense team supporting the Air Force... ...include coordinating incident responses, applying threat... ...cyber readiness to program leads. This role requires TS/SCI clearance and on-site work....Cyber
- ...Job Description Cybersecurity Lead - Joint Base Anacostia-Bolling, Washington, D.C. - Active TS/SCI Clearance with Polygraph Required... ..., and proactive mitigation of cyber threats.RESPONSIBILITIESDefine... ...-authorized teams; review and respond to findings.Develop and maintain...CyberFull time
$111k - $122k
...career at the company leading workforce... ...Salesforce.Computer Security Incident Response AnalystThis... ...Response Analyst will respond to and investigate cyber security events within... ...Government Top Secret/SCI security clearance with... ...requires a USA TS/SCI with Polygraph security...CyberFull timeWork experience placementLocal area$107.9k - $195.05k
...repeatability. Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ... ...detect, analyze, mitigate, and respond to cyber threats and adversarial... ...a US Citizen. Must hold active TS/SCI security clearance to be...CyberFull time- A leading digital automation company is seeking an experienced Incident Manager to gather and analyze cyber threat intelligence. Key responsibilities include identifying emerging threats... ...minimum of 2 years' experience, active TS/SCI clearance, and strong analytical skills...Cyber
- Leidos is seeking a Cyber Security Analyst to support the DoDIN defense from the Fort Belvoir SOC, performing continuous monitoring, incident response, and vulnerability management across on‑prem... .... U.S. citizenship with an active TS/SCI clearance and baseline Security+ CE...Cyber
- A leading technology integrator is seeking an Information System Security Engineer to support... ...security plans, and mitigating cyber threats while ensuring compliance with security standards. Candidates must have a TS/SCI clearance, relevant degrees, and experience...Cyber
- Leidos is seeking a Cyber Security Analyst to support the C5ISR Defensive Cyber Solutions Branch at Fort... ...threat detection, incident response, and vulnerability... ...Responsibilities include leading investigations, analyzing... ...with a fast-paced team. TS/SCI with SAP eligibility...Cyber
$104k - $166k
...to hire an experienced Incident Response Analyst (ICS/... ...' Federal Strategic Cyber group. Location: On‑site... .... This role involves responding to cyber incidents across... ....Ability to obtain a TS/SCI for continued... ...galaxy. As the world’s leading mission capability integrator...CyberContract workCurrently hiringShift work1 day per week- ...is seeking a Security Operations Center Lead for the DISA GSM-O program in Alexandria,... ...-to-day SOC activities, coordinates 24x7 incident handling, and ensures strict adherence to... ...processes. Qualified candidates will have TS/SCI clearance, 10+ years in cybersecurity, and...Cyber
- ...support critical federal engagements in Arlington, VA. The role requires leading forensic teams, conducting cyber investigations, and delivering detailed reports on findings. Candidates must have a TS/SCI clearance, U.S. citizenship, and 5+ years in digital forensics. You...Cyber
- ...Synertex is seeking a Cyber Threat Intelligence... ...recommendations for defensive operations. You'll be... ...risk, and you'll play a lead role in incident analysis, adversarial... ...options. Clearance: TS/SCI RESPONSIBILITIES:Monitor... ...analysts, incident responders, and cybersecurity...Cyber
$120k - $165k
...Pentagon) Clearance Required: TS/SCI minimum (US Citizen) Employment... ...support of the Department of Defense (DoD), Intelligence Community,... ...Analytics is seeking a Principal Cyber Systems Engineer, SME to... ...technological superiority. You will lead the evaluation of innovative...CyberFull timeWork at office$90k - $130k
...Clearance Requirement: TS/SCI Clearance Required... ...remediation plans; support incident response activities... ...novel attack chains, and defensive gaps discovered during... ...(GCIH)GIAC Industrial Cyber Security Professional... ...) or CyberSec First Responder (CFR)Certified Information...CyberFull timeWork at office- ...deep understanding of defense-specific security... ...regulations. Monitor and respond to security incidents, including conducting... ..., to protect against cyber threats. Provide... ...(CISSP, etc.) ~ TS/SCI Clearance ~5+ years... ...practices. ~ Experience leading security incident...Cyber
$155k - $180k
...About Agile Defense At Agile Defense we know that action defines... ...#: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified... ...Defense is seeking experienced Cyber Incident Response Team Lead to...CyberWork experience placement- ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The... ...improvement to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,...CyberContract workFlexible hours
- ...opportunity to support our nation's defense. Make an impact by connecting... ...skilled and multi-faceted Cyber Analyst Principal for a... ...Security Manager (ISSM), and Cyber Lead in ensuring the unyielding security... ...possess a current and active TS/SCI with Polygraph. ●...CyberFull timeContract work
- Leidos is seeking a Mid Exercise Planner - Joint Cyber Defense Collaborative (JCDC) to support HSEEP exercise design, development, conduct... ...evaluation for CISA's National Cyber Exercise Program. An active TS/SCI clearance is required for this position. The role involves...Cyber
- ...Perks: As recognized members of the Cyber Elite, we work together in partnership... ...: We are seeking an Expert Cyber Defense Analyst (TS/SCI Clearance) to analyze cyber events and... ...Collaborate with a functional team lead and team members to support mission objectives...Cyber
$102.5k - $188.9k
...Summary Our Deloitte Cyber team understands the... ...identify, analyze, and respond to exploitation... ...you will support cyber defense efforts by analyzing threat... ...activity, investigating incidents, assessing vulnerabilities... ...to lead projects or workstreamsAbility...CyberWork at office- ...Washington, DCPosition Overview: We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and... ...Information (PII), and coordinating remediation efforts.Cyber Threat Monitoring: Develop and maintain a Cyberthreat Dashboard...CyberContract workFor contractorsWork at officeLocal area
- ARGO Cyber Systems is looking for an Incident Response Expert III to join our team in the Washington DC Metro Area... ...of relevant experience, an active TS/SCI clearance, and a strong... ...include working on national cyber defense initiatives within a mission-driven...Cyber
- Incident Response Engineer-JourneymanIntermittent Telework: Arlington, VATS/SCI RequiredPay Range: $125K - $142KJob Description: The Incident... ...analyzes security alerts, leads triage activities, and coordinates... ...regulatory needs.Active TS/SCI security clearance U.S. citizenship...Remote work
- ...seeking a Network Administrator for the 3rd shift (10 PM-6 AM) to run daily operations, monitor networks, and respond to incidents on-site. The role requires TS/SCI clearance and DoD 8570 IAT II certification, plus a BS in CS/IT with 4+ years' experience. You will...CyberNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cyber Defense Incident Responder TS/SCI. Be the first to apply!
- cyber sales Arlington, VA
- cyber forensics Arlington, VA
- cyber threat intelligence analyst Arlington, VA
- cyber Arlington, VA
- defense contract Arlington, VA
- insurance defense paralegal Arlington, VA
- defense security service Arlington, VA
- defense attorney Arlington, VA
- missile defense Arlington, VA
- criminal defense Arlington, VA


