Cybersecurity Incident Response Lead
Eliassen Group
Job Description
Job Description
Description:
Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA
Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.
Due to federal security clearance requirements, applicant must be a United States Citizen with ability to obtain Public Trust clearance. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $80.00/hr. w2
Responsibilities:- Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
- Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
- Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
- Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
- Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
- Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
- Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
- Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
- Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization’s security posture.
- Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
- Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
- Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
- Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
- Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.
- US Citizenship required.
- 10+ years in incident response, security operations, or penetration testing.
- 5+ years managing incident response teams.
- Strong knowledge of malware analysis, forensics, threat intelligence, and adversary TTPs.
- Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst.
- Ability to obtain and maintain a Public Trust clearance.
- Master of Science degree in IT, Information Security, or related field.
Recruitment Transparency Notice
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( View email address on us.fitly.work , View phone number on us.fitly.work) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range. W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact View email address on us.fitly.work.
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
- ...operations across enterprise infrastructure. You will lead threat detection, incident response, and proactive threat hunting while managing SIEM... ...HIPAA frameworks, and requires a Bachelor's degree in Cybersecurity, Information Assurance, or IT, with CISSP, CEH, or GIAC...Suggested
- ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data...SuggestedContract work
$100k - $120k
...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity...Suggested$138k - $209k
AIS (Applied Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats effectively. The candidate will develop strategies, frameworks, and ensure adherence to security protocols, working closely...Suggested$107.9k - $195.05k
...customers through scale and repeatability. Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single... ...best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC operationsPromote...SuggestedFull time- Base One Technologies is seeking a seasoned Cyber Threat Hunter to serve as the hunt and incident response SME in a high-security environment. You will apply in-depth knowledge of threat actor tools and TTPs, distill findings into executive summaries and deep technical...
- ...seeking a Security Operations Center (SOC) Lead in Alexandria, VA, to direct day-to-day SOC activities and manage 24x7 incident response operations for the DISA GSM-O program.... .../SCI clearance, a strong background in cybersecurity, and hands-on leadership of large, complex...
$138k - $209k
...Inc is seeking a Security Architect in Alexandria, Virginia. The ideal candidate will lead incident management activities, develop cybersecurity strategies, and oversee incident response teams. With a Master's degree in IT or a related field and at least 10 years of...Contract work- ...a Security Operations Center Lead for the DISA GSM-O program in... ...activities, coordinates 24x7 incident handling, and ensures strict adherence to incident response processes. Qualified candidates... ...TS/SCI clearance, 10+ years in cybersecurity, and 4+ years of team leadership...
- ...sophisticated cyber threats. You will join a 24x7 SOC handling monitoring, detection, incident response, and vulnerability management across on-prem and cloud environments. In Fort Belvoir, VA, you’ll lead investigations through the Incident Response lifecycle, correlate events,...
- ...support our mission critical customer in Reston, VA. As the Incident Response Lead/Advisor, you will advise/mentor/coach a team of cyber... ...experience Management experience Experience with DoD cybersecurity operations Experience with classified system information...Full timeContract workTemporary workImmediate startShift work
$140k - $150k
Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon... ...group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position...Work at officeRemote work$172.5k - $260.1k
...heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right... ...of Salesforce.The ExperienceSalesforce's Computer Security Incident Response Team (CSIRT) provides 24x7x365 security monitoring and rapid...Full timeMonday to FridayShift workNight shift- ...ICS (a REDHAWK company) seeks an experienced Tier 2 Cyber Incident Response Team Shift Lead in Beltsville, MD to join the Federal Strategic Cyber Mission program. You will lead Tier 2 shift operations, review tickets for accuracy, and coordinate with CIRT Watch Officers...Shift work
- ...Hogan Lovells Cadwalder looks for an experienced cybersecurity professional to join the Security Operations team in Washington, D.C. You will lead incident response, investigations, and detection improvements across endpoints, cloud, and identity. The role emphasizes collaboration...
- ...about our exciting organization, please visit us at are seeking a Cybersecurity Incident and Application Lead to join our team and support our client. The ideal candidate is a strong incident response and application security professional who remains calm under pressure...Temporary workFor contractorsWork experience placementWork at officeRemote work2 days per week
$155k - $180k
...strengthen and protect our nation’s vital interests. Title : Incident Response Team Lead Clearance : Active Top Secret with SCI eligibility,... ...Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations...Work experience placementRelocation package- ...validation. is searching for a Rapid Response Team Lead to oversee the integrity, security,... ...the Rapid Response Team in response to cybersecurity breaches, focusing on assessing and... ...occur.Communicate plans and responses to incidents to customer leadership, providing...Full timeContract workLocal area
- ...Will Do:The Principal II Fraud Analytics Lead will provide strategic technical... ..., forensic analysis, data mining, and cybersecurity monitoring initiatives. Develop and apply... ...data engineering, predictive analytics, incident response, investigations, platform advisory, or...Full timeFor contractorsFlexible hours
- ...Analytics Senior Consultant Lead will support highly specialized... ...activities across the Cybersecurity Fraud Analytics and Monitoring... ...forensics, fraud detection, incident support, data integration, and... ...stakeholder coordination, and incident response environments. Develop...Full timeFor contractorsFlexible hours
$165k - $180k
Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington... ...Program (SAP) networks. Duties And Responsibilities Lead a small team of advanced and... ...research analysis on the latest cybersecurity tools, provide rationale to renew or...Weekend work- ...connect with us to get a preview of the full benefits package. Required Experience Minimum of 10 years’ experience providing incident response, security operations, and penetration testing support. Minimum 5 years’ managing and directing incident response teams with a...Temporary work
$138k - $209k
...matter, alongside industry‑leading experts, in an environment that... ...needs of our client as an Incident Management Lead. Project Summary... ...Incident Management Lead is responsible for directing enterprise‑... ..., and responding to cybersecurity threats. This role will develop...Contract workTemporary work- ...Holdings, LLC is seeking a Sr Cybersecurity Compliance Specialist to... ...The role is 100% on-site with responsibilities spanning RMF, FISMA, and DoD... ...vulnerability analysis, and incident response support. Applicants... ...s in CS with 4-7 years in a lead/senior role is required, with...
- ...Strategic Operational Solutions (STOPSO) is seeking a Cybersecurity / Task Order Lead to support the Department of Justice (DOJ), Executive Office... ...Support Services program, providing oversight across incident response, security operations, vulnerability management, insider...Contract workFor contractorsWork at office
- ...SecurePro is seeking experienced Lead and Senior Information... ...ISSOs) to support a federal cybersecurity program in Washington, DC. The... ..., security impact analysis, incident coordination, and audit... ...and qualifications. Key Responsibilities Execute the NIST SP 800-3...Contract work
- ...Job Description Job Description Position Summary The Cybersecurity Lead will serve as a “Dual-Hat” role providing senior technical... ...Lead, this role will provide expert oversight for the entire incident response lifecycle, from initial detection and log correlation...Local area
- ...Cyber Investigation and Forensic Response (CIFR) practice is at the... ...the most consequential cyber incidents. Within CIFR, our Cyber Recovery... ...the practice.The Work:Lead enterprise recovery engagements... ...infrastructure, enterprise architecture, cybersecurity, or a closely related...Full timeLive inWork at officeLocal areaShift work
$131k - $218.3k
...industry depth to collaborate with leading solution providers and... ...team, you will be responsible for… Lead day-to-day operational... ...enterprise mission systemsCoordinate incident response, troubleshooting,... ...processesCoordinate with cybersecurity and customer stakeholders to...Local area$62k - $141k
Cybersecurity RMF LeadThe Opportunity:Design, implement, and manage policies and procedures... ...CertificationNice If You Have:Experience leading RMF efforts across multiple systems,... ...Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we...Full timeContract workPart timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Incident Response Lead. Be the first to apply!
- remote cyber security Alexandria, VA
- cybersecurity certificate Alexandria, VA
- cybersecurity administrator Alexandria, VA
- cybersecurity Alexandria, VA
- cybersecurity specialist Alexandria, VA
- cyber security Alexandria, VA
- cybersecurity software engineer Alexandria, VA
- IT cyber security Alexandria, VA
- senior cybersecurity engineer Alexandria, VA
- cybersecurity professional


