Cybersecurity Incident Response Lead
Eliassen Group
Job Description
Job Description
Description:
Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA
Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.
Due to federal security clearance requirements, applicant must be a United States Citizen with ability to obtain Public Trust clearance. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $80.00/hr. w2
Responsibilities:- Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
- Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
- Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
- Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
- Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
- Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
- Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
- Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
- Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization’s security posture.
- Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
- Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
- Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
- Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
- Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.
- US Citizenship required.
- 10+ years in incident response, security operations, or penetration testing.
- 5+ years managing incident response teams.
- Strong knowledge of malware analysis, forensics, threat intelligence, and adversary TTPs.
- Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst.
- Ability to obtain and maintain a Public Trust clearance.
- Master of Science degree in IT, Information Security, or related field.
Recruitment Transparency Notice
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( View email address on us.fitly.work , View phone number on us.fitly.work) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range. W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact View email address on us.fitly.work.
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
- ...A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...Suggested
- Oxley Enterprises, Inc. in Alexandria, VA is seeking a Cybersecurity Analyst / Incident Response Coordinator to oversee incident response, vulnerability... ...hands-on cyber and incident lifecycle management. You will lead security operations, coordinate a team, and produce...Suggested
$100k - $120k
...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity...Suggested- ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data...SuggestedContract work
$138k - $209k
AIS (Applied Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats effectively. The candidate will develop strategies, frameworks, and ensure adherence to security protocols, working closely...Suggested- Amazon Security's Business Assurance Center seeks an Incident Response Coordination Supervisor to lead a 24/7 GSOC team and ensure timely incident management across global security operations. Role requires a Bachelor's degree, 3+ years of operations personnel management...Shift workWeekend workAfternoon shift
$138k - $209k
...Inc is seeking a Security Architect in Alexandria, Virginia. The ideal candidate will lead incident management activities, develop cybersecurity strategies, and oversee incident response teams. With a Master's degree in IT or a related field and at least 10 years of...Contract work- A dynamic Woman Owned Small Business is seeking a Senior Incident Response Coordinator for their Program Management and Cyber Support Services project in Arlington, Virginia. The role entails coordinating cyber incident responses, managing stakeholder communications, and...
- AnaVation is seeking a Security Analyst (Incident Responder) to support client leadership with... ...vulnerability management and incident response activities. The role requires interacting... ...and presenting findings clearly. You'll lead IR operations, monitor EDR and SIEM tools...
- Kapili Services, LLC is seeking an Incident Responder/Incident Response Coordinator to offer support for government clients in Arlington, VA. The ideal candidate will have a four year degree in information technology and a minimum of eight years of relevant experience...
$140k - $150k
Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon... ...group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position...Work at officeRemote work$150k - $190.7k
...connection. We do this by driving Responsible Growth and delivering for our clients... ...us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority... ...principal, staff, or architect level in cybersecurity engineeringExperience defining or...Full timeWork at officeFlexible hoursShift workDay shift$195k - $205k
...IT operations, ensuring compliance with DoD standards, and leading a team in providing technical support. Key responsibilities include preparing Monthly IPRs, ensuring COOP compliance, and managing incidents efficiently. The ideal candidate will have a Bachelor’s degree...- ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor...
- ...Agile Defense, LLC is seeking an experienced Cyber Incident Response Team Lead to support a 24/7/365 CSOC program. The role leads investigations, forensic analyses (host, cloud, network) and develops countermeasures to protect critical assets across USG customers. The...
- ...about our exciting organization, please visit us at are seeking a Cybersecurity Incident and Application Lead to join our team and support our client. The ideal candidate is a strong incident response and application security professional who remains calm under pressure...Temporary workFor contractorsWork experience placementWork at officeRemote work2 days per week
$136k - $184k
...Job Qualifications: Skills: Cyber Incident Response, Cyber Operations, Cyber Risks, Data... ...Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls... ...networking, compute, storage, infrastructure, cybersecurity, applications, hosting, and program...Full timeContract workTemporary workWork experience placementImmediate startRemote workWorldwideFlexible hoursShift work$120k - $170k
...seeking a Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst to support our Prime... ...to employment consideration. Responsibilities RESPONSIBILITIES Collect and... ...working knowledge of the DoDI 8530.01 (Cybersecurity Activities Support to DoD...Full timeContract workTemporary workWork at officeLocal areaShift workWeekend workAfternoon shift- Requisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified Information... ...Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations...Work experience placement
$140k - $160k
Role Overview SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications... ...seeking an experienced Tier 2 Shift Lead for the Cyber Incident Response Team to support our customer's Federal Strategic Cyber...Contract workLocal areaAll shiftsShift work- GEICO seeks a GSOC Supervisor at GEICO Headquarters in Bethesda, MD, to oversee on‑duty SOC operators and lead incident response from detection to resolution, ensuring timely triage and escalation to crisis teams. The role requires proven leadership, strong writing and...
- SkyePoint Decisions seeks an experienced Tier 2 Shift Lead for the Cyber Incident Response Team to support our Federal Strategic Cyber Mission program in Beltsville, MD. This on-site role runs Tuesday through Saturday, 2pm to 10pm, demanding hands-on incident analysis,...Shift work
- Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a team of IR Tier-1, Tier-2, and Forensics specialists on a Federal... ...role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead. The candidate will provide oversight...Contract work
- ...validation. is searching for a Rapid Response Team Lead to oversee the integrity, security,... ...the Rapid Response Team in response to cybersecurity breaches, focusing on assessing and... ...occur.Communicate plans and responses to incidents to customer leadership, providing...Full timeContract workLocal area
- ...Will Do:The Principal II Fraud Analytics Lead will provide strategic technical... ..., forensic analysis, data mining, and cybersecurity monitoring initiatives. Develop and apply... ...data engineering, predictive analytics, incident response, investigations, platform advisory, or...Full timeFor contractorsFlexible hours
- ...Analytics Senior Consultant Lead will support highly specialized... ...activities across the Cybersecurity Fraud Analytics and Monitoring... ...forensics, fraud detection, incident support, data integration, and... ...stakeholder coordination, and incident response environments. Develop...Full timeFor contractorsFlexible hours
$138k - $209k
...matter, alongside industry-leading experts, in an environment that... ...needs of our client as a Incident Management Lead. Project Summary... ...Incident Management Lead is responsible for directing enterprise-... ...analyzing, and responding to cybersecurity threats. This role will...Contract workTemporary work- ...Description Job TitleLead Cyber Defense Incident ResponderClearanceTS/SCI (active,... ...Program (SAP) networks.Duties and Responsibilities- Lead a small team of advanced and mid-level... ...Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or...Weekend work
- ...Job Description Job Description Position Summary The Cybersecurity Lead will serve as a “Dual-Hat” role providing senior technical... ...Lead, this role will provide expert oversight for the entire incident response lifecycle, from initial detection and log correlation...Local area
- bcmcllc is seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses on forensic investigations and incident response, requiring an active TS/SCI clearance. Candidates should possess at least 8 years of experience in...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Incident Response Lead. Be the first to apply!
- cybersecurity specialist Alexandria, VA
- cyber security Alexandria, VA
- senior cybersecurity engineer Alexandria, VA
- cyber security lead Alexandria, VA
- IT cyber security Alexandria, VA
- cybersecurity policy and compliance analyst Alexandria, VA
- cybersecurity technical writer Alexandria, VA
- cybersecurity Alexandria, VA
- remote cyber security Alexandria, VA
- cybersecurity software engineer Alexandria, VA


