Lead Cyber Defense Incident Responder / SOC Lead (TS/SCI Required)
Full-time
search-tactics
Note - Active TS/SCI Clearance is required.
Description:
The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.
Duties and Responsibilities
Description:
The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.
Duties and Responsibilities
- - Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.
- - Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.
- - Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.
- - Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.
- - Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.
- - Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.
- - Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.
- - Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.
- - Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).
- - Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence.
- - Bachelor's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.
- - Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.
- - Demonstrated leadership skills, preferably in a formal leadership role.
- - Scripting experience.
- - TS/SCI clearance is required.
- - Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.
- - Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.
- - Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.
- - Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.
- - Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.
- - Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).
- - Technical mentorship: experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.
- - Advanced forensics: deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.
- - Malware and script analysis: high-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.
- - Superior research capabilities: exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.
- - Executive communication: excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership.
- - Technical translation: ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers.
- - Project and case management: proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.
- - Crisis management: ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.
- - Collaboration: well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.
- - Attention to detail: excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead Cyber Defense Incident Responder / SOC Lead (TS/SCI Required) in Arlington, VA vacancy
- S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA on-site to lead a skilled team defending TS/SCI and SAP environments. The role demands hands-on threat detection, threat intelligence, and advanced incident response capabilities in highly secure...Cyber
- S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA. The role requires hands-on threat hunting, incident response leadership, and direct engagement with government clients operating TS/SCI and SAP networks. The ideal candidate has extensive experience...Cyber
- S2i2 in Arlington, VA is seeking a Lead Cyber Defense Incident Responder (Advanced) to lead a small team of senior and mid‑level analysts. This on‑site... ...incident defense for highly secure government enclaves (TS/SCI/SAP). The ideal candidate has TS/SCI clearance, DoD 8570...Cyber
- ...Analyst to support enterprise cyber defense in the Washington, D.C.... ...risks and process gaps, support incident-response, and translate... ...actionable recommendations. The role requires on-site work within 50 miles... ...and the candidate must hold TS/SCI with CI Poly. #J-18808-...Cyber
$100k - $125k
...solutions provider is seeking an Incident Response Expert III in Arlington,... ...matter expert in incident response, requiring strong analytical skills and an active TS/SCI clearance. Candidates should have... ...critical national security missions. #J-18808-Ljbffr Argo Cyber SystemsCyber- NTT DATA seeks a Cyber Defense & Incident Responder to monitor, analyze, and respond to cybersecurity incidents in Arlington, VA. The role emphasizes... ...triage, documenting findings, and coordinating with SOC leads. Requires active security clearance and DoD 8140 certification...Cyber
- Nightwing in Arlington, VA seeks a Cyber Action Officer to support a U... .... You will manage cyber incidents, produce official reports,... ...for rapid mitigation. The role requires 5+ years of cyber incident management... ...experience and an active TS/SCI clearance. Candidates should...Cyber
- A leading cybersecurity firm is seeking a Cloud Forensics Analyst to support onsite incident response to cyber-attacks. The role involves acquiring and analyzing computer artifacts, conducting... ...in cyber forensics and hold an active TS/SCI clearance. The position offers...Cyber
- ...Overview Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client.... ...include coordinating with SOC teams, ISSOs, and AOs, integrating... ...organizational resilience against evolving cyber threats. This position requires deep...CyberContract workFlexible hours
- ...are seeking a highly skilled Lead Incident Responder to manage and maintain... ...coordinating remediation efforts.Cyber Threat Monitoring: Develop... ...Operations Center (SOC) Tools Management: Set up and... ...standards, and accessibility requirements.Qualifications:Education:...CyberContract workFor contractorsWork at officeLocal area
- ...1435 Job Title: Incident Response Team Lead Location: Reston,... ...Clearance Level: TS (SCI Eligible) Active... ...CISSP) SUMMARY Agile Defense is seeking an experienced Cyber Incident Response... ...Operations Center (SOC) services. The IR... .... QUALIFICATIONS Required Certifications: Certified...CyberWork experience placement
$111k - $122k
...career at the company leading workforce... ...Computer Security Incident Response AnalystThis... ...role and will require you to be on-site... ...Response Analyst will respond to and investigate cyber security events... ...Top Secret/SCI security clearance... ...position requires a USA TS/SCI with...CyberFull timeWork experience placementLocal area- ...Arlington, VA to support U.S. Government missions related to cyber incident response. This role demands a minimum of 12 years in systems engineering and active TS/SCI clearance. The position involves leading technology mapping and workflow development while collaborating...Cyber
- A leading digital automation company is seeking an experienced Incident Manager to gather and analyze cyber threat intelligence. Key responsibilities include... ...management capabilities. The role requires a minimum of 2 years' experience, active TS/SCI clearance, and strong...Cyber
$175k - $235k
...Operations Center (SOC) Chief... ...Active Top Secret/SCI required Travel: 0-10... ...This position leads the Security Operations... ...— overseeing cyber defense operations,... ...serving as primary incident commander, and... ...Incident Responder (PR-CIR-001) work... ...operations at the TS/SCI level...CyberFull timeContract workFor contractorsWork experience placementFlexible hours- Responsibilities Respond to and resolve cybersecurity incidents and proactively prevent reoccurrence... ...assist recovery efforts Requirements 4+ years of experience... ...in cybersecurity or SOC environments 1+ years of... ...stakeholders, including government leads, vendors, and technical...Cyber
- ...Cybersecurity Analyst in McLean, VA to detect and respond to cyber threats using SIEM and threat... ...-focused environment. The role requires TS/SCI with poly and the ability to obtain DoD... ...-II within 6 months. You will work on incident detection, analysis, and protective technology...Cyber
$104k - $166k
...hire an experienced Incident Response Analyst (... ...Federal Strategic Cyber group. Location:... ...This role involves responding to cyber incidents... ...to meet mission requirements for incident response... ...to obtain a TS/SCI for continued employment... .... As the world’s leading mission capability...CyberContract workCurrently hiringShift work1 day per week- ...Synertex is seeking a Cyber Threat... ...recommendations for defensive operations. You'... ...and you'll play a lead role in incident analysis,... ...Clearance: TS/SCI RESPONSIBILITIES... ...analysts, incident responders, and cybersecurity... ...standards and reporting requirements. Brief senior...Cyber
- ...Small Business (SDVOSB) providing Cyber Security, Intelligence... ...Community (IC), the Department of Defense (DoD), and other federal government... ...OpenLayers. The position requires translating business needs... ...growing SDVOSB ~ Active TS/SCI clearance with CI Polygraph is...CyberFull timeMonday to FridayShift workDay shift
$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position... ...plans; support incident response activities with... ...attack chains, and defensive gaps discovered during... ...GCIH)GIAC Industrial Cyber Security Professional... ...) or CyberSec First Responder (CFR)Certified Information...CyberFull timeWork at office$120k - $165k
...Arlington, VA (Pentagon) Clearance Required: TS/SCI minimum (US Citizen)... ...support of the Department of Defense (DoD), Intelligence Community... ...Analytics is seeking a Principal Cyber Systems Engineer, SME to... ...technological superiority. You will lead the evaluation of innovative...CyberFull timeWork at office- ...support critical federal engagements in Arlington, VA. The role requires leading forensic teams, conducting cyber investigations, and delivering detailed reports on findings. Candidates must have a TS/SCI clearance, U.S. citizenship, and 5+ years in digital forensics....Cyber
$120k - $170k
...Overview We are seeking a Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst to support our... ...Contract with the Defense Threat Reduction Agency... ...Belvoir. This position requires an active Top-Secret Clearance... ...-Secret Clearance with SCI eligibility DOD 8570...CyberFull timeContract workTemporary workWork at officeLocal areaShift workWeekend workAfternoon shift$101.38k - $152.06k
...with us. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington,... ...or critical incidents to Senior SOC Analysts or SOC Leads. Document and communicate incident... ...additional voluntary or legally-required benefits. About NTT DATA NTT DATA...CyberTemporary workWork at officeRemote workFlexible hours- ...to support our nation's defense. Make an impact by... ...skilled and multi-faceted Cyber Analyst Principal for a... ...systems. This position requires the employee to report... ...Manager (ISSM), and Cyber Lead in ensuring the... ...possess a current and active TS/SCI with Polygraph. ● Certifications...CyberFull timeContract work
- ...As recognized members of the Cyber Elite, we work together in partnership... ...We are seeking an Expert Cyber Defense Analyst (TS/SCI Clearance) to analyze cyber... .... Supervise team members as required. Collaborate with a functional team lead and team members to support...Cyber
$102.5k - $188.9k
...Our Deloitte Cyber team understands the... ...identify, analyze, and respond to exploitation... ...will support cyber defense efforts by analyzing... ..., investigating incidents, assessing vulnerabilities... ...to lead projects or workstreamsAbility... ...Security+ is required.Must be legally authorized...CyberWork at office$110k - $150k
...over bureaucracy. Lead Cyber Defense Forensics Analyst Location... ...: Active Top Secret/SCI required Travel: 0-10%... ...investigations, driving incident response analysis, and... ...alongside — not above — the SOC Chief, contributing... ...investigations at TS/SCI level within SCIFs...CyberFull timeWork experience placementFlexible hours- ...security program professional to manage incident response, monitoring, and risk... ...emphasizes rapid containment, proactive defense, and coordination with government and... ...impact on critical systems. A bachelor's degree and TS clearance are required. #J-18808-Ljbffr JobtailorCyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cyber Defense Incident Responder / SOC Lead (TS/SCI Required). Be the first to apply!
Related searches
- cyber forensics Arlington, VA
- cyber Arlington, VA
- cyber sales Arlington, VA
- cyber threat intelligence analyst Arlington, VA
- self defense Arlington, VA
- defense investigator Arlington, VA
- criminal defense Arlington, VA
- defense attorney Arlington, VA
- missile defense Arlington, VA
- insurance defense attorney Arlington, VA



