Incident Responder (IR Specialist)
$131.75k - $178.25kSocket
Type of Requisition Regular Clearance Level Must Currently Possess Interim Secret Clearance Level Must Be Able to Obtain Top Secret/SCI Public Trust/Other Required None Job Family Cyber and IT Risk Management Job Qualifications Skills Cyber Incident Response, Monitoring Tools, Network Forensics Certifications None Experience 5 + years of related experience US Citizenship Required Yes Position Summary The Incident Responder provides hands‑on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on‑site operations, collaborating with hunt and intelligence teams, and surging during high‑tempo events. Key Responsibilities Incident Response Execution Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent. Drive containment, eradication, and recovery with affected entities and the command center. Build and maintain evidence‑based incident timelines. Determine and document root cause when evidence supports it. Deployed & Remote Engagement Support Support on‑site incident response, including travel as needed. Conduct remote engagements when deployment is not required or feasible. Operate within available monitoring and tooling, clearly noting visibility limitations. Work directly with affected technical staff, translating findings into actionable steps. Technical Analysis Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement. Use outputs from commercial detection and monitoring tools in environments outside organizational control. Triage suspicious files and artifacts; escalation items requiring deeper analysis. Document indicators of compromise and share with intelligence and hunt teams. Coordination Across Mission Functions & Agencies Maintain accurate incident status and ensure required notifications. Collaborate with hunt teams to align response findings with hunt operations. Work with intelligence teams to enrich findings and support broader threat understanding. Coordinate with external responders such as federal law enforcement, National Guard, and state teams. Documentation, Reporting & After‑Action Produce technical documentation, findings, and actionable reports meeting customer standards. Support case file completion aligned with NCISS requirements. Ensure rationale for response actions is preserved. Contribute to after‑action reviews and procedural improvements. Surge Readiness Maintain readiness to deploy or surge on short notice for major cyber events. Support crisis action team operations during elevated tempo. Stay current on tools, tradecraft, and mission‑relevant environments. Required Qualifications Hands‑on enterprise incident response experience, including scoping, containment, eradication, and recovery. Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity. Experience using commercial detection and monitoring tools in external environments. Experience producing technical incident documentation for external stakeholders. Ability to work directly with affected organizations during active incidents. Willingness and ability to travel and support surge operations. Relevant technical training, certification, or degree, plus 5 years of experience. Active Top Secret clearance. Preferred Qualifications National‑level incident response experience. Experience withICS/OT or critical infrastructure environments. Experience coordinating multi‑agency or multi‑jurisdictional response. Malware triage and basic reverse engineering skills. Experience with flyaway kits or deployable response tooling. Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar. GDIT Is Your Place Growth: AI-powered career tool that identifies career steps and learning opportunities Support: An internal mobility team focused on helping you achieve your career goals Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off Community: Award-winning culture of innovation and a military-friendly workplace Own Your Opportunity Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters. The likely salary range for this position is $131,750 - $178,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours 40 Travel Required 25-50% Telecommuting Options Hybrid Work Location USA VA Arlington Additional Work Locations Total Rewards at GDIT Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post‑tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans #J-18808-Ljbffr Socket
- General Dynamics IT seeks an Incident Responder to provide hands-on cyber incident response across federal Civilian agencies and critical infrastructure... ...travel. Qualified candidates have 5+ years in enterprise IR, host and network forensic analysis, experience with...SuggestedRemote work
- General Dynamics Information Technology in Arlington, VA seeks an experienced Incident Responder to perform hands-on cyber incident response across critical infrastructure and government partners. You will handle high‑value intrusions, drive containment and eradication...SuggestedRemote work
$172.5k - $260.1k
...investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud,... ...investigative rigor, and mentor junior responders on advanced analysis technique.Support CREST... ...certified.3-5 years in a lead or senior IR role within a large, global organization....SuggestedFull time$53.9k - $120.1k
Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident Response Triage IR Analyst role will work in the CIRT... ...insider-threat presence. The Work Actively monitor and respond to cybersecurity incidents related to alerted policy violations...SuggestedWork experience placementLive inWork at officeLocal area$172.5k - $260.1k
...right place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce is seeking a Lead Incident Responder for our GovCloud Computer Security Incident Response Team (CSIRT). The CSIRT provides 24x7x365 security monitoring and rapid...SuggestedFull timeMonday to FridayAfternoon shift- ...Department of Defense (DoD) customers. We are seeking a (CSSP/IR) specialist with specific skills in intrusion detection/prevention and... ...new and emerging threats. Providing detailed triage of CSSP/IR incidents including implementing intrusion detection and prevention signatures...Work at officeMonday to FridayWeekend work
- ...MIOS in Arlington, VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber threats across program networks. The role includes SIEM monitoring, incident handling, log analysis, and coordination with stakeholders to contain and recover from...
- ...solving people-person, apply today! Location: Washington, DC Position Overview: We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and ensure compliance with government standards for various systems. The...Contract workFor contractorsWork at officeLocal area
- Digital Global Connectors is seeking a seasoned Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The role conducts advanced incident analysis, containment, eradication, and recovery for enterprise systems, networks,...
- ...Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing leadership and direction...Contract workFlexible hours
- ...guidelines and regulations.About this position: Sr. Cybersecurity Incident Response SpecialistLocation - Washington, DCThe Essential... ...flows and application interactions to enhance SOC’s ability to respond to incidents.Prepare and manage playbooks and relevant scenarios...Full timeContract workLocal area
- Pondurance is seeking an Incident Response Consultant to guide clients through the IR lifecycle, contain threats, and eradicate malicious activity. You will investigate intrusions, analyze TTPs, and strengthen detections across endpoints, networks, and cloud environments...Remote job
- ...We are seeking a skilled Incident Response Specialist to join our Cybersecurity Operations team. In this role, you will be responsible for detecting, investigating, responding to, and recovering from cybersecurity incidents affecting enterprise systems and networks. The...
$23.41 - $41 per hour
...security issues worldwide. The BAC is looking for talented incident response specialists to support our rapidly growing GSOC program. A successful... .... You must obsess over our customers, triaging and responding to their physical security needs. This is a shift-based role...Hourly payWorldwideFlexible hoursShift workAfternoon shift$80k - $128k
ResponsibilitiesPeraton is currently searching for a Junior Cyber Incident Analyst - Notification Specialist - for our Federal Strategic Cyber program. Location:... ...ticket actions and ticket submissions.Monitor, respond, and catalog targeted notification section emails as...Contract workShift work$165k - $180k
Job Title Lead Cyber Defense Incident Responder Clearance TS/SCI (active, required) Location Arlington, VA On-site Salary Range $165,000 to $180,000 Certification Required DoD 8570 / DoD 8140 IAT Level II; One of the following: Security+ CE, CCNA-Security, CySA+, GICSP...Weekend work- A prominent government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role involves leading incident response efforts, conducting annual Security Control Assessments...For contractors
- NTT DATA North America is seeking a Cyber Defense & Incident Responder in Arlington, Virginia to monitor, analyze, and respond to cybersecurity incidents. You will triage, investigate, contain, and assist in recovery, using SIEM, EDR, and threat intelligence to determine...
- ...Operations Center (SOC) Officer in Washington, D.C. This position is fully in-person and requires monitoring, detecting, and responding to security incidents affecting people, facilities, assets, and operations. The SOC Analyst will monitor CCTV, access control, intrusion...
- Diligent Consulting Inc is seeking a Cyber Security Incident and Event Management/Elastic Specialist in Washington, DC. The role requires a clear understanding... ...designing data ingestion, integrating Elastic, and responding to cybersecurity threats. Experience with NIST 800-5...
- ...Medical Center is looking for a dedicated Cardiovascular Invasive Specialist 2 to join the Interventional Radiology team. This role will be... ...experience. \n \n \n Preferred Requirements: \n \n ~ IR experience \n About Us\n We are Inova, Northern Virginia’s...Immediate startRemote workRelocation packageFlexible hoursShift workDay shift
- ...premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post...Work at office
- A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a...
- ...Amazon Corporate Security’s BAC seeks an Incident Response Coordination Specialist to manage physical security incidents worldwide, draft communications, and coordinate with response stakeholders in a 24/7 GSOC environment. The role requires strong written reporting and...WorldwideShift workAfternoon shift
- ...Lead Consultant For Incident Response And Forensics Practice Location: Scottsdale, AZ preferred... ...forensics. As a Lead Consultant you will respond to, analyze, diagnose, and report on... ...Consultants must also be able to develop IR Plans and Playbooks and run IR Tabletop...Remote work
- Edgewater Federal Solutions is seeking a Tier II Incident Response Analyst to support a federal government contract. The role requires US Citizenship and offers opportunities to work on enterprise security incidents within a government program. The ideal candidate will...Contract work
- TikTok USDS Joint Venture LLC is seeking a proactive IR Analyst based in Washington, DC, to monitor, investigate, contain, and recover... ...SOC team that collaborates with global counterparts to drive incident response and post-incident analysis. Responsibilities include leading...
- ...defense tech company seeking a Senior SecOps Analyst to monitor and respond to threats across endpoints, cloud, and SaaS. You’ll develop detection signatures, participate in threat modeling, and lead incident response as needed. As part of the Detection and Response team,...
$90k - $165k
Change Management & CX Specialist - IRS The Position: We are looking for eager, driven candidates with experience in people management, communication, facilitation, problem-solving, and analysis to guide our teams in developing impactful solutions for our Federal clients...Full timeWork experience placementWork at officeRemote workWork from homeFlexible hoursNight shift$130k - $152.5k
...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United States; Chicago, IL, United States... ...by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance...Work at officeLocal areaWork from home3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Responder (IR Specialist). Be the first to apply!
- cost specialist Arlington, VA
- strategic sourcing specialist Arlington, VA
- absence management specialist Arlington, VA
- authorization specialist Arlington, VA
- treasury specialist Arlington, VA
- workforce management specialist Arlington, VA
- wellness specialist Arlington, VA
- helpdesk specialist Arlington, VA
- program eligibility specialist Arlington, VA
- central scheduling specialist Arlington, VA


