Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Responder (IR Specialist)

$131.75k - $178.25k
Full-time

Gdit

Responsibilities for this Position

Location: USA VA Arlington
Full Part/Time: Full time
Job Req: RQ226609

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Interim Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Cyber Incident Response, Monitoring Tools, Network Forensics
Certifications:
None
Experience:
5 + years of related experience
US Citizenship Required:
Yes

Job Description:

Position Summary
The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high-value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on-site operations, collaborating with hunt and intelligence teams, and surging during high-tempo events.

Key Responsibilities

Incident Response Execution
Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent.
Drive containment, eradication, and recovery with affected entities and the command center.
Build and maintain evidence-based incident timelines.
Determine and document root cause when evidence supports it.

Deployed & Remote Engagement Support
Support on-site incident response, including travel as needed.
Conduct remote engagements when deployment is not required or feasible.
Operate within available monitoring and tooling, clearly noting visibility limitations.
Work directly with affected technical staff, translating findings into actionable steps.

Technical Analysis
Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement.
Use outputs from commercial detection and monitoring tools in environments outside organizational control.
Triage suspicious files and artifacts; escalate items requiring deeper analysis.
Document indicators of compromise and share with intelligence and hunt teams.

Coordination Across Mission Functions & Agencies
Maintain accurate incident status and ensure required notifications.
Collaborate with hunt teams to align response findings with hunt operations.
Work with intelligence teams to enrich findings and support broader threat understanding.
Coordinate with external responders such as federal law enforcement, National Guard, and state teams.

Documentation, Reporting & After-Action
Produce technical documentation, findings, and actionable reports meeting customer standards.
Support case file completion aligned with NCISS requirements.
Ensure rationale for response actions is preserved.
Contribute to after-action reviews and procedural improvements.

Surge Readiness
Maintain readiness to deploy or surge on short notice for major cyber events.
Support crisis action team operations during elevated tempo.
Stay current on tools, tradecraft, and mission-relevant environments.

Required Qualifications
Hands-on enterprise incident response experience, including scoping, containment, eradication, and recovery.
Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity.
Experience using commercial detection and monitoring tools in external environments.
Experience producing technical incident documentation for external stakeholders.
Ability to work directly with affected organizations during active incidents.
Willingness and ability to travel and support surge operations.
Relevant technical training, certification, or degree, plus 5 years of experience.
Active Top Secret clearance.

Preferred Qualifications
National-level incident response experience.
Experience with ICS/OT or critical infrastructure environments.
Experience coordinating multi-agency or multi-jurisdictional response.
Malware triage and basic reverse engineering skills.
Experience with flyaway kits or deployable response tooling.
Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.

GDIT Is Your Place
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace

Own Your Opportunity
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

The likely salary range for this position is $131,750 - $178,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
25-50%

Telecommuting Options:
Hybrid

Work Location:
USA VA Arlington

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans



PI286624959





Position Summary
The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high-value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on-site operations, collaborating with hunt and intelligence teams, and surging during high-tempo events.



Key Responsibilities



Incident Response Execution
Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent.
Drive containment, eradication, and recovery with affected entities and the command center.
Build and maintain evidence-based incident timelines.
Determine and document root cause when evidence supports it.



Deployed & Remote Engagement Support
Support on-site incident response, including travel as needed.
Conduct remote engagements when deployment is not required or feasible.
Operate within available monitoring and tooling, clearly noting visibility limitations.
Work directly with affected technical staff, translating findings into actionable steps.



Technical Analysis
Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement.
Use outputs from commercial detection and monitoring tools in environments outside organizational control.
Triage suspicious files and artifacts; escalate items requiring deeper analysis.
Document indicators of compromise and share with intelligence and hunt teams.



Coordination Across Mission Functions & Agencies
Maintain accurate incident status and ensure required notifications.
Collaborate with hunt teams to align response findings with hunt operations.
Work with intelligence teams to enrich findings and support broader threat understanding.
Coordinate with external responders such as federal law enforcement, National Guard, and state teams.



Documentation, Reporting & After-Action
Produce technical documentation, findings, and actionable reports meeting customer standards.
Support case file completion aligned with NCISS requirements.
Ensure rationale for response actions is preserved.
Contribute to after-action reviews and procedural improvements.



Surge Readiness
Maintain readiness to deploy or surge on short notice for major cyber events.
Support crisis action team operations during elevated tempo.
Stay current on tools, tradecraft, and mission-relevant environments.



Required Qualifications
Hands-on enterprise incident response experience, including scoping, containment, eradication, and recovery.
Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity.
Experience using commercial detection and monitoring tools in external environments.
Experience producing technical incident documentation for external stakeholders.
Ability to work directly with affected organizations during active incidents.
Willingness and ability to travel and support surge operations.
Relevant technical training, certification, or degree, plus 5 years of experience.
Active Top Secret clearance.



Preferred Qualifications
National-level incident response experience.
Experience with ICS/OT or critical infrastructure environments.
Experience coordinating multi-agency or multi-jurisdictional response.
Malware triage and basic reverse engineering skills.
Experience with flyaway kits or deployable response tooling.
Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.



GDIT Is Your Place
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace


Own Your Opportunity
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.


The likely salary range for this position is $131,750 - $178,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.



Scheduled Weekly Hours:
40



Travel Required:
25-50%



Telecommuting Options:
Hybrid



Work Location:
USA VA Arlington



Additional Work Locations:



Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.



Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.



About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.


Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc .


Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans







PI286624959

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Incident Responder (IR Specialist) in Arlington, VA vacancy
  • $172.5k - $260.1k

     ...investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud,...  ...investigative rigor, and mentor junior responders on advanced analysis technique.Support CREST...  ...certified.3-5 years in a lead or senior IR role within a large, global organization.... 
    Suggested
    Full time

    Salesforce

    Washington DC
    3 days ago
  • $53.9k - $120.1k

    Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident Response Triage IR Analyst role will work in the CIRT...  ...insider-threat presence. The Work Actively monitor and respond to cybersecurity incidents related to alerted policy violations... 
    Suggested
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture Federal Services Careers Marketplace

    Arlington, VA
    1 day ago
  •  ...guidelines and regulations.About this position: Sr. Cybersecurity Incident Response SpecialistLocation - Washington, DCThe Essential...  ...flows and application interactions to enhance SOC’s ability to respond to incidents.Prepare and manage playbooks and relevant scenarios... 
    Suggested
    Full time
    Contract work
    Local area

    Bering Straits Native Corporation

    Washington DC
    2 days ago
  •  ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing... 
    Suggested
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    1 day ago
  •  ...MIOS in Arlington, VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber threats across program networks. The role includes SIEM monitoring, incident handling, log analysis, and coordination with stakeholders to contain and recover from... 
    Suggested

    NJVC

    Arlington, VA
    1 day ago
  • Digital Global Connectors is seeking a seasoned Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The role conducts advanced incident analysis, containment, eradication, and recovery for enterprise systems, networks,... 

    Digital Global Connectors

    Mc Lean, VA
    2 days ago
  •  ...Department of Defense (DoD) customers. We are seeking a (CSSP/IR) specialist with specific skills in intrusion detection/prevention and...  ...new and emerging threats. Providing detailed triage of CSSP/IR incidents including implementing intrusion detection and prevention signatures... 
    Work at office
    Monday to Friday
    Weekend work

    Bespoke Corps LLC

    Arlington, VA
    5 days ago
  •  ...Note - Active TS/SCI Clearance is required. Description: The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This... 
    Full time
    Weekend work

    search-tactics

    Arlington, VA
    2 days ago
  • $80k - $128k

    ResponsibilitiesPeraton is currently searching for a Junior Cyber Incident Analyst - Notification Specialist - for our Federal Strategic Cyber program. Location:...  ...ticket actions and ticket submissions.Monitor, respond, and catalog targeted notification section emails as... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  • Pondurance is seeking an Incident Response Consultant to guide clients through the IR lifecycle, contain threats, and eradicate malicious activity. You will investigate intrusions, analyze TTPs, and strengthen detections across endpoints, networks, and cloud environments... 
    Remote job

    Pondurance

    Mc Lean, VA
    1 day ago
  •  ...today! Location 200 Constitution Ave NW, Suite N-1301, Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and ensure compliance with government standards for various systems. The... 
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    3 days ago
  •  ...We are seeking a skilled Incident Response Specialist to join our Cybersecurity Operations team. In this role, you will be responsible for detecting, investigating, responding to, and recovering from cybersecurity incidents affecting enterprise systems and networks. The... 

    Mybridge

    Arlington, VA
    1 day ago
  • $23.41 - $41 per hour

     ...security issues worldwide. The BAC is looking for talented incident response specialists to support our rapidly growing GSOC program. A successful...  .... You must obsess over our customers, triaging and responding to their physical security needs. This is a shift-based role... 
    Hourly pay
    Worldwide
    Flexible hours
    Shift work
    Afternoon shift

    Amazon

    Arlington, VA
    2 days ago
  • NTT DATA North America is seeking a Cyber Defense & Incident Responder in Arlington, Virginia to monitor, analyze, and respond to cybersecurity incidents. You will triage, investigate, contain, and assist in recovery, using SIEM, EDR, and threat intelligence to determine... 

    NTT DATA North America

    Arlington, VA
    5 days ago
  • S2i2 is seeking a Lead Cyber Defense Incident Responder in Arlington, VA on-site to lead a skilled team defending TS/SCI and SAP environments. The role demands hands-on threat detection, threat intelligence, and advanced incident response capabilities in highly secure... 

    S2i2, Inc

    Arlington, VA
    1 day ago
  •  ...premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post... 
    Work at office

    OneMain Financial

    Washington DC
    5 days ago
  • A cybersecurity firm is seeking a qualified Cybersecurity Service Provider/Incident Response Analyst in Arlington, VA. The ideal candidate will provide on-site support for DoD customers, possessing technical skills in intrusion detection and prevention, and will have a... 

    Bespoke Corps LLC

    Arlington, VA
    3 days ago
  •  ...Amazon Corporate Security’s BAC seeks an Incident Response Coordination Specialist to manage physical security incidents worldwide, draft communications, and coordinate with response stakeholders in a 24/7 GSOC environment. The role requires strong written reporting and... 
    Worldwide
    Shift work
    Afternoon shift

    Amazon

    Arlington, VA
    2 days ago
  •  ...Lead Consultant for the IR/Forensics Practice Employment Type: 1099/Independent Consultant...  ...The Lead Consultant will be part of the Incident Response and Forensics practice, whose...  ...forensics. As a Lead Consultant you will respond to, analyze, diagnose, and report on... 
    Remote work

    Lumifi Cyber

    Arlington, VA
    1 day ago
  • $136k - $184k

    Cyber Incident Response Team (CIRT) Lead Aug 13, 2026 $136,000 - $184,000/year Type of Requisition...  ..., and ensure the team is prepared to respond to time‑sensitive events under tight...  ...both pre and post‑tax dollars up to the IRS annual limits and receive a company match... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    General Dynamics Information Technology

    Falls Church, VA
    3 days ago
  • Edgewater Federal Solutions is seeking a Tier II Incident Response Analyst to support a federal government contract. The role requires US Citizenship and offers opportunities to work on enterprise security incidents within a government program. The ideal candidate will... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    2 days ago
  • $131.3k - $237.35k

     ...scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program.The Department...  ...program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise... 
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    1 day ago
  •  ...domains in the interest of national security. Job Title: Specialist, EO/IR Systems Engineer (Top Secret Clearance) Job Code: 39908 Job...  ...system performance and must be able to recognize and respond to anomalous conditions.The individual is expected to be able... 
    Full time
    Casual work
    Relocation
    Relocation package
    Shift work

    L3Harris Technologies

    Herndon, VA
    2 hours ago
  • Raytheon Technologies in Arlington, Virginia, is seeking a cybersecurity professional with expertise in cyber incident management. The ideal candidate will have over 5 years of relevant experience and be knowledgeable in incident response methodologies. The position requires... 

    Raytheon Technologies

    Arlington, VA
    4 days ago
  •  ...Cardiovascular Invasive Specialist 2 Inova Fairfax Medical Center is looking for a dedicated Cardiovascular Invasive Specialist 2 to join...  ...or Radiology Technology or equivalent education and experience. Preferred Requirements: ~ IR experience Inova Health System
    Immediate start
    Remote work
    Relocation package
    Flexible hours
    Shift work
    Day shift

    Inova Health System

    Falls Church, VA
    5 days ago
  •  .... Come join our team! Zantech is looking for a talented Senior Incident Response Coordinator to contribute to the success of our upcoming...  ....S. Cyber Command, and private sector partners to prepare for, respond to, and recover from significant cyber incidents,... 
    Contract work
    Local area

    Zantech

    Arlington, VA
    1 day ago
  • $150k - $190.7k

     ...grow, and make an impact. Join us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority responsible...  ...(Incidents, SecOps, CMDB, IR workflows)Drive platform reliability, resilience, and auditability... 
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    2 days ago
  • cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting the Administrative Office of the United States...  ...Technology, or a related field ~3+ years of experience in an IR role.  ~2+ years’ experience using Python and PowerShell scripts... 
    Work at office

    cFocus Software Incorporated

    Washington DC
    1 day ago
  •  ...Incident Response Analyst (Task 4 - Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro...  ...The ideal candidate has hands-on experience with enterprise IR tooling- CrowdStrike , FireEye (Trellix) , Splunk , NetWitness... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy Inc

    Washington DC
    1 day ago
  • Omniscius Consulting is seeking an experienced security professional in Washington, DC to lead incident response, triage threats, and coordinate containment and recovery. The role includes tuning SIEM dashboards, generating detailed findings, and documenting security posture... 

    Omniscius Consulting

    Washington DC
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Responder (IR Specialist). Be the first to apply!