Lead Cyber Defense Incident Responder On-site - TS/SCI
S2i2 Inc
Job Description
Job Description
Job TitleLead Cyber Defense Incident ResponderClearanceTS/SCI (active, required)LocationArlington, VA On-siteSalary Range$175,000 to $180,000Certification RequiredDoD 8570 / DoD 8140 IAT Level IIOne of the following: Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalentApplication DeadlineAugust 31, 2026 Description:The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.Duties and Responsibilities- Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.- Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.- Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.- Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.- Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.- Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.- Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.- Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.- Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).- Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence. Minimum Qualifications and Requirements- Bachelor's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.- Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.- Demonstrated leadership skills, preferably in a formal leadership role.- Scripting experience.- TS/SCI clearance is required.Knowledge, Skills, and Abilities- Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.- Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.- Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.- Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.- Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.- Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).- Technical mentorship: experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.- Advanced forensics: deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.- Malware and script analysis: high-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.- Superior research capabilities: exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.- Executive communication: excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership.- Technical translation: ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers.- Project and case management: proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.- Crisis management: ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.- Collaboration: well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.- Attention to detail: excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks. About S2i2S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company.We are proud to include:Support to achieve professional certifications and degreesLeadership that is accessible to all employeesRegular company updatesClient networking social engagementsMonthly team-building activities (past examples: Top Golf)Supporting our community - including veteransAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
$111k - $122k
...career at the company leading workforce... ...Computer Security Incident Response AnalystThis... ...you to be on-site in Northern Virginia... ...Response Analyst will respond to and investigate cyber security events... ...Top Secret/SCI security clearance... ...position requires a USA TS/SCI with...CyberWebsiteFull timeWork experience placementLocal area$104k - $166k
...hire an experienced Incident Response Analyst (ICS... ...' Federal Strategic Cyber group. Location: On‑site in Arlington,... ...This role involves responding to cyber incidents across... ...Ability to obtain a TS/SCI for continued employment... .... As the world’s leading mission capability integrator...CyberWebsiteContract workCurrently hiringShift work1 day per week- ...Chenega Corporation is seeking a Cyber Defense Incident Responder (Advanced) in Arlington, VA. This role requires... .... The ideal candidate will lead a team, guide analysts, and contribute... ...experience in threat hunting and hold a TS/SCI clearance. Here, you'll excel in a collaborative...Cyber
- ...INFRASTRUCTURE SERVICE LEAD (ISL) YOUR... ...to support national defense. Your work will help... ...and initial incident assessment Monitor... ...regional operations, cyber teams, network teams... ...enterprise monitoring sites, and collaboration... ...CLEARANCE: Active TS/SCI clearance with a...CyberWebsiteNight shift
$101.38k - $152.06k
...with us. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia... ...to Senior SOC Analysts or SOC Leads. Document and communicate incident findings... ...locally to NTT DATA offices or client sites. This ensures we can provide timely...CyberWebsiteTemporary workWork at officeRemote workFlexible hours$170k - $180k
...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our... ...’s (CISA) Joint Cyber Defense Collaborative (JCDC). The... ...to plan, share, and respond to cyber threats in real time... ...Top Secret Clearance and SCI eligibleOn-site 3-5 days per week in Arlington...CyberWebsiteWork at office3 days per week$164.38k - $189.75k
...Specialist Senior to engage in defense and security efforts... ...Pacific theater. You will lead the development and execution... ...Clearance: Active TS/SCI w/ polygraph On Customer Site Desired Education and... ...modernization, AI/ML, Cloud, Cyber and application development...CyberWebsiteTemporary workImmediate startRemote workWorldwideFlexible hours$90k - $130k
...Clearance Requirement: TS/SCI Clearance Required... ...remediation plans; support incident response activities... ...novel attack chains, and defensive gaps discovered during... ...(GCIH)GIAC Industrial Cyber Security Professional... ...) or CyberSec First Responder (CFR)Certified Information...CyberWebsiteFull timeWork at office$120k - $165k
...Pentagon) Clearance Required: TS/SCI minimum (US Citizen) Employment... ...support of the Department of Defense (DoD), Intelligence Community,... ...Analytics is seeking a Principal Cyber Systems Engineer, SME to... ...technological superiority. You will lead the evaluation of innovative...CyberWebsiteFull timeWork at office- ...opportunity to support national defense. Your work will help keep... ...Collaborate with engineering, cyber, and operations teams to validate... ...Ensure high availability, site resilience, and optimized performance... ..., etc.) CLEARANCE: Active TS/SCI clearance with a favorable...CyberWebsite
- ...to support our nation's defense. Make an impact by... ...skilled and multi-faceted Cyber Analyst Principal for a... ...to report full time on site in McLean, VA. The... ...Manager (ISSM), and Cyber Lead in ensuring the... ...possess a current and active TS/SCI with Polygraph. ● Certifications...CyberWebsiteFull timeContract work
$73.45k - $132.78k
...Administrator in our INTEL SECTOR- Cyber & Analytics Business Area... ...maintenance of a company site in Alexandria.Primary... ...systems and will respond to hardware and software incidents impacting local users. She... ...Clearance Required: Must have TS/SCI with Polygraph.Preferred Qualifications...CyberWebsiteFull timeWork at officeLocal areaImmediate startRemote workFlexible hours- ...Own your career as a Cyber Security Analyst at GDIT... ...strong lines of cyber defense using cutting-edge technologies... ...case evidence and incident reports. Work on... ...Security Clearance Level: TS/SCI clearance and ability to... ...: 100% On Customer Site Bolling AFB, Washington...CyberWebsiteShift workDay shift
- ...personal impact as a Cyber Security Project... .... Be the change, lead our change – join... ..., analyzing, and responding to security incidents across enterprise... ...with cyber defense teams to mitigate... ...Clearance Level : TS/SCI with active polygraph... ...VA - On Customer Site GDIT IS YOUR...CyberWebsite
- ...Description cFocus Software seeks a Lead Information System Security... ...to join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications...Website
$106.68k - $246.98k
...Security Clearance: TS/SCI Level of Experience... ...Systems comprises cyber and mission IT; electronic... ...security and defense objectives.This... ...systems. Will analyze site survey reports, recommend... ...assist operations leads in creating... ...accommodation will be responded to from this email...CyberWebsiteFull timeWork experience placementLocal areaWorldwide- ...Description cFocus Software seeks a Chief Engineer/Lead Architect to join our program supporting the Defense Intelligence Agency (DIA). This position is on site; in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications:...Website
- ...Owned Small Business (SDVOSB) providing Cyber Security, Intelligence Analysis, Financial... ...Intelligence Community (IC), the Department of Defense (DoD), and other federal government... ...growth within a growing SDVOSB ~ Active TS/SCI clearance with CI Polygraph is a must...CyberFull timeMonday to FridayShift workDay shift
- ...currently seeking an Incident Response Expert... ...Requirements Active TS/SCI clearance with... ...directly relevant cyber incident response... ...notice Experience leading or mentoring technical... ...Computer Network Defense (CND) policies, procedures... ...or Incident Responder GIAC...Cyber
$80k - $128k
...searching for a Junior Cyber Incident Analyst - Notification... ...program. Location: On site in Arlington, VAIn... ...submissions.Monitor, respond, and catalog targeted... ...the ability to obtain a TS/SCI.In addition, the selected... ...galaxy. As the world’s leading mission capability...CyberWebsiteContract workShift work$101.38k - $152.06k
...apply now. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington,... ...incidents to Senior SOC Analysts or SOC Leads. # Document and communicate incident... ...to NTT DATA offices or client sites. This ensures we can provide timely and...CyberWebsiteTemporary workWork at officeRemote workFlexible hours- DescriptionCyber Security Engineer - TS/SCI Xcelerate Solutions is seeking a Cyber Security Engineer working... ...work is conducted on-site at our client location in... ...DoD security guidance.Lead the integration of RMF... ...systems.Support security incident response and forensics...CyberWebsiteContract workRemote workFlexible hours
$110k - $140k
...Belvoir, VA Clearance Required: TS/SCI minimum (US Citizen)... ...support of the Department of Defense (DoD), Intelligence Community,... ...Intelligence Solutions Integrator (Team Lead) to support the Data... ...Certification (GSEC), GIAC Certified Incident Handler (GCIH), Cisco...WebsiteFull timeContract workFor contractors$155k - $180k
...About Agile Defense At Agile Defense we know that action defines the... ...Requisition #: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified... ...Defense is seeking experienced Cyber Incident Response Team Lead to...CyberWork experience placement$160k - $200k
...talented Senior Cyber Threat... ...fortifying our defenses against cyber threats... ...and spearheading incident response initiatives... ...is based on-site in our... ...prevent, detect, and respond to cyber incidents... ...posture.Lead incident response... ...independently.Active TS/SCI security...CyberWebsitePermanent employmentFull timeWork at officeLocal areaRemote workWorldwide- ...Overview Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder... ...to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,...CyberContract workFlexible hours
- ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and... ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat Dashboard...CyberContract workFor contractorsWork at officeLocal area
$142.79k
...Top Secret/SCI Clearance Level... ...relocate to another site in the National... ...and implements incident response procedures... ...Level: Active TS/SCI clearance with... ....S. government, defense and intelligence... ..., offering leading mission-ready capabilities... ...in AI, cloud, cyber and software...CyberWebsiteTemporary workSummer workWork at officeLocal areaImmediate startRemote workWorldwideRelocationFlexible hours- ...Description Job Description We are looking to hire a Senior Cyber Defense Incident Responder to support a full range of cyber security services on a... ...external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain...CyberWebsiteLong term contractPermanent employmentFull timeImmediate start
$102.5k - $188.9k
...Summary Our Deloitte Cyber team understands the... ...identify, analyze, and respond to exploitation... ...you will support cyber defense efforts by analyzing threat... ...activity, investigating incidents, assessing vulnerabilities... ...to lead projects or workstreamsAbility...CyberWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cyber Defense Incident Responder On-site - TS/SCI. Be the first to apply!
- cyber Arlington, VA
- cyber sales Arlington, VA
- cyber forensics Arlington, VA
- cyber threat intelligence analyst Arlington, VA
- site services specialist Arlington, VA
- construction site safety Arlington, VA
- site leader Arlington, VA
- official site Arlington, VA
- website content developer Arlington, VA
- IT site lead Arlington, VA


