Incident Response Lead
$107.9k - $195.05kLeidos
Description
At Leidos , we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.
If this sounds like the kind of environment where you can thrive, keep reading!
The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability.
Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis, application development, and a 24x7x365 support staff.
Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP) and is responsible for directing and coordinating detection and response activities performed by each Component SOC. Direction and coordination are achieved through a shared DHS incident tracking system and other means of coordination and communication.
Primary Responsibilities
In-depth knowledge of each phase of the Incident Response life cycle
Expertise in Operating Systems (Windows/Linux) operations and artifacts
Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)
Ability to recognize suspicious activity/events, common attacker TTPs, perform logical analysis and research to determine root cause and scope of Incidents
Drive implementation and improvement of new tools, capabilities, frameworks, and methodologies
Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC operations
Promote and drive implementation of automation and process efficiencies
Familiarity with Cyber Kill Chain and ATT&CK Framework and how to leverage in Security Operations
Provide guidance and mentorship to improve analyst skill sets and ensure delivery of high quality analysis and work products
Establish trust and business relationships with customer and other relevant stakeholders
Bachelor's Degree and 8-12 years of experience in a technical discipline.
4+ years of supervising and/or managing teams
5+ years of intrusion detection and/or incident handling experience
CISSP and SANS GCIH or GCIA required upon start
Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise
Significant experience supervising and leading employees of various labor categories and technical skill levels in efforts similar in size and scope to a mature Security Operation
Mature understanding of industry accepted standards for incident response actions and best practices related to SOC operations;
Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings.
Strong analytical and troubleshooting skills.
Must be a US Citizen.
Must hold active TS/SCI security clearance to be considered
Preferred Qualifications
Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization including prior experience performing large-scale incident response.
Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:
August 25, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $107,900.00 - $195,050.00
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos' name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on click.appcast.io .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission ( .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
REQNUMBER: R-00190531
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.
$140k - $150k
...Job DescriptionEverforth ECS is seeking an Incident Response Leadto work in ourWashington, DCoffice /remote. The role is contingent upon additional... ...funding.We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a...SuggestedRemote work- ...A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...Suggested
- ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data...SuggestedContract work
$172.5k - $260.1k
...heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right... ...of Salesforce.The ExperienceSalesforce's Computer Security Incident Response Team (CSIRT) provides 24x7x365 security monitoring and rapid...SuggestedFull timeMonday to FridayShift workNight shift$262k - $364k
...network security and security protocols. 10 years of experience leading teams in a technical capacity or leading technical risk... ...of AI-driven exploitation and enablement, and providing rapid response and threat hunting for developing global exploitation and threats...Suggested- ...client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage... ...integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures...Hourly payFull timeContract workLocal area2 days per week3 days per week
- ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security... ...will have extensive experience in risk management, incident response, and vulnerability assessment within a government contract setting...Contract workFor contractorsWork at officeLocal area
- ...highest form of third-party validation. is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the... ...before they occur.Communicate plans and responses to incidents to customer leadership, providing them confidence that cybersecurity...Full timeContract workLocal area
$172.5k - $260.1k
...to level-up your career at the company leading workforce transformation in the agentic... ...investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud,... ...You Have:8+ years in security incident response with consistent hands-on technical case...Full time- ...Description Job Description Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential... ...the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure...Contract workFlexible hours
- ...Geospatial & Cloud Analytics (GCA) is seeking a mission-driven Rapid Response Team Lead to support the high-priority, time-sensitive operational... ...activities, VIP support in GO/Flag quarters, and immediate incident response across critical infrastructure. The ideal...Full timeContract workImmediate startWorldwideNight shift
$82k - $92k
...Incident & Crisis Management Support Support the coordination and facilitation of response activities during operational disruption events Assist with incident communications, stakeholder updates, and response tracking Maintain and update incident management playbooks...Full timeTemporary workLocal areaVisa sponsorshipWork visaFlexible hours- ...diversity. The Enterprise Operational Resilience team is looking to hire an Incident / Crisis Management Lead to help drive the continuous enhancement of the crisis event management response structure and play a lead role in facilitating and coordinating large scale...Temporary workLocal areaVisa sponsorshipWork visaFlexible hours
- ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead will oversee 24x7x3... ...enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security...Full time
$175.1k - $236.9k
...security leader, you will own building and managing a team of incident managers and technical leaders, fostering a strong team... ...level of ownership and accountability is a must.Key job responsibilities- Build and lead a high-performing team of security engineers, focusing on...Remote workFlexible hoursShift workNight shift$175.1k - $236.9k
...solutions that are no-brainers to buy and easy to use.AWS Security Incident Response is looking for a Security Manager who combines deep technical... ...VPs of Security, and their teams — to communicate findings, lead post-incident reviews, advise on security posture, and build...WorldwideFlexible hoursShift work$70.33k - $90.66k
...field-based lessons into broader systems and policy change. Primary Function: This position primarily supports the Eviction Data Response Network (EDRN), a groundbreaking initiative to create the country’s first large-scale eviction data infrastructure and use that...Full timeWork at officeLocal areaImmediate startWork from home$114.1k - $268.18k
..., a world-class training facility, and leading market tools, we help our people continue... ...our Managed Services practice. Responsibilities: Manage cloud security posture across... ...governance managed services, including incident, problem, and service request management...Full timeH1bLocal area- ...Description: The Access Control Supervisor is responsible for overseeing the daily operations of... ...systems, personnel accountability, incident response activities, and customer service... ...of 1-2 years of supervisory, team lead, or shift lead experience preferred....For contractorsWork at officeShift workRotating shift
- ..., a world-class training facility, and leading market tools, we help our people continue... ...join our Federal Advisory practice. Responsibilities: Lead the architecture, deployment,... ...PAM operations and remediation of incidents Provide strategic leadership in the...Full timeLocal area
- ...Position Overview: The Ground Ramp Lead oversees daily ramp operations,... ...the best in the industry. Job Responsibilities: ~ Lead and supervise ramp... ...~ Report any hazards, near misses, incidents, accidents, or dangerous occurrences to...Full timePart timeImmediate start
$100k - $124k
...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical... ...- 2:00 PM, EST), Tuesday - Saturday Responsibilities: Detect, classify, process, track,... ...and report on cyber security events and incidents. Perform advanced in-depth analysis...Contract workLocal areaRemote workAll shiftsShift workDay shift$86.6k - $181.8k
...Team Lead- Network Operations – Tier 2The Enterprise Communications Services 3 (ECS3... ...role the Network Administrator will be responsible for:Conduct approved network changes to... ...network components to research errors, incidents, problems and to perform incident analysis...Contract workWork experience placementRemote workFlexible hours- ...buses. The Fleet Maintenance Manager is responsible for supervising approximately seven to... ...Maintenance Leadership: Ability to lead and supervise fleet maintenance operations... ...vehicle breakdowns, accidents, environmental incidents, and emergency maintenance situations....Work at officeLocal area
- ...and a variety of revenue cycle outsource capabilities. Team leads supervise and promote teamwork to Patient Account Representatives... ...R account remediation, productivity, and quality outputs. Responsibilities: Manages assigned staff and provides supervision and...
$131.3k - $237.35k
...Description Primary Responsibilities. Serve as the subject matter expert in the areas of... ...architecture and design activities. Lead cloud and network architecture and design... ...local law enforcement and report the incident to the U.S. Federal Trade Commission (...Local areaImmediate start- ...Description Job Description Position Summary The Cybersecurity Lead will serve as a “Dual-Hat” role providing senior technical... ...Lead, this role will provide expert oversight for the entire incident response lifecycle, from initial detection and log correlation within...Local area
- ...Overview SecurePro is seeking experienced Lead and Senior Information System Security... ..., security impact analysis, incident coordination, and audit support. This... ...experience and qualifications. Key Responsibilities Execute the NIST SP 800-37 Rev. 2 RMF...Contract work
- cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (... ...confirmed or suspected findings to the Cybersecurity Triage and Incident Response teams in accordance with the Judiciary SOC Incident Response...Full timeWork at office
$112k - $179k
...Responsibilities Peraton is now Hiring: TASO Team Lead – Federal Strategic Cyber Programs.Location: Arlington, VAPosition Overview:Peraton is seeking a highly... ...hunting, malware analysis, digital forensics, and incident response within Department networks.Key Responsibilities...Contract workImmediate startShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Lead. Be the first to apply!




