Incident Commander & Incident Response Lead
Defianx
Job Description
The Incident Commander serves as the senior operational leader during cybersecurity incidents and is responsible for directing, coordinating, and managing all response activities throughout the incident lifecycle. This position acts as the central decision-maker during major cyber events, ensuring that technical teams, business stakeholders, executive leadership, and external partners operate in a coordinated and effective manner. The Incident Commander leads incident response efforts involving ransomware, data breaches, cloud compromises, insider threats, business email compromise, advanced persistent threats, and other high-impact security incidents. The role is responsible for establishing response priorities, coordinating technical investigations, managing escalation activities, directing containment and recovery actions, and ensuring timely communication with executive leadership and stakeholders. The Incident Commander serves as the bridge between technical teams and organizational leadership by translating complex technical findings into actionable business information. The position oversees incident status reporting, executive briefings, operational decision-making, forensic coordination, threat intelligence integration, and post-incident reviews. The Incident Commander is ultimately accountable for ensuring incidents are managed efficiently, risks are minimized, and business operations are restored as quickly and safely as possible. Requirements The candidate must have a minimum of Secrete Clearance .
Candidates must possess extensive experience leading cybersecurity incident response operations within enterprise, government, defense, critical infrastructure, or managed security service environments. The successful candidate should demonstrate strong expertise in incident response, crisis management, cyber defense operations, threat intelligence, digital forensics coordination, and executive communications. The candidate must have experience managing complex security incidents involving multiple teams, technologies, stakeholders, and business units. Strong knowledge of incident handling methodologies, cyber attack lifecycle, ransomware response, breach management, cloud security incidents, and enterprise security operations is required. Experience coordinating technical teams during high-pressure situations while maintaining operational awareness and decision-making discipline is essential. The position requires exceptional leadership, communication, and organizational skills. Candidates must be capable of delivering executive briefings, managing stakeholder expectations, facilitating crisis communications, and translating technical information into business-focused recommendations. Experience coordinating forensic investigations, threat intelligence activities, legal considerations, regulatory reporting, and recovery operations is highly desirable. Preferred certifications include CISSP, GCIH, GCFA, CISM, CASP+, PMP, ITIL, or equivalent industry-recognized certifications. Equivalent experience leading major cybersecurity incidents, crisis response operations, or cyber defense missions may be considered in lieu of specific certifications. Core Skills
The Incident Commander serves as the senior operational leader during cybersecurity incidents and is responsible for directing, coordinating, and managing all response activities throughout the incident lifecycle. This position acts as the central decision-maker during major cyber events, ensuring that technical teams, business stakeholders, executive leadership, and external partners operate in a coordinated and effective manner. The Incident Commander leads incident response efforts involving ransomware, data breaches, cloud compromises, insider threats, business email compromise, advanced persistent threats, and other high-impact security incidents. The role is responsible for establishing response priorities, coordinating technical investigations, managing escalation activities, directing containment and recovery actions, and ensuring timely communication with executive leadership and stakeholders. The Incident Commander serves as the bridge between technical teams and organizational leadership by translating complex technical findings into actionable business information. The position oversees incident status reporting, executive briefings, operational decision-making, forensic coordination, threat intelligence integration, and post-incident reviews. The Incident Commander is ultimately accountable for ensuring incidents are managed efficiently, risks are minimized, and business operations are restored as quickly and safely as possible. Requirements The candidate must have a minimum of Secrete Clearance .
Candidates must possess extensive experience leading cybersecurity incident response operations within enterprise, government, defense, critical infrastructure, or managed security service environments. The successful candidate should demonstrate strong expertise in incident response, crisis management, cyber defense operations, threat intelligence, digital forensics coordination, and executive communications. The candidate must have experience managing complex security incidents involving multiple teams, technologies, stakeholders, and business units. Strong knowledge of incident handling methodologies, cyber attack lifecycle, ransomware response, breach management, cloud security incidents, and enterprise security operations is required. Experience coordinating technical teams during high-pressure situations while maintaining operational awareness and decision-making discipline is essential. The position requires exceptional leadership, communication, and organizational skills. Candidates must be capable of delivering executive briefings, managing stakeholder expectations, facilitating crisis communications, and translating technical information into business-focused recommendations. Experience coordinating forensic investigations, threat intelligence activities, legal considerations, regulatory reporting, and recovery operations is highly desirable. Preferred certifications include CISSP, GCIH, GCFA, CISM, CASP+, PMP, ITIL, or equivalent industry-recognized certifications. Equivalent experience leading major cybersecurity incidents, crisis response operations, or cyber defense missions may be considered in lieu of specific certifications. Core Skills
- Incident Response Leadership
- Crisis Management
- Executive Briefings and Communications
- Threat Intelligence Integration
- Digital Forensics Coordination
- Major Incident Management
- Cybersecurity Operations
- Risk Assessment and Decision Making
- Stakeholder Management
- Recovery and Business Continuity Coordination
- Regulatory and Reporting Awareness
- Cross-Functional Team Leadership
Vacancy posted 3 hours ago
Similar jobs that could be interesting for youBased on the Incident Commander & Incident Response Lead in McLean, VA vacancy
- ...physical and technical security services. The Custodial Lead is responsible for overseeing custodial operations within a secure... ...escalate concerns as appropriate Immediately report security incidents, safety hazards, or suspicious activity Support emergency...SuggestedContract workImmediate start
$7.5k
...Authorization And Accreditation Lead Location: McLean / Herndon / Reston, VA (Northern Virginia Territory) Security Clearance... ..., cybersecurity compliance, IT system troubleshooting, and incident response OR High School Diploma and eight (8) years of combined...SuggestedWork experience placementWork at officeImmediate startFlexible hours- ...Overview The Cloud Platform Lead supports the United States Space Force (USSF... ...Digital Environment (IDE) platform. Responsibilities Secure digital environment operations... ...system hardening; STIG awareness; Provide incident support and maintain platform...SuggestedTemporary workImmediate startFlexible hours
$7.5k
...are looking for a Systems Administrator Lead to join our program supporting a key government customer. This individual is responsible application design, development and deployment... ..., IT system troubleshooting, and incident response OR High School Diploma and five...SuggestedWork experience placementImmediate startFlexible hours- ...The candidate will engage in hands-on, mission-driven work. Responsibilities span the full solution lifecycle—from design and prototyping... ...APIs, and dashboards to support event correlation, alerting, incident response, capacity planning, trend analysis, and service reliability...SuggestedWork experience placementRelocation
- ...comprehensive solutions that enable their mission outcomes. Roles & Responsibilities: MITRE's Intelligence Network Services department is... ...APIs, and dashboards to support event correlation, alerting, incident response, capacity planning, trend analysis, and service...Work experience placementLocal areaRelocation
- ...VA DCJS License #11-1017 TX DPS License #: B04096301 Responsibilities The selected candidate will perform various security duties... ...around building. Reporting of all pertinent issues and incidents to the operations manager, the client and other Admiral/ADM...Contract workWork experience placementWork at office
$17 - $27.75 per hour
...Ambassador embodying of Coach values and increasing brand awareness Leads implementation of Company initiatives and support full... ...and successes; fosters open dialogue; lets people finish and be responsible for their work; defines success in terms of the whole team; creates...Minimum wageShift work- ...seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and... ...documentation are accurate, complete, and defensible. Key Responsibilities Plan and Coordinate Assessments (Primary) ~...For contractorsRemote work
$22.88 per hour
...start your career with SecTek today! We are currently seeking a Full-Time Unarmed Lead Supervisor for our client. Job Skills / Requirements Our Assistant Supervisors are responsible for providing quality physical security at the client site. Duties include, but...Full timeContract workPart timeShift workNight shiftWeekend work- ...community as needed. The RN Supervisor is responsible for overseeing nursing staff, supporting... .... If you are passionate about leading teams, supporting residents, and making... ...accurate and timely documentation of care and incidents Support staff training, mentoring,...Relief
$197.3k - $225.1k
...environment to build and deliver industry leading ethical hacking capabilities to... ...most effectively address the threats. Responsibilities: Lead "Defense Improvement Analysis"... ...threat detection engineering, threat hunt, incident response, forensics ~4+ years of...Full timePart timeH1bLocal area- ...security agencies, federal buildings, healthcare facilities, and leading commercial clients in Washington D.C and across the nation... ...the CBA for Local 99. #EGS #LI-NS1 Essential Duties & Responsibilities: • Supervise and assist with the maintenance of site equipment...For subcontractorLocal area
- ...including all required systems start-ups, required cash handling, and ensuring the floor and stock room are ready for the business day. Responsible for opening back door of store for deliveries. Completes product returns, order voids, customer refunds, cash drops to the...Work experience placementSeasonal workLocal areaShift work
- ...MITRE is seeking an experienced contracts professional to lead and support day-to-day contract execution activities across a... ...flexible enough to support other FFRDCs as needed. Roles & Responsibilities: Provide cradle-to-grave contract administration for one...Contract workWork experience placementWork at officeLocal areaFlexible hours
$167k - $251k
...model governance, and data-driven oversight while developing and leading talent in a fast-paced, mission-critical environment. Our... ...Financial Risk team within the Enterprise Risk Division is responsible for oversight and effective challenge of the company's most important...Full timeLocal area$20 - $23 per hour
...Experience, is seeking a part-time Guest Experience Communication Lead to support guest communication efforts for Hershey Super Sweet... .... This position pays $20.00 - $23.00 per hour. Primary Responsibilities Coordinate and manage guest communication and email...Hourly payPart timeWork at officeWorldwideFlexible hoursAfternoon shift- ...Growth Lead For Military Health And Veterans Affairs LMI is a growing consulting firm with a 60-year history dedicated to advancing... ...of Growth of the Health and Civilian Market (HCM). Responsibilities The Growth Lead for Military Health and Veterans Affairs will...Local area
$150k - $190k
...Overview We are looking for an Enterprise AI Lead to design, build, and scale AI capabilities across the organization. This... ...results that strengthen missions and drive lasting value. Responsibilities What You'll Do • Design and build enterprise AI/LLM platforms...Contract workShift work$7.5k
...Requirements Management Lead Location: McLean / Herndon / Reston, VA (Northern Virginia Territory) Security Clearance Required... ...are not limited to, the extent and intricacy of the role's responsibilities, the candidate's educational background, their work experience...Work experience placementWork at officeImmediate startFlexible hours- ...Cybersecurity Lead Job Locations US-VA-McLean ID 2026-10876 # of Openings... ...deliver operationally ready systems. #compmod Responsibilities Support preparation for and execution of Command Cyber Readiness Inspections (CCRIs) Provide cybersecurity...Worldwide
- ...choose MITRE - and make a difference with us. As part of MITRE’s Center for Transforming Health, the CMS Programs Division is responsible for managing work shaping, engagement, and end-to-end delivery for the Health FFRDC’s CMS Portfolio with the Centers for Medicare...Work experience placementLocal area
- ...programs. Priority account areas include Army commands, program offices, and service components... ...momentum and expand market share. Lead development of strategic outreach materials... ...demonstrations. Support RFI and RFP responses with market intelligence and competitive...Contract workWork at officeRemote workFlexible hours
- ...Overview The Cybersecurity Lead will provide the Defense Nuclear Facilities Safety Board (DNFSB) support and implement all phases of the Risk Management Framework (RMF). Responsibilities Ensure information systems maintain an appropriate level of confidentiality...Temporary workFor contractorsWork at officeImmediate startFlexible hours
$80k - $105k
...UX Copy Lead - Product & Experience New York, New York; Tysons, Virginia, United States About TEGNA TEGNA Inc. helps people... ...to serve and connect local communities everywhere. Key Responsibilities: Lead UX Writing & UX Content Design: Write and review...Full timeTemporary workPart timeLocal areaShift work$100k - $118k
...able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more... ...closely with business and technical stakeholders. Key Responsibilities Workfront Fusion Development & Delivery Lead design and...Full timeLocal area- ...Store Floor Lead With over 58 stores and the largest avocational cooking program in the US, Sur La Table offers an unsurpassed... ...experience, a company-wide standard for excellence in service. Key Responsibilities Leadership & Team Development Lead the sales floor...Work at officeFlexible hoursNight shift
- ...Introduction Expert Price-to-Win (PTW) lead with deep expertise in federal acquisition, competitive intelligence, pricing strategy... ...performance across the federal marketplace. Your role and responsibilities As a Pricing and Technical SME you will be Responsible for...Contract work
- ...CEOs and startup founders to experts from leading hedge funds and tech companies. If... ...key modeling, analysis, and insight responsibilities Build and evolve financial models... ...accounting fundamentals with a strong command of P&L, balance sheet, and cash flow dynamics...Work at officeRelocationMonday to Friday
- ...Defense Growth Lead, USCYBERCOM We were early to the fight against Ubiquitous Technical... ...across USCYBERCOM and its component commands. Scale the Small Win: Establish pilot... ...technical demonstrations. Support RFI and RFP responses with market intelligence and competitive...Contract workWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Commander & Incident Response Lead. Be the first to apply!
Related searches


