Lead Cyber Defense Incident Responder On-site - TS/SCI
$175k - $180kS2i2 Inc
Job Description
Job Description
Job Title
Lead Cyber Defense Incident Responder
Clearance
TS/SCI (active, required)
Location
Arlington, VA On-site
Salary Range
$175,000 to $180,000
Certification Required
DoD 8570 / DoD 8140 IAT Level II
One of the following: Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent
Application Deadline
August 31, 2026
Description:
The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.
Duties and Responsibilities
- - Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.
- - Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.
- - Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.
- - Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.
- - Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.
- - Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.
- - Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.
- - Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.
- - Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).
- - Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence.
Minimum Qualifications and Requirements
- - Bachelor's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.
- - Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.
- - Demonstrated leadership skills, preferably in a formal leadership role.
- - Scripting experience.
- - TS/SCI clearance is required.
Knowledge, Skills, and Abilities
- - Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.
- - Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.
- - Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.
- - Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.
- - Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.
- - Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).
- - Technical mentorship: experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.
- - Advanced forensics: deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.
- - Malware and script analysis: high-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET)
- ...opportunity to support national defense. Your work will help keep... ...Collaborate with engineering, cyber, and operations teams to validate... ...Ensure high availability, site resilience, and optimized performance... ...Security+ CE, etc.) Active TS/SCI clearance with a favorable...CyberWebsite
- ...program supporting the Defense Intelligence Agency (DIA... ...). This position is on site in the Washington DC,... ...This position requires a TS/SCI + CI Polygraph... ...and analyzing security incidents Experience with security... ...Strong technical skills in cyber defense, encryption, security...CyberWebsite
- ...INFRASTRUCTURE SERVICE LEAD (ISL) YOUR... ...to support national defense. Your work will help... ...and initial incident assessment Monitor... ...regional operations, cyber teams, network teams... ...enterprise monitoring sites, and collaboration... ...CLEARANCE: Active TS/SCI clearance with a...CyberWebsiteNight shift
- ...Description Quick Overview: ~100% work on site - no remote work ~ Secret clearance with the ability to acquire a TS ~ Locations near the Pentagon or... ...Bachelor Position Summary The Cyber Defense & Incident Responder is responsible for monitoring, analyzing...CyberWebsiteRemote work
$164.38k - $189.75k
...Specialist Senior to engage in defense and security efforts... ...Pacific theater. You will lead the development and execution... ...Clearance: Active TS/SCI w/ polygraph On Customer Site Desired Education and... ...modernization, AI/ML, Cloud, Cyber and application development...CyberWebsiteTemporary workImmediate startRemote workWorldwideFlexible hours- ...established in the Department of Defense and support agencies.... ...SSO USSF Region 3 for cyber, personnel activities... ..., personnel security, incident handling, information... ...and guidance. On-site presence is required... ...-Secret clearance with SCI is required for this role...CyberWebsiteTemporary workFor contractorsWork at officeRemote workMonday to FridayFlexible hours
- ...to support our nation's defense. Make an impact by... ...skilled and multi-faceted Cyber Analyst Principal for a... ...to report full time on site in McLean, VA. The... ...Manager (ISSM), and Cyber Lead in ensuring the... ...possess a current and active TS/SCI with Polygraph. ● Certifications...CyberWebsiteFull timeContract work
$120k - $170k
...Description Overview We are seeking a Cyber Security Operations Incident Responder/Swing- Shift Lead Analyst to support our Prime Contract with the Defense Threat Reduction Agency at Fort... ...Minimum of a Top-Secret Clearance with SCI eligibility DOD 8570 IAT II and...CyberFull timeContract workTemporary workWork at officeLocal areaShift workWeekend workAfternoon shift- ...join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications... ..., verification and validation in cyber environments. Integrates...CyberWebsiteShift work
- ...personal impact as a Cyber Security Project... .... Be the change, lead our change – join... ..., analyzing, and responding to security incidents across enterprise... ...with cyber defense teams to mitigate... ...Clearance Level : TS/SCI with active polygraph... ...VA - On Customer Site GDIT IS YOUR...CyberWebsite
- ...America is under sustained cyber attack. Our adversaries... ...a government customer site, ensuring the... ...we measure reliability, lead incident response in a constrained... ...supporting government or defense environments, including... ...be able to maintain a TS/SCI security clearance with...CyberWebsiteWork at officeRemote workFlexible hours
- cFocus Software seeks a Lead Information System Security Officer (ISSO) to join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications...WebsiteFull time
- ...Owned Small Business (SDVOSB) providing Cyber Security, Intelligence Analysis, Financial... ...Intelligence Community (IC), the Department of Defense (DoD), and other federal government... ...growing SDVOSB Requirements ~ Active TS/SCI clearance with CI Polygraph is a must...CyberFull time
$101.38k - $152.06k
...apply now. We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington,... ...incidents to Senior SOC Analysts or SOC Leads. # Document and communicate incident... ...to NTT DATA offices or client sites. This ensures we can provide timely and...CyberWebsiteTemporary workWork at officeRemote workFlexible hours- ...Description cFocus Software seeks a Chief Engineer/Lead Architect to join our program supporting the Defense Intelligence Agency (DIA). This position is on site; in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance. Qualifications:...Website
$155k - $180k
...About Agile Defense At Agile Defense we know that action... ...#: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (SCI Eligible) Active Certified... ...Defense is seeking experienced Cyber Incident Response Team Lead to...CyberWork experience placement- ...America is under sustained cyber attack. Our adversaries infiltrate... ...real missions. You’ll also lead technical initiatives and mentor... ...This role requires an active TS/SCI security clearance with appropriate... ...maintain it. This role is on-site in Arlington, VA with...CyberWebsiteFull timeWork at officeFlexible hours
- ...Washington, DC Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and... ...Information (PII), and coordinating remediation efforts. Cyber Threat Monitoring: Develop and maintain a Cyberthreat Dashboard...CyberContract workFor contractorsWork at officeLocal area
- ...Lead Incident Responder Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The... ...improvement to strengthen organizational resilience against evolving cyber threats. This position requires deep technical expertise,...CyberContract workFlexible hours
- ...Job Description Title: Incident Manager III... ...owners who experience cyber-attacks, providing immediate... ...Must have an active TS/SCI clearance ~ Must be able... ...techniques, and cybersecurity defense policies, procedures,... ..., mobile code, cross-site scripting, PL/SQL and injections...CyberWebsiteFor contractorsImmediate start
- ...Job Description Title: Incident Manager III... ...owners who experience cyber-attacks, providing immediate... ...Must have an active TS/SCI clearance ~ Must be able... ...incidents Recommending defense in depth principles and... ...overflow, mobile code, cross-site scripting, PL/SQL and...CyberWebsiteFor contractorsImmediate startShift work
- ...are seeking an accomplished Cyber Security Service lead with diverse experience in... ...after-action reports involving incidents reported by the SOC team.... ...Security Clearance Level: TS/SCI clearance and ability to... ...Location : On Customer Site Reston, VA Bolling, AFB...CyberWebsiteWork experience placementShift work
$110k - $140k
...Belvoir, VA Clearance Required: TS/SCI minimum (US Citizen)... ...support of the Department of Defense (DoD), Intelligence Community,... ...Intelligence Solutions Integrator (Team Lead) to support the Data... ...Certification (GSEC), GIAC Certified Incident Handler (GCIH), Cisco Certified...WebsiteFull timeContract workFor contractors$246.5k - $333.5k
...Possess: Top Secret SCI + Polygraph... ...personal impact as a Lead Architect supporting... ...Clearance Level : TS/SCI with polygraph... ..., MD - On Customer Site GDIT IS YOUR PLACE... ...U.S. government, defense and intelligence community... ..., AI/ML, Cloud, Cyber and application...CyberWebsiteFull timeTemporary workPart timeImmediate startRemote workWorldwideFlexible hours- ...Description cFocus Software seeks a Lead Agile Coach/Release Train Engineer... ...join our program supporting the Defense Intelligence Agency (DIA). This position is on site in the Washington DC, MD, & VA area. This position requires a TS/SCI + CI Polygraph clearance....Website
$138.06k - $186.79k
...Obtain Top Secret SCI + Polygraph Public... ...deliverables—wireframes, site maps, diagrams,... ...Security Clearance Level: TS/SCI with Polygraph... ...U.S. government, defense and intelligence... ..., offering leading capabilities in digital... ...modernization, AI/ML, Cloud, Cyber and application...CyberWebsiteTemporary workWork experience placementImmediate startWorldwideFlexible hours- ...Automated Test Engineer – TS/SCI Xcelerate Solutions has... ...is primarily conducted on-site at our client location in Bethesda... ...Description Xcelerate is a leading defense and national security company... ..., Digital Solutions, Cyber Security, and Strategic Consulting...CyberWebsiteContract workRemote workFlexible hours
- ...impact as a Task Order Lead supporting customer activities... ...a premier provider of cyber security services to... ...includes patch, asset, incident, configuration,... ...Security Clearance Level : TS/SCI with active polygraph... ...McLean, VA - On Customer Site GDIT IS YOUR PLACE...CyberWebsite
- ...evaluation, implementation, and operation of leading security Cyber defense tools and technologies and apply in-... ...Management Framework ~ Top Secret/SCI clearance with the ability to obtain a... ...Experience with performing site surveys, data gathering, and research...CyberWebsiteTemporary workRelocation package
$124k - $148k
...Strategic Communications Director (Program Lead) to support a U.S. Air Force customer.... ...Requirements The position requires on-site work (limited remote opportunities) in the... ...domestic travel may be required Active TS/SCI clearance required (with prior experience...WebsiteContract workWork experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cyber Defense Incident Responder On-site - TS/SCI. Be the first to apply!




