Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Response Lead

$140k - $150k

ECS Limited

Incident Response Lead

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.

We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.

Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.

Salary Range: $140,000 - $150,000 General Description of Benefits

Incident Response & Threat Operations

  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures

Threat Hunting & Detection Engineering

  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes

Security Operations

  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks

Leadership & Collaboration

  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.

Vacancy posted 22 hours ago
Similar jobs that could be interesting for youBased on the Incident Response Lead in Washington DC vacancy
  • $107.9k - $195.05k

     ...transformation and IT programs, allowing us to better serve our customers through scale and repeatability. Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC... 
    Suggested
    Local area
    Immediate start

    Leidos

    Washington DC
    3 days ago
  •  ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data... 
    Suggested
    Contract work

    ShorePoint Inc

    Washington DC
    1 day ago
  • $100k - $120k

     ...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 
    Suggested

    Bering Straits Native Corporation

    Washington DC
    22 hours ago
  •  ...Cadwalder looks for an experienced cybersecurity professional to join the Security Operations team in Washington, D.C. You will lead incident response, investigations, and detection improvements across endpoints, cloud, and identity. The role emphasizes collaboration with... 
    Suggested

    Hogan Lovells

    Washington DC
    22 hours ago
  •  ...ICS (a REDHAWK company) seeks an experienced Tier 2 Cyber Incident Response Team Shift Lead in Beltsville, MD to join the Federal Strategic Cyber Mission program. You will lead Tier 2 shift operations, review tickets for accuracy, and coordinate with CIRT Watch Officers... 
    Suggested
    Shift work

    AGR

    Beltsville, MD
    3 days ago
  •  ...client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage...  ...integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures... 
    Hourly pay
    Full time
    Contract work
    Local area
    2 days per week
    3 days per week

    Eliassen Group

    Alexandria, VA
    3 days ago
  • $172.5k - $260.1k

     ...heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the right...  ...of Salesforce.The ExperienceSalesforce's Computer Security Incident Response Team (CSIRT) provides 24x7x365 security monitoring and rapid... 
    Full time
    Monday to Friday
    Shift work
    Night shift

    Salesforce

    Washington DC
    7 days ago
  •  ...Washington, DCPosition Overview: We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security...  ...will have extensive experience in risk management, incident response, and vulnerability assessment within a government contract setting... 
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions, LLC

    Washington DC
    18 days ago
  •  ...Geospatial & Cloud Analytics (GCA) is seeking a mission-driven Rapid Response Team Lead to support the high-priority, time-sensitive operational...  ...activities, VIP support in GO/Flag quarters, and immediate incident response across critical infrastructure. The ideal... 
    Full time
    Contract work
    Immediate start
    Worldwide
    Night shift

    Geospatial And Cloud Analytics Inc

    Washington DC
    18 days ago
  •  ...Description Job Description Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government...  ...the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure... 
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    18 days ago
  •  ...Responsibilities And Qualifications Responsibilities Monitor and control project budgets...  ...and management practices (e.g., Asset, Incident, Problem, Change, Release, Capacity, Operations...  ...Officer's Representative (ACOR). Lead the rapid response efforts during... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Monday to Friday
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    Washington DC
    12 hours ago
  •  ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead will oversee 24x7x3...  ...enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security... 
    Full time

    cFocus Software Incorporated

    Washington DC
    a month ago
  • $70.33k - $90.66k

     ...field-based lessons into broader systems and policy change. Primary Function: This position primarily supports the Eviction Data Response Network (EDRN), a groundbreaking initiative to create the country’s first large-scale eviction data infrastructure and use that... 
    Full time
    Work at office
    Local area
    Immediate start
    Work from home

    New America

    Washington DC
    8 days ago
  • $172.5k - $260.1k

     ...to level-up your career at the company leading workforce transformation in the agentic...  ...investigations into advanced or high-impact incidents across Salesforce Core, Marketing Cloud,...  ...You Have:8+ years in security incident response with consistent hands-on technical case... 
    Full time

    Salesforce

    Washington DC
    5 days ago
  •  ...highest form of third-party validation. is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the...  ...before they occur.Communicate plans and responses to incidents to customer leadership, providing them confidence that cybersecurity... 
    Full time
    Contract work
    Local area

    ValidaTek

    Arlington, VA
    4 days ago
  •  ...Description: The Access Control Supervisor is responsible for overseeing the daily operations of...  ...systems, personnel accountability, incident response activities, and customer service...  ...of 1-2 years of supervisory, team lead, or shift lead experience preferred.... 
    For contractors
    Work at office
    Shift work
    Rotating shift

    T47 INTERNATIONAL, INC.

    Bowie, MD
    4 days ago
  •  ..., a world-class training facility, and leading market tools, we help our people continue...  ...join our Federal Advisory practice. Responsibilities: Lead the architecture, deployment,...  ...PAM operations and remediation of incidents Provide strategic leadership in the... 
    Full time
    Local area

    KPMG

    Washington DC
    22 days ago
  • $108.01k - $183.61k

     ...contract award. ICF is seeking an IAM Lead to architect, implement, and operate the...  ...and anomalies. Respond to identity-related incidents including account takeover, phishing,...  ...Experience supporting identity incident response including account takeover, phishing, and... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Work at office
    Remote work

    ICF

    Washington DC
    22 hours ago
  •  ...guiding principles with pride and integrity. ROLES AND RESPONSIBILITIES The Front Desk Weekend Lead (Part-Time) position provides a welcoming and safe...  .... Partner with GM/AGM to quickly address any incidents, maintenance or equipment issues that are visible to... 
    16 hours
    Temporary work
    Part time
    Local area
    Shift work
    Weekend work
    2 days per week

    New York Sports Clubs

    Washington DC
    1 day ago
  •  ...buses. The Fleet Maintenance Manager is responsible for supervising approximately seven to...  ...Maintenance Leadership: Ability to lead and supervise fleet maintenance operations...  ...vehicle breakdowns, accidents, environmental incidents, and emergency maintenance situations.... 
    Work at office
    Local area

    Transportation Services

    Alexandria, VA
    1 day ago
  •  ...Summary We are seeking an experienced Lead Program Specialist to support the U.S....  ...unless exceptionally qualified. Key Responsibilities Grants Management & Program...  ...performance, change in scope actions, and incident tracking Support development and implementation... 
    Contract work
    Work at office
    Remote work

    FM Talent Source

    Silver Spring, MD
    22 hours ago
  • $23 - $26 per hour

     ...continue to expand, we are looking for shift leads who shares our passion for the...  ...is eager to grow with us. Role and Responsibilities Assists manager to oversee restaurant...  ...situations are recorded following the incident reporting process and/or brought to Manager... 
    Hourly pay
    Casual work
    Local area
    Shift work
    Night shift

    Burgermaster

    Washington DC
    18 days ago
  • cFocus Software seeks a Forensic and Malware Lead to join our program supporting the Administrative Office of the United States...  ...intrusion vectors. Coordinate with Cybersecurity Triage and Incident Response teams to support investigation, escalation, containment,... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    a month ago
  •  ...Cyber Threat Intelligence & Threat Hunting Lead Position Overview The Cyber...  ...-informed defense capabilities. Key Responsibilities Lead CTI, detection engineering, and...  ...workflows, detection engineering, and incident response operations. Analyze: malware... 
    Full time

    cFocus Software Incorporated

    Washington DC
    a month ago
  • cFocus Software seeks a Blue Team Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC...  ..., SOC personnel, Detection Engineering, Threat Hunting, Incident Response, and Cyber Threat Intelligence teams to support exercise planning... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    a month ago
  • $90k - $140k

     ...Job Description Job Description Application Configuration Lead — ServiceNow Vendor Performance Platform (Department of...  ...standardized SLA/KPI definitions and dashboards (e.g., availability, responsiveness, incident resolution, defect leakage, vendor compliance) to cover... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Work from home
    Flexible hours
    Night shift

    Censeo Consulting Group

    Washington DC
    23 days ago
  •  ...Compute, Storage and Data Protection Team Lead to join our  National Institutes of...  ...as well as other adjudications.   Responsibilities: ~ Provide day-to-day oversight for your...  ...members.   ~ Provide oversight for incidents, coordinating with resolution parties and... 

    General Dynamics Information Technology

    Bethesda, MD
    26 days ago
  • cFocus Software seeks a Threat Hunt Lead to join our program supporting the Administrative Office of the United States Courts (...  ...confirmed or suspected findings to the Cybersecurity Triage and Incident Response teams in accordance with the Judiciary SOC Incident Response... 
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    a month ago
  •  ...Description Job Description Position Summary The Cybersecurity Lead will serve as a “Dual-Hat” role providing senior technical...  ...Lead, this role will provide expert oversight for the entire incident response lifecycle, from initial detection and log correlation within... 
    Local area

    Leader Communications Inc

    Alexandria, VA
    10 days ago
  • $79.37k - $134.92k

     ...Desk Analyst to serve as a working task lead for a five-person onsite support desk...  ...role combines hands-on troubleshooting responsibilities with leadership duties, guiding team members...  ...systems. Diagnose and resolve incidents through remote tools, phone support, and... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours
    Shift work

    BAE Systems

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Response Lead. Be the first to apply!