Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Response Lead

$140k - $150k

ECS Limited

Incident Response Lead

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.

We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.

Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.

Salary Range: $140,000 - $150,000 General Description of Benefits

Incident Response & Threat Operations

  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures

Threat Hunting & Detection Engineering

  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes

Security Operations

  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks

Leadership & Collaboration

  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Incident Response Lead in Washington DC vacancy
  • Amazon Security's Business Assurance Center seeks an Incident Response Coordination Supervisor to lead a 24/7 GSOC team and ensure timely incident management across global security operations. Role requires a Bachelor's degree, 3+ years of operations personnel management... 
    Suggested
    Shift work
    Weekend work
    Afternoon shift

    Socket.dev

    Arlington, VA
    2 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    3 days ago
  • $150k - $190.7k

     ...through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates,...  ...and make an impact. Join us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority responsible for... 
    Suggested
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    13 hours ago
  •  ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor’... 
    Suggested

    EmergencyMD

    Washington DC
    5 days ago
  •  ...A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding... 
    Suggested

    Nightwing

    Arlington, VA
    3 days ago
  • $100k - $120k

     ...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 

    Bering Straits Native Corporation

    Washington DC
    3 days ago
  •  ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data... 
    Contract work

    ShorePoint Inc

    Washington DC
    4 days ago
  •  ...client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage...  ...integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures... 
    Hourly pay
    Full time
    Contract work
    Temporary work
    Local area
    2 days per week
    3 days per week

    Eliassen Group

    Alexandria, VA
    6 days ago
  • $135k - $216k

     ...extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise...  ...The Role Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber... 
    Contract work
    Temporary work
    Work at office
    Local area
    All shifts
    Shift work
    Afternoon shift

    Peraton

    Beltsville, MD
    4 days ago
  • A dynamic Woman Owned Small Business is seeking a Senior Incident Response Coordinator for their Program Management and Cyber Support Services project in Arlington, Virginia. The role entails coordinating cyber incident responses, managing stakeholder communications, and... 

    Zantech

    Arlington, VA
    13 hours ago
  • $138k - $209k

     ...Inc is seeking a Security Architect in Alexandria, Virginia. The ideal candidate will lead incident management activities, develop cybersecurity strategies, and oversee incident response teams. With a Master's degree in IT or a related field and at least 10 years of... 
    Contract work

    Applied Information Sciences, Inc

    Alexandria, VA
    13 hours ago
  •  ...security operations professional to oversee continuous security operations across enterprise infrastructure. You will lead threat detection, incident response, and proactive threat hunting while managing SIEM telemetry and investigations of breach attempts. This role... 

    myBridge Corporation

    Arlington, VA
    2 days ago
  •  ...Inc. in Alexandria, VA is seeking a Cybersecurity Analyst / Incident Response Coordinator to oversee incident response, vulnerability management...  ...hands-on cyber and incident lifecycle management. You will lead security operations, coordinate a team, and produce... 

    Oxley Enterprises, Inc.

    Alexandria, VA
    13 hours ago
  • Kapili Services, LLC is seeking an Incident Responder/Incident Response Coordinator to offer support for government clients in Arlington, VA. The ideal candidate will have a four year degree in information technology and a minimum of eight years of relevant experience... 

    Kapili Services, LLC

    Arlington, VA
    3 days ago
  • Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a team of IR Tier-1, Tier-2, and Forensics specialists on a Federal government contract. The role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead. The candidate... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  • SkyePoint Decisions seeks an experienced Tier 2 Shift Lead for the Cyber Incident Response Team to support our Federal Strategic Cyber Mission program in Beltsville, MD. This on-site role runs Tuesday through Saturday, 2pm to 10pm, demanding hands-on incident analysis,... 
    Shift work

    SkyePoint Decisions

    Laurel, MD
    2 days ago
  • AnaVation is seeking a Security Analyst (Incident Responder) to support client leadership with...  ...vulnerability management and incident response activities. The role requires interacting...  ...and presenting findings clearly. You'll lead IR operations, monitor EDR and SIEM tools... 

    Nava

    Alexandria, VA
    1 day ago
  • $195k - $205k

     ...IT operations, ensuring compliance with DoD standards, and leading a team in providing technical support. Key responsibilities include preparing Monthly IPRs, ensuring COOP compliance, and managing incidents efficiently. The ideal candidate will have a Bachelor’s degree... 

    Akima

    Alexandria, VA
    13 hours ago
  •  ...and securing critical operations across the globe, keeping our country safe and secure. Job Description Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls Church, VA Clearance: Active SECRET (must be maintained) At GDIT, we are... 
    Full time
    Contract work
    Work experience placement
    Shift work

    General Dynamics Information Technology

    Falls Church, VA
    3 days ago
  • $138k - $209k

    AIS (Applied Information Sciences) is seeking a qualified Security Architect to lead incident response activities and manage cybersecurity threats effectively. The candidate will develop strategies, frameworks, and ensure adherence to security protocols, working closely... 

    AIS (Applied Information Sciences)

    Alexandria, VA
    4 days ago
  • BCMC is seeking a TEN Lab Manager to support on-site incident response and IT operations for a U.S. Government customer in Arlington. You will act as the first line Help Desk for TEN Lab systems, assist with user setups, tickets, and asset management, and help implement... 

    Business Computers Management Consulting Group Llc

    Arlington, VA
    4 days ago
  • Edgewater Federal Solutions is seeking a Tier II Incident Response Analyst to support a federal government contract. The role requires US Citizenship and offers opportunities to work on enterprise security incidents within a government program. The ideal candidate will... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    13 hours ago
  •  ...highest form of third-party validation. is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the...  ...before they occur.Communicate plans and responses to incidents to customer leadership, providing them confidence that cybersecurity... 
    Full time
    Contract work
    Local area

    ValidaTek

    Arlington, VA
    2 days ago
  • $138k - $209k

     ...on projects that matter, alongside industry-leading experts, in an environment that fosters innovation...  ...support the unique needs of our client as a Incident Management Lead. Project Summary The Incident Management Lead is responsible for directing enterprise-wide incident... 
    Contract work
    Temporary work

    Applied Information Sciences

    Alexandria, VA
    4 days ago
  •  ...required. Description: The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional...  ...Special Access Program (SAP) networks. Duties and Responsibilities - Lead a small team of advanced and mid-level security analysts... 
    Full time
    Weekend work

    search-tactics

    Arlington, VA
    1 day ago
  •  ...Washington, DCPosition Overview: We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security...  ...will have extensive experience in risk management, incident response, and vulnerability assessment within a government contract setting... 
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions, LLC

    Washington DC
    9 days ago
  •  ...Description Job Description Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government...  ...the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure... 
    Contract work
    Flexible hours

    Evolver Federal

    Washington DC
    9 days ago
  •  ...Geospatial & Cloud Analytics (GCA) is seeking a mission-driven Rapid Response Team Lead to support the high-priority, time-sensitive operational...  ...activities, VIP support in GO/Flag quarters, and immediate incident response across critical infrastructure. The ideal... 
    Full time
    Contract work
    Immediate start
    Worldwide
    Night shift

    Geospatial And Cloud Analytics Inc

    Washington DC
    a month ago
  • bcmcllc is seeking Host Forensics Analysts to support the DHS’s Hunt and Incident Response Team (HIRT). This role focuses on forensic investigations and incident response, requiring an active TS/SCI clearance. Candidates should possess at least 8 years of experience in... 

    bcmcllc

    Arlington, VA
    4 days ago
  • $82k - $92k

     ...Incident & Crisis Management Support Support the coordination and facilitation of response activities during operational disruption events Assist with incident communications, stakeholder updates, and response tracking Maintain and update incident management playbooks... 
    Full time
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    Willis Towers Watson

    Washington DC
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Response Lead. Be the first to apply!