Incident Responder (IR Specialist)
Position Summary
The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on‑site operations, collaborating with hunt and intelligence teams, and surging during high‑tempo events.
Key Responsibilities
- Incident Response Execution: Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent. Drive containment, eradication, and recovery with affected entities and the command center. Build and maintain evidence‑based incident timelines. Determine and document root cause when evidence supports it.
- Deployed & Remote Engagement Support: Support on‑site incident response, including travel as needed. Conduct remote engagements when deployment is not required or feasible. Operate within available monitoring and tooling, clearly noting visibility limitations. Work directly with affected technical staff, translating findings into actionable steps.
- Technical Analysis: Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement. Use outputs from commercial detection and monitoring tools in environments outside organizational control. Triage suspicious files and artifacts; escalate items requiring deeper analysis. Document indicators of compromise and share with intelligence and hunt teams.
- Coordination Across Mission Functions & Agencies: Maintain accurate incident status and ensure required notifications. Collaborate with hunt teams to align response findings with hunt operations. Work with intelligence teams to enrich findings and support broader threat understanding. Coordinate with external responders such as federal law enforcement, National Guard, and state teams.
- Documentation, Reporting & After‑Action: Produce technical documentation, findings, and actionable reports meeting customer standards. Support case file completion aligned with NCISS requirements. Ensure rationale for response actions is preserved. Contribute to after‑action reviews and procedural improvements.
- Surge Readiness: Maintain readiness to deploy or surge on short notice for major cyber events. Support crisis action team operations during elevated tempo. Stay current on tools, tradecraft, and mission‑relevant environments.
Required Qualifications
- Hands‑on enterprise incident response experience, including scoping, containment, eradication, and recovery
- Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity
- Experience using commercial detection and monitoring tools in external environments
- Experience producing technical incident documentation for external stakeholders
- Ability to work directly with affected organizations during active incidents
- Willingness and ability to travel and support surge operations
- Relevant technical training, certification, or degree, plus 5 years of experience
- Active Top Secret clearance
Preferred Qualifications
- National‑level incident response experience
- Experience with ICS/OT or critical infrastructure environments
- Experience coordinating multi‑agency or multi‑jurisdictional response
- Malware triage and basic reverse engineering skills
- Experience with flyaway kits or deployable response tooling
- Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar
Pay
The likely salary range for this position is $131,750 - $178,250. Salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Schedule
Scheduled Weekly Hours: 40. Travel Required: 25-50%. Telecommuting Options: Hybrid. Work Location: USA VA Arlington.
Benefits
- Medical plan options, some with Health Savings Accounts
- Dental plan options
- Vision plan
- 401(k) plan with ability to contribute pre and post-tax dollars up to IRS annual limits and receive a company match
- Full flex work weeks where possible
- Paid time off plans including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
- Short and long-term disability benefits
- Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance