NewCybersecurity Incident Manager (2nd Shift/OnSite) Triangle Cyber, LLCCybersecurity Incident Manager (2nd Shift/OnSite)Arlington, VAMust have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
Senior Threat Hunter Revolutional, LLCSenior Threat HunterWashington, DC$135,000–$175,000 / yearYou proactively hunt for Advanced Persistent Threats and adversary activity across enterprise network environments — using network flow, PCAP, logs, sensors, and endpoint data — before they manifest as confirmed incidents. You manage hunt operations against tight deadlines, develop reusable hunt tactics that raise the team's capabilities, and brief findings clearly to technical peers and executive audiences alike.
Lead Incident Responder Evolver IncLead Incident ResponderWashington, DCResponsibilities include coordinating with SOC teams, ISSOs, and AOs, integrating threat intelligence and forensic analysis into response processes, and driving continuous improvement to strengthen organizational resilience against evolving cyber threats. The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting to federal stakeholders.
Endpoint Security Engineer (EDR/XDR) (Hybrid) A.C. CoyEndpoint Security Engineer (EDR/XDR) (Hybrid)Falls Church, VirginiaFleet-Wide Behavioral Defense & Control Engineering: Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of heterogeneous endpoints. Balance proactive protection with business continuity - partnering directly with end-users and application owners to tune policies and eliminate operational friction, while providing tier-3/tier-4 technical escalations to Security Operations Center (SOC) analysts and IT Operations staff during active investigations.
Deputy Program Manager Agile DefenseDeputy Program ManagerAshburn, VirginiaRequisition #: 1433 Job Title: Deputy Program Manager Location: Reston, VA Clearance Level: TS (SCI Eligible) Required Certification(s): CISSP or CISSP-ISSMP or CISM or PMP SUMMARY Agile Defense is currently seeking a highly technical, hands-on Cybersecurity Operations Center (CSOC) Lead and Deputy Program Manager with advanced skillsets in cyber security, to develop and operate cyber security capabilities for a variety of federal customers. A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in insider threat monitoring software, host-based forensic tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint detection and response tools, security operations ticket management.
SOC Lead ID.me IncSOC LeadMcLean, VA$96,086–$111,683 / yearKey Responsibilities: Lead cyber security incident response for cloud-native infrastructure, including investigating compromised containers, Kubernetes clusters, and CI/CD pipelines, and coordinating rapid isolation, remediation, and root-cause analysis across cloud workloads. Oversee the detection, analysis, and mitigation of complex insider threats and incidents, utilizing advanced security tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls.
Cloud Incident Response Training- Contract Instructors (Remote) CybervanceCloud Incident Response Training- Contract Instructors (Remote)Kensington, MDRemoteHelp students investigate and mitigate threats by teaching detection of common Azure attack patterns (e.g., password spraying, lateral movement, data exfiltration) and conducting threat hunting using Kusto Query Language (KQL). We are looking for experienced instructors to deliver a series of virtual Cloud Incident Response (IR) courses designed for SOC analysts, incident responders, and security professionals transitioning to or specializing in cloud security.
Staff Cloud Detection & Response Engineer ID.meStaff Cloud Detection & Response EngineerMclean, VA$160,963–$227,360 / yearAdvise engineering and platform teams on secure-by-design cloud architecture, IAM least-privilege structures, network security perimeters (e.g., AWS Organizations SCPs / VPC Service Controls), and workload identity, serving as a technical reviewer and consultant rather than the engineer implementing the change. Perform proactive threat hunting for IOCs and APT TTPs specific to cloud and container environments, translating cloud-native telemetry (CloudTrail/Cloud Audit Logs, VPC/network flow logs, Kubernetes audit logs) into concrete detections.
SOC Lead ID.meSOC LeadMclean, VA$96,086–$111,683 / yearKey Responsibilities: Lead cyber security incident response for cloud-native infrastructure, including investigating compromised containers, Kubernetes clusters, and CI/CD pipelines, and coordinating rapid isolation, remediation, and root-cause analysis across cloud workloads. Oversee the detection, analysis, and mitigation of complex insider threats and incidents, utilizing advanced security tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls.
Cyber Defense- Cyber Incident Response - Experienced Associate PricewaterhouseCoopers LLPCyber Defense- Cyber Incident Response - Experienced AssociateWashington, DC$63,000–$140,000 / yearCertifications Preferred: Global Information Assurance Certification (GIAC) including Global Certified Forensic Analyst (GCFA), Global Certified Forensic Examiner (GCFE),Global Reverse Engineering Malware (GREM), Global Information Assurance Certification Network Forensic Analyst(GNFA), Global Critical Controls Certification (GCCC), or Global Certified Intrusion Analyst (GCIA). PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy .
Endpoint Security Engineer PlanIT GroupEndpoint Security EngineerReston, VARemoteProtecting an enterprise comprising 600,000+ employees and 30,000+ physical sites, you will maintain rigorous security posture across traditional end-user computing (EUC) devices (laptop, desktop, mobile devices & retail terminals), on-premise physical & virtual servers & containerized workloads, and dynamic multi-cloud workloads (AWS, Azure, GCP). Fleet-Wide Behavioral Defense & Control Engineering: Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of heterogeneous endpoints.
Incident Response & Forensics Lead RedportIncident Response & Forensics LeadGaithersburg, MarylandWe are seeking a Senior Incident Response & Forensics Lead for a hands-on cybersecurity position responsible for managing a team while personally performing investigations, analysis, and responses to cyber incidents. Monitor external data sources, including cyber defense vendor sites and Computer Emergency Response resources, for information relevant to cyber defense and incident response activities.
Cyber Incident Response Team Lead ManTechCyber Incident Response Team LeadAshburn, VAThe ultimate purpose of this role is to provide the disciplined leadership and structural organization necessary to rapidly implement critical, high-impact security solutions that directly protect the Nation's digital borders while ensuring continuous, compliant contract delivery for 24x7x365 network, cyber, and cloud services. + Certified Information System Security Professional (CISSP) and at least one of the following: SANS GIAC Certified Intrusion Analyst (GCIA), SANS GIAC Certified Incident Handler (GCIH), SANS GIAC Certified Forensic Analyst (GCFA), SANS GIAC Certified Enterprise Defender (GCED), or other IAT Level III certification.
Penetration Tester III Agile DefensePenetration Tester IIISpringfield, VirginiaThis senior level cyber TE analysts engage with senior leadership to identify, report, and perform real-world threat activity simulation attacks, such as those used by our nation’s adversaries, in order to train and measure the effectiveness of the people, processes, and technology used to defend Agency networks and systems. Strong proficiency Report writing – a technical writing sample and technical editing test will be required if the candidate has no prior published intelligence analysis reporting, excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings.
Cyber Threat Intelligence III AerovironmentCyber Threat Intelligence IIIHerndon, VA$74,500–$113,500 / yearThe ideal candidate understands threat actors and geopolitical or industry-specific threats while also possessing hands-on familiarity with security technologies, endpoint and network telemetry, SIEM/XDR platforms, vulnerability data, and common attacker techniques. This role combines traditional threat intelligence analysis with strong technical cybersecurity aptitude to ensure intelligence is actionable and can be translated into detections, investigations, vulnerability prioritization, and defensive security improvements.
Incident Responder G2ITIncident ResponderSuitland, Maryland$120,000–$135,000 / yearMust possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER). Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
Forensics - Crisis and Investigations - Manager Ernst & Young Global LtdForensics - Crisis and Investigations - ManagerMcLean, VA$104,800–$192,300 / yearClients call upon EY to deploy former federal law enforcement officers, forensics accountants, compliance professionals and technology specialists to coordinate response activity and timelines, collect critical information and business intelligence, investigate suspicious activities, summarize procedures and outcomes, and streamline communications and reporting when responding to critical business events that can lead to an organizational crisis. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.
Information Security Manager Cypress Creek Renewables LLCInformation Security ManagerWashington, DCDigital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed. Please be aware of recruiting scams-official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to HR@ccrenew.com.
Information Security Manager CYPRESS CREEK RENEWABLES, LLCInformation Security ManagerWashington, DCDigital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed. Please be aware of recruiting scams-official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to HR@ccrenew.com.
Senior Security Engineer, IAM Relativity ODA LLCSenior Security Engineer, IAMWashington, D.C., DC$130,000–$195,000 / yearExpert, hands-on experience architecting and operating identity platforms across IdP/SSO (Okta, Entra ID/Azure AD, Ping), IGA (SailPoint, Saviynt), and PAM (CyberArk, BeyondTrust), with advanced knowledge of authentication and federation protocols (SAML, OIDC, OAuth 2.0, SCIM, LDAP, Kerberos). Required Skills: Access Management, Application Security, Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Information, Security Information and Event Management (SIEM), Security Operations, Vulnerability Management.