Incident Response Team Lead (CBP) Agile DefenseIncident Response Team Lead (CBP)Reston, Virginia$155,000–$180,000 / yearQUALIFICATIONS Minimum required experience Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers.
NewBiometrics Watchlist Lead Science Applications International CorpBiometrics Watchlist LeadBethesda, MD$200,001–$240,000 / yearSAIC is seeking a Biometrics Watchlist Lead to serve as the senior technical and operational authority for all biometric watchlisting, identity intelligence processing, and attribution analysis activities performed under an Intelligence Community program. Coordinating with Digital Forensics, Multimedia Intelligence, Reverse Engineering, and Data Science functional areas to identify fusion opportunities and integrate biometric findings into broader multi-disciplinary intelligence products.
Principal, Digital Forensics Control RisksPrincipal, Digital ForensicsWashington, DCThe Principal will support a range of forensic investigations and eDiscovery matters across many different industries, providing assistance with data collections, chain-of-custody documentation, proper evidence handling, forensic analysis, expert reporting, declaration/affidavits, and expert witness testimony. Assist the business development team throughout the sales process by building relationships with current and potential future clients, demonstrating firm technology and expertise to potential clients, and providing supporting documentation, including proposals and cost estimates, regarding our offerings.
NewCybersecurity Incident Manager (2nd Shift/OnSite) Triangle Cyber, LLCCybersecurity Incident Manager (2nd Shift/OnSite)Arlington, VAMust have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
NewCybersecurity Incident Manager Day (Day Shift) Triangle Cyber, LLCCybersecurity Incident Manager Day (Day Shift)Arlington, VAMust have knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code). Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return- oriented attacks, and malicious code).
NewSenior Incident Response Consultant PonduranceSenior Incident Response ConsultantMcLean, VA$110,000–$136,000 / yearOne or more of the following technical certifications preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent certifications. About the role: The Incident Response team is focused on supporting the IR lifecycle and providing indicators to the SOC that will assist in enhanced detection capabilities of network, log, and host data.
Senior Threat Hunter Revolutional, LLCSenior Threat HunterWashington, DC$135,000–$175,000 / yearYou proactively hunt for Advanced Persistent Threats and adversary activity across enterprise network environments — using network flow, PCAP, logs, sensors, and endpoint data — before they manifest as confirmed incidents. You manage hunt operations against tight deadlines, develop reusable hunt tactics that raise the team's capabilities, and brief findings clearly to technical peers and executive audiences alike.
Lead Incident Responder Evolver IncLead Incident ResponderWashington, DCResponsibilities include coordinating with SOC teams, ISSOs, and AOs, integrating threat intelligence and forensic analysis into response processes, and driving continuous improvement to strengthen organizational resilience against evolving cyber threats. The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting to federal stakeholders.
Deputy Program Manager Agile DefenseDeputy Program ManagerAshburn, Virginia$145,000–$185,000 / yearRequisition #: 1433 Job Title: Deputy Program Manager Location: Reston, VA Clearance Level: TS (SCI Eligible) Required Certification(s): CISSP or CISSP-ISSMP or CISM or PMP SUMMARY Agile Defense is currently seeking a highly technical, hands-on Cybersecurity Operations Center (CSOC) Lead and Deputy Program Manager with advanced skillsets in cyber security, to develop and operate cyber security capabilities for a variety of federal customers. A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in insider threat monitoring software, host-based forensic tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint detection and response tools, security operations ticket management.
Endpoint Security Engineer (EDR/XDR) (Hybrid) A.C. CoyEndpoint Security Engineer (EDR/XDR) (Hybrid)Falls Church, VirginiaFleet-Wide Behavioral Defense & Control Engineering: Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of heterogeneous endpoints. Balance proactive protection with business continuity - partnering directly with end-users and application owners to tune policies and eliminate operational friction, while providing tier-3/tier-4 technical escalations to Security Operations Center (SOC) analysts and IT Operations staff during active investigations.
Cyber Defense- Cyber Incident Response - Experienced Associate PricewaterhouseCoopers LLPCyber Defense- Cyber Incident Response - Experienced AssociateWashington, DC$63,000–$140,000 / yearCertifications Preferred: Global Information Assurance Certification (GIAC) including Global Certified Forensic Analyst (GCFA), Global Certified Forensic Examiner (GCFE),Global Reverse Engineering Malware (GREM), Global Information Assurance Certification Network Forensic Analyst(GNFA), Global Critical Controls Certification (GCCC), or Global Certified Intrusion Analyst (GCIA). PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy .
SOC Lead ID.meSOC LeadMclean, VA$160,963–$227,360 / yearLead cyber security incident response for cloud-native infrastructure, including investigating compromised containers, Kubernetes clusters, and CI/CD pipelines, and coordinating rapid isolation, remediation, and root-cause analysis across cloud workloads. Oversee the detection, analysis, and mitigation of complex insider threats and incidents, utilizing advanced security tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls.
SOC Lead ID.me IncSOC LeadMcLean, VA$96,086–$111,683 / yearKey Responsibilities: Lead cyber security incident response for cloud-native infrastructure, including investigating compromised containers, Kubernetes clusters, and CI/CD pipelines, and coordinating rapid isolation, remediation, and root-cause analysis across cloud workloads. Oversee the detection, analysis, and mitigation of complex insider threats and incidents, utilizing advanced security tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls.
Cloud Incident Response Training- Contract Instructors (Remote) CybervanceCloud Incident Response Training- Contract Instructors (Remote)Kensington, MDRemoteHelp students investigate and mitigate threats by teaching detection of common Azure attack patterns (e.g., password spraying, lateral movement, data exfiltration) and conducting threat hunting using Kusto Query Language (KQL). We are looking for experienced instructors to deliver a series of virtual Cloud Incident Response (IR) courses designed for SOC analysts, incident responders, and security professionals transitioning to or specializing in cloud security.
Endpoint Security Engineer PlanIT GroupEndpoint Security EngineerReston, VARemoteProtecting an enterprise comprising 600,000+ employees and 30,000+ physical sites, you will maintain rigorous security posture across traditional end-user computing (EUC) devices (laptop, desktop, mobile devices & retail terminals), on-premise physical & virtual servers & containerized workloads, and dynamic multi-cloud workloads (AWS, Azure, GCP). Fleet-Wide Behavioral Defense & Control Engineering: Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of heterogeneous endpoints.
Incident Response & Forensics Lead RedportIncident Response & Forensics LeadGaithersburg, MarylandWe are seeking a Senior Incident Response & Forensics Lead for a hands-on cybersecurity position responsible for managing a team while personally performing investigations, analysis, and responses to cyber incidents. Monitor external data sources, including cyber defense vendor sites and Computer Emergency Response resources, for information relevant to cyber defense and incident response activities.
Penetration Tester III Agile DefensePenetration Tester IIISpringfield, VirginiaThis senior level cyber TE analysts engage with senior leadership to identify, report, and perform real-world threat activity simulation attacks, such as those used by our nation’s adversaries, in order to train and measure the effectiveness of the people, processes, and technology used to defend Agency networks and systems. Strong proficiency Report writing – a technical writing sample and technical editing test will be required if the candidate has no prior published intelligence analysis reporting, excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings.
NewIncident Responder (Weekend Day Shift) Leidos Holdings IncIncident Responder (Weekend Day Shift)Suitland, MD$107,900–$195,050 / yearMust possess one of the following certifications or obtain one within 30 days of accepting an offer: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER). Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
NewIncident Responder (Weekend Night Shift) Leidos Holdings IncIncident Responder (Weekend Night Shift)Suitland, MD$107,900–$195,050 / yearMust possess one of the following certifications or obtain one within 30 days of accepting an offer: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER). Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
Incident Responder (3rd Shift) Leidos Holdings IncIncident Responder (3rd Shift)Suitland, MD$107,900–$195,050 / yearMust possess one of the following certifications or obtain one within 30 days of accepting an offer: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER). Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.