Forensics - Crisis and Investigations - Senior Ernst & Young Global LtdForensics - Crisis and Investigations - SeniorMcLean, VA$84,700–$139,800 / yearClients call upon EY to deploy former federal law enforcement officers, forensics accountants, compliance professionals and technology specialists to coordinate response activity and timelines, collect critical information and business intelligence, investigate suspicious activities, summarize procedures and outcomes, and streamline communications and reporting when responding to critical business events that can lead to an organizational crisis. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.
HSEEP Cybersecurity/Infrastructure Protection Exercise Professional (Remote) CybervanceHSEEP Cybersecurity/Infrastructure Protection Exercise Professional (Remote)Washington, DCRemoteResponsibilities of the Project Manager include, but are not limited to, providing assistance to the Project Executive; enforcement of the contract provisions; serving as the primary point of contact for Contract communications; maintaining appropriate staffing levels; implementation of quality assurance and control measures; review of daily activity; review and submittal of invoices; and overall management and oversight of action planning and process improvements. Proven production experience in understanding cybersecurity frameworks, familiarity with SIEM tools, knowledge of network protocols and infrastructures, ability to analyze logs for irregularities, basic scripting or coding for task automation, threat intelligence analysis, and incident response.
HSEEP Cybersecurity/Infrastructure Protection Exercise Professional CybervanceHSEEP Cybersecurity/Infrastructure Protection Exercise ProfessionalWashington, DCResponsibilities of the Project Manager include, but are not limited to, providing assistance to the Project Executive; enforcement of the contract provisions; serving as the primary point of contact for Contract communications; maintaining appropriate staffing levels; implementation of quality assurance and control measures; review of daily activity; review and submittal of invoices; and overall management and oversight of action planning and process improvements. Proven production experience in understanding cybersecurity frameworks, familiarity with SIEM tools, knowledge of network protocols and infrastructures, ability to analyze logs for irregularities, basic scripting or coding for task automation, threat intelligence analysis, and incident response.
Tier 2 Shift Lead SkyePoint DecisionsTier 2 Shift LeadLaurel, MarylandSkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Must possess at least one of the following certifications: CASP+ CE; CCNA Cyber Ops; CCNA-Security; CCNP Security; CEH; CFR; CHFI; CISA;CISSP (or Associate); CISSP-ISSAP; CISSP-ISSEP; CySA+; GCED; GCFA; GCIH; SCYBER.
Cyber Defense Incident Responder - Swing Shift ASRC Federal Holding CompanyCyber Defense Incident Responder - Swing ShiftVAMinimum Requirements: At least two (2) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
CRIMINAL INVESTIGATOR U.S. Department of Veterans AffairsCRIMINAL INVESTIGATORWashington, DC$63,780–$97,087 / yearSpecial Instructions for Foreign Education: If you are using education completed in foreign colleges or universities to meet the qualification requirements, you must show that the education credentials have been evaluated by a private organization that specializes in interpretation of foreign education programs and such education has been deemed equivalent to that gained in an accredited U.S. education program; or full credit has been given for the courses at a U.S. accredited college or university. Veterans Preference: If you are a veteran with preference eligibility and you are claiming 5-point veterans preference, you must submit a copy of your DD-214 (Member Copy 4) or an official statement from your command if currently on active duty that certifies you are expected to be discharged or released from active duty service in the armed forces under honorable conditions not later than 120 days after the date the certification is signed.
Incident Responder - Tier 2 EC Technology, LLCIncident Responder - Tier 2Ft. Meade, MD$115,000–$147,000 / yearRequired Certifications: DoD 8570/8140 IAT Level III or CSSP Incident Responder certification (e.g., GCIH, GCFA, or CySA) required; working knowledge of endpoint detection and response (EDR) tooling, packet analysis, and at least one scripting language (e.g., Python, PowerShell, or Bash) preferred. Required Education and Experience: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience; three to five years of hands-on incident response, digital forensics, or security operations experience.
Incident Responder Shift Lead - Tier 2 EC Technology, LLCIncident Responder Shift Lead - Tier 2Ft. Meade, MD$130,000–$158,000 / yearRequired Certifications: DoD 8570/8140 IAT Level III or CSSP Incident Responder certification (e.g., GCIH, GCFA, or CySA) required; working knowledge of endpoint detection and response (EDR) tooling, packet analysis, and at least one scripting language (e.g., Python, PowerShell, or Bash) preferred. Position Summary: The Tier 2 Incident Responder – Team Lead performs in-depth investigation, containment, and remediation of security incidents escalated from Tier 1, applying the NIST SP 800-61 incident response life cycle and manages Tier 1 Analysts and Tier 2 Incident Responders.
SOC Manager Valiant Solutions, LLCSOC ManagerWashington, Washington, DCFull timeTo ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. The SOC Manager coordinates containment, eradication, and recovery actions across SOC, engineering, and partner SOC teams, manages the SIEM notable events dashboard, and maintains the partner and Cloud Service Provider call tree that drives stakeholder notification during an incident.
Intrusion Analysis Technical Lead ParsonsIntrusion Analysis Technical LeadMarylandYou will help guide the team’s technical approach, support complex investigations, and ensure high-quality analysis that enables our customer to better understand, detect, and respond to sophisticated cyber threats. You will collaborate closely with a highly skilled team of analysts, providing technical direction, mentorship, and day-to-day support to strengthen team performance and help individuals grow in their careers.
Intrusion Analysis Technical Lead Parsons Commercial Technology Group Inc.Intrusion Analysis Technical LeadLinthicum Heights, MD$125,100–$225,200 / yearYou will help guide the team's technical approach, support complex investigations, and ensure high-quality analysis that enables our customer to better understand, detect, and respond to sophisticated cyber threats. You will collaborate closely with a highly skilled team of analysts, providing technical direction, mentorship, and day-to-day support to strengthen team performance and help individuals grow in their careers.
Security Operations Center Manager (CBP) Agile DefenseSecurity Operations Center Manager (CBP)Reston, Virginia$155,000–$185,000 / yearExperience collecting data, chain of custody and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and vulnerability assessment, and you are accountable for how well those functions work together, not just how well each one works alone.
Threat Hunt Lead (CBP) Agile DefenseThreat Hunt Lead (CBP)Reston, Virginia$165,000–$200,000 / yearCandidates will have experience in maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and activities to enhance cybersecurity posture of the organization’s IT operating environment. Applicant will possess a strong cyber security background with experience in host and network-based forensics related to the identification of advanced cyber threat activities, intrusion detection, malware identification, and security content development (e.g., signatures, rules, queries etc.).
Senior Cyber Lead Quantum SkySenior Cyber LeadLinthicum Heights, Maryland$175,000–$225,000 / yearFull timeDescription: Quantum Sky is searching for a Senior Cyber Lead to support the Department of Defense Cyber Crime Center (DC3) Cyber Forensics Laboratory (CFL) mission supporting digital forensics, cyber investigations, intrusion analysis, malware analysis, cyber defense operations, and mission-critical DFIR activities. Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial Base (DIB) investigations.
Ai-Powered Cyber Defense Product Sales Engineer Booz Allen Hamilton Inc.Ai-Powered Cyber Defense Product Sales EngineerAnnapolis Junction, MD$77,600–$176,000 / yearExperience supporting enterprise SOCs, Network Operations Centers (NOCs), or Cyber Defense Centers, and with cybersecurity technologies, including SIEM, SOAR, XDR, EDR, NDR, threat intelligence, attack surface management, or security analytics platforms. Ability to communicate complex technical concepts to SOC analysts, security engineers, architects, CISOs, and executive leadership, and partner closely with product management and engineering teams to communicate customer requirements, competitive intelligence, and product feedback.
AI-Powered Cyber Defense Product Sales Engineer Booz Allen HamiltonAI-Powered Cyber Defense Product Sales EngineerMcLean, Virginia$77,600–$176,000 / yearExperience supporting enterprise SOCs, Network Operations Centers (NOCs), or Cyber Defense Centers, and with cybersecurity technologies, including SIEM, SOAR, XDR, EDR, NDR, threat intelligence, attack surface management, or security analytics platforms. Ability to communicate complex technical concepts to SOC analysts, security engineers, architects, CISOs, and executive leadership, and partner closely with product management and engineering teams to communicate customer requirements, competitive intelligence, and product feedback.
Information Systems Security Officer (ISSO) CymertekInformation Systems Security Officer (ISSO)Annapolis Junction, MarylandInformation Systems Security Officer (ISSO), Cybersecurity Officer, Security Compliance Officer, IT Security Specialist, Information Assurance Officer, Network Security Analyst, Security Controls Assessor, System Security Administrator, Cyber Defense Analyst, Risk Management Framework Specialist, etc. Cybersecurity, Information Systems, Computer Science, Information Technology, Computer Engineering, Network Security, Information Assurance, Systems Engineering, Risk Management, Data Science, etc.
Senior Incident Responder, Global CSIRT Salesforce IncSenior Incident Responder, Global CSIRTMclean, VA$148,500–$223,900 / yearYou can perform host and network forensics across Windows, macOS, and Linux - analyzing file system, memory, process, and network artifacts for indicators of compromise - and have responded to incidents in cloud environments (AWS, Azure, and/or GCP), including familiarity with cloud architectures, CI/CD (continuous integration/continuous delivery) pipelines, and cloud logging/telemetry. You've handled high-priority incidents, including insider investigations, adversary activity, and web application attacks, and have a solid, current understanding of the threat landscape - attacker tactics, techniques, and procedures (TTPs), tooling, and hardening best practices - including working knowledge of a framework such as MITRE ATT&CK.
Senior Incident Responder, Global Csirt Salesforce.com, Inc.Senior Incident Responder, Global CsirtMclean, VA$148,500–$223,900 / yearYou can perform host and network forensics across Windows, macOS, and Linux - analyzing file system, memory, process, and network artifacts for indicators of compromise - and have responded to incidents in cloud environments (AWS, Azure, and/or GCP), including familiarity with cloud architectures, CI/CD (continuous integration/continuous delivery) pipelines, and cloud logging/telemetry. You've handled high-priority incidents, including insider investigations, adversary activity, and web application attacks, and have a solid, current understanding of the threat landscape - attacker tactics, techniques, and procedures (TTPs), tooling, and hardening best practices - including working knowledge of a framework such as MITRE ATT&CK.
NewIncident Manager III Solutions³ LLCIncident Manager IIIArlington, VAFull timeSolutions³ LLC is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyberattacks, providing immediate investigation and resolution. Knowledge of system and application security threats and attack methods (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, and malicious code).