Computer Network Defense Incident Manager III

argocyber

Arlington (VA)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Argo Cyber Systems, LLC is seeking an experienced Cyber Incident Manager - Computer Network Defense to lead incident response for a high-profile U.S. Government customer. You will oversee triage, analysis, and resolution across federal civilian networks and critical assets.

The role requires active TS/SCI clearance, a Bachelor's in a related field, and 5+ years in cyber incident management or SOC/DFIR. On-site Arlington, VA with shift-based duties.

Qualifications

  • U.S. Citizenship required.
  • Active TS/SCI clearance required.
  • Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related field.
  • Ability to obtain DHS EOD suitability.
  • 5+ years in cyber incident management or SOC/DFIR operations.
  • Strong incident response methodologies, containment, and recovery knowledge.
  • Experience with NIST SP 800-61 and FISMA reporting.

Responsibilities

  • Lead incident response and cyber defense operations for allocated networks.
  • Correlate incident data to identify trends and vulnerabilities.
  • Perform CND triage, assess scope, urgency, and impact of events.
  • Develop and recommend defense-in-depth strategies and resilience improvements.
  • Document resolutions and mitigations for enterprise recovery.
  • Apply threat intelligence to detect and respond to intrusions.
  • Monitor threat data sources and maintain situational awareness.
  • Lead root-cause investigations and document attacker methodologies.
  • Review security alerts and escalate as needed.
  • Maintain comprehensive incident reports and lessons learned.

Skills

Incident management
SOC/DFIR
Triage & analysis
Defense-in-Depth
Threat intelligence
NIST SP 800-61
FISMA reporting
Leadership
Communication

Education

Bachelor's Degree in Cybersecurity / CS

Tools

Splunk
SentinelOne
CrowdStrike
ServiceNow

Job description

Computer Network Defense Incident Manager III

Location: Arlington, VA (On-Site)

Citizenship: US only

Clearance: Active TS/SCI (DHS EOD Suitability required)

Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned Small Business (SDVOSB)

Argo Cyber Systems provides mission-critical cybersecurity support to U.S. Government agencies and critical infrastructure owners nationwide. Our teams deliver rapid incident response, advanced forensics, and coordinated recovery operations to protect vital systems from evolving cyber threats. We combine technical precision with operational agility-helping federal partners identify, contain, and recover from complex cyber incidents with speed and confidence.

Argo Cyber Systems is seeking an experienced Cyber Incident Manager - Computer Network Defense to lead and coordinate incident response operations for a high-profile U.S. Government customer. The Incident Manager will oversee the triage, analysis, and resolution of cybersecurity events across federal civilian networks and critical assets. This role requires a mix of technical depth, investigative skill, and the ability to synthesize complex data into actionable recommendations for both technical and executive audiences.

Role and Responsibilities
  • Lead and manage incident response and cyber defense operations, ensuring timely containment, eradication, and recovery.
  • Correlate and analyze incident data to identify trends, adversary tactics, and systemic vulnerabilities.
  • Conduct Computer Network Defense (CND) triage, assessing scope, urgency, and operational impact of security events.
  • Develop and recommend Defense-in-Depth strategies, layered defense architectures, and resilience improvements.
  • Research and document resolutions and mitigations to support enterprise recovery and strengthen future defenses.
  • Apply cybersecurity and threat intelligence concepts to detect, analyze, and respond to intrusions in both small and large-scale network environments.
  • Monitor and assess external threat data sources to maintain situational awareness and anticipate potential impacts to the enterprise.
  • Lead the investigation of incident root causes, infection vectors, and attacker methodologies.
  • Receive, analyze, and validate security alerts from enterprise monitoring tools, escalating as appropriate.
  • Track and document all incident response activities from detection through closure, ensuring comprehensive reporting and lessons learned.
  • Support continuous improvement by refining processes, updating playbooks, and mentoring junior analysts.
Qualifications, Education and Skills Requirements
  • U.S. Citizenship (required)
  • Active TS/SCI clearance (required)
  • Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related discipline
  • Ability to obtain DHS Entry on Duty (EOD) Suitability
  • 5+ years of hands-on experience in cyber incident management or SOC/DFIR operations
  • Deep understanding of incident response methodologies, containment strategies, and recovery workflows
  • Working knowledge of NIST SP 800-61 Rev.2 (Computer Security Incident Handling Guide) and FISMA incident reporting standards
  • Strong ability to analyze, prioritize, and document incidents, including phishing, lateral movement, and privilege escalation cases
  • Comprehensive understanding of cyberattack lifecycle stages and adversary tactics, techniques, and procedures (TTPs)
  • Proficiency in identifying vulnerabilities, threat vectors, and exploitation patterns
  • Knowledge of operating system hardening, network defense, and system administration fundamentals
  • Familiarity with nation-state, criminal, and opportunistic threat actor profiles and their operational tradecraft
  • Excellent communication, coordination, and leadership skills in high-pressure, mission-driven environments
Additional Desires and Considerations
  • Proficiency with enterprise SIEM, EDR, and incident management platforms (e.g., Splunk, SentinelOne, CrowdStrike, ServiceNow)
  • Experience leading shift-based operations or 24x7 response teams
  • Deep knowledge of malware, intrusion detection, and threat hunting techniques
  • Familiarity with log analysis, packet capture, and intrusion detection systems (IDS/IPS)
  • Strong understanding of MITRE ATT&CK framework and cyber kill chain methodology
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Intrusion Analyst (GCIA/GCED)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cyber Forensics Professional (CCFP) or equivalent
Additional Information
  • Shift work position; schedule determined upon start.

  • ECP-1 rates apply.

  • Must be available for onsite support during active incidents or surge operations.

Why Join Argo

As part of Argo Cyber Systems, you will serve at the forefront of national cyber defense-protecting civilian agencies and high-value assets from persistent and emerging threats. You'll join a veteran-founded, mission-driven team dedicated to operational excellence, collaboration, and innovation in the cyber domain.

Company Benefits

ARGO Cyber Systems provides industry competitive employee benefits to include medical, dental, vision, life insurance, and 401K.

Argo Cyber Systems is a Federal Contractor and an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Manager Level II
Cyber Incident Manager Level II

argocyber • Arlington (VA)

On-site
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Incident Response Expert III
Incident Response Expert III

ARGO Cyber Systems • Arlington (VA)

On-site
USD 100,000 - 125,000
Cyber Threat intelligence Analyst II
Cyber Threat intelligence Analyst II

argocyber • Arlington (VA)

On-site
USD 90,000 - 120,000
Cyber Network Defense Analyst (CNDA) III – Cloud Forensics
Cyber Network Defense Analyst (CNDA) III – Cloud Forensics

argocyber • Arlington (VA)

Hybrid
USD 100,000 - 130,000
Cyber Threat intelligence Analyst II
Cyber Threat intelligence Analyst II

ARGO Cyber Systems • Arlington (VA)

On-site
USD 70,000 - 85,000
Senior Cyber Incident Manager - Network Defense (On-Site)
Senior Cyber Incident Manager - Network Defense (On-Site)

argocyber • Arlington (VA)

On-site
USD 140,000 - 190,000
Cyber Systems Engineer II
Cyber Systems Engineer II

argocyber • Arlington (VA)

On-site
USD 75,000 - 95,000
Medical insurance
Dental insurance
Vision insurance
+2
Business Process Analyst III – IT Requirements Manager
Business Process Analyst III – IT Requirements Manager

ARGO Cyber Systems, LLC • Arlington (VA)

On-site
USD 95,000 - 140,000
Business Process Analyst III – IT Requirements Manager
Business Process Analyst III – IT Requirements Manager

ARGO Cyber Systems • Arlington (VA)

On-site
USD 85,000
Business Process Analyst III – IT Requirements Manager
Business Process Analyst III – IT Requirements Manager

argocyber • Arlington (VA)

On-site
USD 110,000 - 150,000