Cyber Defense Cloud Incident Responder

ASRC Federal

Fort Meade (MD)

On-site

USD 106,000 - 160,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ASRC Federal is seeking a Cyber Defense Incident Responder with cloud experience to support a mission-critical DCSA cybersecurity program. The role focuses on detecting, analyzing, and responding to security incidents in cloud-hosted and hybrid environments supporting national security systems. Remote flexibility is available with telework, onsite up to one day a week at Ft.

Meade, MD. The position emphasizes threat hunting, threat detection innovations, and collaboration with CSOC colleagues

Qualifications

  • Five years of hands-on cybersecurity experience in incident response or threat hunting.
  • Active Top Secret clearance required, eligible to be upgraded to TS/SCI.
  • DoD 8570.01-M / IAT II or IAM II requirements; at least one active qualifying certification.
  • Bachelor’s Degree in Cybersecurity and/or Information Systems Management or equivalent.

Responsibilities

  • Cloud Security Operations & Monitoring across AWS, Azure, and Google Cloud.
  • Analyze logs, telemetry, and cloud audit data for indicators of compromise.
  • Lead and support incident response across the full lifecycle: identification, containment, eradication, recovery, lessons learned.
  • Map adversary activity to MITRE ATT&CK and cloud threat models.
  • Coordinate response actions with SOC analysts, engineering teams, and government stakeholders.
  • Document incidents and remediation in accordance with government reporting requirements.
  • Identify cloud misconfigurations and support vulnerability remediation in cloud-hosted systems.
  • Support compliance with NIST 800-53, RMF, and DoD requirements.

Skills

Cloud security
SIEM/SOAR
Incident response
Threat hunting
Networking & systems
MITRE ATT&CK mapping
NIST RMF/CWQP

Education

Bachelor's degree in Cybersecurity or Information Systems Management

Tools

Splunk
Elastic
Swimlane
AWS GuardDuty
Defender for Cloud
Security Command Center

Job description

Posted Friday, August 21, 2026 at 4:00 AM

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are atop veteran employer and Certified Great Place to Work™

ASRC Federal is seeking aCyber Defense Incident Responder with cloud experienceto support a mission-critical DCSA cybersecurity program. This role is responsible for detecting, analyzing, and responding to security incidents affecting cloud-hosted and hybrid environments supporting national security systems.

Remote flexibility available! Telework offered with a requirement to be onsite up to one (1) day a week at Ft. Meade, MD.

Position Description:

As the Cyber Defense Analyst, your primary duty is to safeguard our national security systems through proactive threat hunting and advanced threat detection activities. You will continuously monitor and analyze threat intelligence sources to stay informed about emerging threats, searching for signs of malicious activity across our network infrastructure, endpoints, and systems that evade traditional security solutions. A key part of your role involves developing and implementing new and innovative threat detection techniques and strategies, analyzing large datasets to identify patterns and anomalies indicative of malicious activities, and mapping adversary tactics to the MITRE ATT&CK framework. You will collaborate with other CSOC team members and stakeholders to respond to and investigate security incidents, perform in-depth forensic analysis to understand the nature and impact of threats, and provide detailed reports and briefings on threat hunting activities and findings to senior management.

  • Five (5) years’ hands-on cybersecurity experiencein one or more of the following:
  • Incident Response or Threat Hunting within a mid-to-large enterprise
  • SOC operations supporting cloud or hybrid environments
  • Enterprise vulnerability management or endpoint/cloud security operations
  • Active Top Secret (TS) Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • DoD 8570Information Assurance (IA) Program/DoD8140Cyber Workforce Qualification Program (CWQP):Must meet DoD 8570.01-M / IAT Level II or IAM Level II requirements at a minimum. At leastone active qualifying certificationrequired, including but not limited to:
  • Bachelor’s Degree, in Cybersecurity, and/or Information Systems Management or equivalent combination of education, experience and military service
Key Responsibilities:
  • Cloud Security Operations & Monitoring
  • Monitor AWS, Azure, and/or Google Cloud environments for malicious or anomalous activity using SIEM, SOAR, and cloud-native security tooling.
  • Analyze logs, telemetry, alerts, and cloud audit data to identify indicators of compromise (IOCs) and attack patterns.
  • Tune detection logic and alerting to reduce false positives and improve response fidelity.
  • Lead and support incident response activities across the full lifecycle:identification, containment, eradication, recovery, and lessons learned.
  • Perform root cause analysis and impact assessments for cloud-related security incidents.
  • Coordinate response actions with SOC analysts, engineering teams, system owners, and government stakeholders.
  • Document incidents, response actions, and remediation recommendations in accordance with government reporting requirements.
  • Leverage threat intelligence sources to identify emerging threats targeting cloud platforms and federal environments.
  • Map adversary activity to MITRE ATT&CK and cloud-specific threat models.
  • Recommend defensive improvements based on observed tactics, techniques, and procedures (TTPs).
  • Vulnerability & Risk Management
  • Identify cloud misconfigurations, exposed services, and security gaps.
  • Support vulnerability assessments and remediation prioritization for cloud-hosted systems.
  • Advise on security controls aligned to NIST and DoD requirements.
  • Compliance & Audit Support
  • Support compliance activities aligned toNIST 800-53, RMF, and DoD cybersecurity requirements.
  • Assist with security documentation, evidence collection, and audit response.
  • Validate cloud security configurations against established baselines and policies.
Required Technical Skills:
  • Cloud Platformexperience:Practical experience securing AWS, Azure, and/or Google Cloud environments
  • Security Tooling:Experience with SIEM/SOAR platforms such as Splunk, Elastic, Swimlane, or equivalent
  • Incident Response:Proven experience executing IR playbooks and responding to real-world security incidents
  • Networking & Systems:Strong understanding of TCP/IP, DNS, authentication mechanisms, operating systems,log analysis,and cloud architecture
  • Frameworks & Standards:Familiarity with NIST Cybersecurity Framework, NIST 800-53, and RMF concepts
  • Analysis & Reporting:Ability to clearly document findings, response actions, and technical recommendations
Desired (Nice-to-Have) Qualifications:
  • Experience supporting classified or DoD environments
  • Familiarity with cloud-native security services (e.g.,AWSGuardDuty,AWS Security Hub,Defender for Cloud, Security Command Center)
  • Experience with automation, scripting, or SOAR workflows
  • Exposure to threat hunting or advanced adversary analysis
Work Environment and Physical Demands:
  • This is primarily a Telework position with a requirement to be onsite up to one (1) day a week. Full-time onsite presence at Fort Meade may berequired in the future at the government’s discretion
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of$106,015.00 - $159,890.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Threat Analyst
Cloud Threat Analyst

ASRC Federal • Hanover (MD)

Hybrid
USD 115,000 - 135,000
Health benefits
401(k)
Education assistance
+1
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Virginia (MN)

On-site
USD 110,000 - 150,000
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Quantico (VA)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+5
Cyber Defense Incident Responder - Swing Shift
Cyber Defense Incident Responder - Swing Shift

ASRC Federal • Quantico (VA)

On-site
USD 90,000 - 120,000
Health care
401(k)
Education assistance
+1
Senior Cyber Tools Architect/Engineer
Senior Cyber Tools Architect/Engineer

ASRC Federal • Quantico (VA)

Hybrid
USD 140,000 - 210,000
Health care
Dental
Vision
+4
Remote Cloud Cyber Defense Incident Responder
Remote Cloud Cyber Defense Incident Responder

ASRC Federal • Fort Meade (MD)

Hybrid
USD 106,000 - 160,000
Cybersecurity Program Manager
Cybersecurity Program Manager

ASRC Federal • Reston (VA)

Hybrid
USD 120,000 - 160,000
Health insurance
401(k)
Education assistance
+1
Penetration Tester
Penetration Tester

ASRC Federal • Washington

Hybrid
USD 120,000 - 180,000
Health insurance
401(k) plan
Education assistance
+1
Elastic SIEM Engineer
Elastic SIEM Engineer

ASRC Federal • Hanover (MD)

Hybrid
USD 150,000 - 166,000
Health care
Dental insurance
Vision insurance
+4
Senior Operations & Maintenance Support - TS/SCI clearance required
Senior Operations & Maintenance Support - TS/SCI clearance required

ASRC Federal • Patterson (OH)

On-site
USD 120,000 - 150,000
Competitive pay
Health care
401(k)
+2