Cyber Defense Incident Responder - Swing Shift

ASRC Federal

Quantico (VA)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health care
401(k)
Education assistance
Paid time off

Job summary

ASRC Federal is seeking a highly skilled Cyber Incident Responder for on-site work at Quantico, VA. The role supports DoD missions by detecting, triaging, containing, and eradicating cyber threats, with swing shift coverage including weekends and holidays.

You will work with SIEM, SOAR, CrowdStrike, CyberArk, and ESS, coordinate with DoD partners, and maintain incident playbooks while ensuring regulatory compliance and rapid recovery across enterprise systems.

Qualifications

  • Active Secret Clearance required, eligible to upgrade to TS/SCI.
  • DoD and NIST-based standards experience.
  • Swing shift, on-site at Quantico, weekend/holiday rotation.
  • Bachelor’s degree in IT, Information Systems Management, Cyber Security, or equivalent.
  • DoD 8570 certification requirements at hire — IAT II; GICSP, GSEC, CCNA Security, CySA+ or GCFA preferred.

Responsibilities

  • Detect, triage, contain, and eradicate incidents in real time across enterprise systems.
  • Coordinate with DoD partners and internal teams for incident reporting and remediation.
  • Maintain incident response playbooks and SOPs; document evidence and case files.
  • Perform investigations and forensics to identify indicators of compromise and root causes.
  • Prepare regular incident trend reports and escalation packages for leadership.

Skills

Incident Detection
Incident Response
Containment & Eradication
Forensics & Investigation
Malware Analysis
Documentation
Reporting
Communication

Education

Bachelor's degree in IT / Cyber Security

Tools

SIEM
SOAR
CrowdStrike
CyberArk
Endpoint Security Suite (ESS)

Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™

ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the swing shift (1400 - 0000), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA — no telework is available for this role.

The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.

Position Description

The Cyber Incident Responder is a vital role responsible for executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).

The Incident Responder will collaborate with cross-functional IT and security teams to:

  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours
Minimum Requirements
  • At least two (2) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
  • Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire — IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.
  • Willingness and availability to work the swing shift (1400 - 0000), including weekend and holiday rotations, fully on-site at Quantico, VA.
Required Skills
  • Incident Detection & Triage: Monitor security alerts and events from SIEM, EDR, IDS/IPS, firewall, DNS, and ESS sources to rapidly detect, triage, and prioritize potential security incidents.
  • Incident Response Lifecycle: Execute the full incident response lifecycle - preparation, detection and analysis, containment, eradication, recovery, and post-incident activity - in accordance with NIST SP 800-61.
  • Containment & Eradication: Take decisive containment and eradication actions on compromised endpoints, accounts, and systems to limit incident impact.
  • Cyber Task Management: Process and handle JFHQ-DODIN cyber-related tasks, orders, and incident reporting requirements to completion within required timelines.
  • Investigation & Forensics: Identify evidence of illegal activity involving cybercrime offenses; examine computers potentially involved in crime or malware infection and preserve forensic evidence following chain-of-custody procedures.
  • Malware Analysis: Use forensic tools and investigative methods to identify, isolate, and analyze specific electronic data associated with complex malware infections.
  • Incident Documentation: Develop and maintain incident response playbooks, standard operating procedures (SOPs), and detailed incident case documentation.
  • Reporting & Escalation: Provide timely incident reports and escalations to senior leadership and deliver daily/weekly/monthly summaries on incident trends and key indicators of network security.
Work Environment And Physical Demands
  • This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.
  • Must work the assigned swing shift (1400 - 0000) and support weekend and holiday coverage as scheduled.
  • Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages.

  • Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.

The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Quantico (VA)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+5
Cyber Incident Responder (24x7 Days)
Cyber Incident Responder (24x7 Days)

ASRC Federal • Virginia (MN)

On-site
USD 110,000 - 150,000
Cyber Defense Cloud Incident Responder
Cyber Defense Cloud Incident Responder

ASRC Federal • Fort Meade (MD)

On-site
USD 106,000 - 160,000
RMF Cybersecurity Analyst
RMF Cybersecurity Analyst

ASRC Federal • Virginia (IL), Northern (KY)

Hybrid
USD 90,000 - 120,000
Health care
Dental
Vision
+4
Cyber Incident Responder — On-Site, Swing Shift (VA)
Cyber Incident Responder — On-Site, Swing Shift (VA)

ASRC Federal • Quantico (VA)

On-site
USD 90,000 - 120,000
Health care
401(k)
Education assistance
+1
Cloud Threat Analyst
Cloud Threat Analyst

ASRC Federal • Hanover (MD)

Hybrid
USD 115,000 - 135,000
Health benefits
401(k)
Education assistance
+1
On-Site Cyber Incident Responder — Day Shift
On-Site Cyber Incident Responder — Day Shift

ASRC Federal • Virginia (MN)

On-site
USD 110,000 - 150,000
Senior Cyber Tools Architect/Engineer
Senior Cyber Tools Architect/Engineer

ASRC Federal • Quantico (VA)

Hybrid
USD 140,000 - 210,000
Health care
Dental
Vision
+4
Cloud Threat Analyst
Cloud Threat Analyst

ASRC Federal Holding Company • Hanover (MD)

Hybrid
USD 115,000 - 135,000
Cyber Incident Responder - Day Shift On-Site (Quantico)
Cyber Incident Responder - Day Shift On-Site (Quantico)

ASRC Federal • Quantico (VA)

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+5