Job Description
Incident Response & Digital Forensics Lead
Work arrangement: Hybrid (1-2 days a week onsite)
Location: Germantown, Maryland
Employment type: Full-Time
Clearance requirement: Top Secret/RD
Position Overview
We are seeking an experienced Incident Response & Digital Forensics Lead to manage the day-to-day operations of a cybersecurity response team while remaining actively involved in technical investigations.
This is a hands-on leadership role supporting a federal customer. The successful candidate will lead incident response and digital forensic activities, coordinate directly with customer stakeholders, and translate complex findings into clear briefings and recommendations for senior federal leadership.
The role also provides technical support across cloud security, endpoint security, identity and access management, secure networking, and incident response. The ideal candidate has strong incident handling and forensic investigation experience, combined with the organizational and stakeholder-management skills of a mid-level project or program manager. This position requires some on-site work.
Key Responsibilities
- Manage the team’s daily operations, priorities, workload, assignments, and deliverables.
- Lead and participate directly in cyber incident investigations, forensic examinations, analysis, containment, eradication, and recovery activities.
- Coordinate incident response functions across technical teams, business stakeholders, vendors, and customer leadership.
- Serve as a primary point of contact for the customer during active incidents and related investigative activities.
- Prepare and deliver incident briefings, executive summaries, technical findings, status reports, and recommended courses of action to senior federal leadership.
- Collect, preserve, document, and analyze intrusion artifacts, including malware, malicious code, scripts, executables, logs, system images, and network evidence.
- Use investigative findings and threat intelligence to support containment, mitigation, remediation, and prevention of cyber defense incidents across the enterprise.
- Provide expert technical guidance to enterprise cyber defense analysts, engineers, administrators, and technicians working to resolve security incidents.
- Conduct or oversee forensic acquisition and analysis of endpoints, servers, mobile devices, cloud environments, and other relevant digital evidence.
- Maintain evidentiary integrity, chain-of-custody records, investigation notes, timelines, and other case documentation.
- Monitor relevant external information sources, including cybersecurity vendors, government advisories, Computer Emergency Response Teams, information-sharing organizations, and threat-intelligence providers.
- Assess emerging vulnerabilities, threats, tactics, techniques, and procedures for potential impact on the customer environment.
- Develop and improve incident response plans, playbooks, escalation procedures, forensic processes, reporting templates, and operational metrics.
- Coordinate lessons-learned reviews and ensure corrective actions are documented, assigned, and tracked through completion.
- Support technical cybersecurity activities involving cloud platforms, endpoint protection, identity and access management, network security, logging, and monitoring.
- Mentor team members and promote consistent investigative, technical, and documentation standards.
- Support incident response exercises, tabletop exercises, readiness assessments, and after-action reviews.
Required Qualifications
- Demonstrated professional experience in cybersecurity incident response, incident handling, and digital forensic investigations.
- Experience leading or coordinating a cybersecurity operations, incident response, or forensic investigation team.
- Ability and willingness to perform hands-on technical work while managing team operations and customer deliverables.
- Experience collecting, preserving, analyzing, and documenting digital evidence and intrusion artifacts.
- Working knowledge of Windows and Linux operating systems, enterprise networks, endpoint technologies, cloud environments, authentication systems, and security logging.
- Familiarity with common attacker tactics, techniques, and procedures, including the phases of an intrusion and methods used to establish persistence, evade detection, and exfiltrate data.
- Ability to assess technical evidence, determine incident scope and impact, and recommend ap