Incident Responder

G2IT

Suitland (MD)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

G2IT is seeking an Incident Responder to join a mission-focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) in Suitland, MD. You will serve as a digital first responder defending critical maritime intelligence networks, responding to incidents, containing systems, and supporting recovery in TS/SCI environments.

The role requires extensive experience in CND, SIEM, and network defense, with collaboration across security

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or related field desired; Master's preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with SIEM systems such as Splunk and Elastic.
  • Experience with NIDPS such as Cisco FirePower and Palo Alto NGFW, host tools Trellix ePO, Microsoft Defender, Tanium.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.

Responsibilities

  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit ESAFs to the NNWC Electronic Spillage Center.
  • Monitor DLP outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including SSOs, JAG, ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC/DoD SOC/DCO teams.
  • Maintain detailed incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.

Skills

Incident response
Cybersecurity operations
SIEM monitoring
Security coordination
Stakeholder communication

Education

Bachelor's degree preferred
Master's degree preferred
15+ years without a degree

Tools

Splunk
Elastic
Cisco FirePower
Palo Alto NGFW
Trellix ePO
Microsoft Defender
Tanium
Kali
SamuraiWTF
Nmap
Burp Suite
sqlmap
Metasploit

Job description

We are seeking an Incident Responderto join a mission focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) inSuitland, MD.

In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will respond to and investigate cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities
  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
  • Maintain detailed and accurate incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
Required Certifications
  • Must possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER).

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities.

As set forth in G2IT’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Responder – TS/SCI Defender
Cyber Incident Responder – TS/SCI Defender

G2IT • Suitland (MD)

On-site
USD 140,000 - 190,000
Incident Responder
Incident Responder

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Virginia (MN)

On-site
USD 85,000 - 105,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Incident Manager - I
Incident Manager - I

Base One Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Incident Manager II
Incident Manager II

Solutions³ LLC • Virginia (MN)

On-site
USD 90,000 - 130,000
Incident Manager II
Incident Manager II

Solutions3 LLC • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 150,000
Incident Manager II
Incident Manager II

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Cyber Incident Manager/ Incident Manager
Cyber Incident Manager/ Incident Manager

Node.Digital LLC • Arlington (VA)

On-site
USD 100,000 - 130,000