Incident Responder

G2IT, LLC.

Suitland (MD)

On-site

USD 130,000 - 190,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

G2IT, LLC. is seeking an experienced Incident Responder to join a mission-focused cyber defense team supporting the Office of Naval Intelligence (ONI) at HGCC in Suitland, MD.

You will act as a digital first responder to defend maritime intelligence networks and investigate incidents across the response lifecycle. You will work with cybersecurity, intelligence, and investigative partners to protect TS/SCI environments, handling escalations, ESAF submissions, DLP monitoring, and coordination with

Qualifications

  • Bachelor's degree in Cybersecurity, IT, IA, or related field desired; Master's preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with SIEM systems such as Splunk and Elastic.
  • Experience with NIDPS, such as Cisco FirePower and Palo Alto NGFW, plus host-based tools Trellix ePO, Defender, and Tanium.
  • Knowledge of scripting languages: Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tools: Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques.

Responsibilities

  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response for TS/SCI networks (JWICS, ATLAS).
  • Receive and respond to incident notifications via phone and email.
  • Prepare and submit ESAFs to the NNWC Electronic Spillage Center.
  • Monitor DLP outputs for classified code words and spillage indicators.
  • Coordinate with SSOs, JAG, ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS and others.
  • Maintain detailed incident documentation and timelines.
  • Participate in incident response meetings and after-action reviews.
  • Support execution and evaluation of annual security exercises.

Skills

Incident response
SIEM
NIDPS
Python
PowerShell
C/C++/Java
Cybersecurity analysis
DLP monitoring

Education

Bachelor's degree in Cybersecurity/IT/IA
Master's degree preferred

Tools

Splunk
Elastic
Cisco FirePower
Palo Alto NGFW
Trellix ePO
Microsoft Defender
Tanium
Kali
SamuraiWTF
Nmap
Burp Suite
sqlmap
Metasploit

Job description

We are seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) in Suitland, MD. In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will respond to and investigate cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities
  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
  • Maintain detailed and accurate incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
Required Certifications
  • Must possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Responder
Incident Responder

G2IT • Suitland (MD)

On-site
USD 140,000 - 190,000
Cyber Defense Analyst
Cyber Defense Analyst

G2IT, LLC. • Suitland (MD)

On-site
USD 120,000 - 180,000
Cyber Incident Responder – TS/SCI Defender
Cyber Incident Responder – TS/SCI Defender

G2IT • Suitland (MD)

On-site
USD 140,000 - 190,000
Senior Cyber Incident Responder (TS/SCI)
Senior Cyber Incident Responder (TS/SCI)

G2IT, LLC. • Suitland (MD)

On-site
USD 130,000 - 190,000
Incident Responder (3rd Shift)
Incident Responder (3rd Shift)

Via Logic LLC • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder (Weekend Night Shift)
Incident Responder (Weekend Night Shift)

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder (3rd Shift)
Incident Responder (3rd Shift)

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder (2nd Shift)
Incident Responder (2nd Shift)

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Health and Wellness programs
Income protection
Paid leave and retirement
Incident Manager - I
Incident Manager - I

Base One Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Incident Responder (Weekend Day Shift)
Incident Responder (Weekend Day Shift)

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000