Incident Response Engineer — Threat Hunting & Forensics

Dunhill Professional Search & Government Solutions

Arlington (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Dunhill Professional Search & Government Solutions is seeking an Incident Response Engineer Journeyman to detect, triage, and remediate security incidents affecting mission-critical systems in a highly regulated government environment.

You will analyze alerts, lead triage activities, and coordinate containment and recovery with operations, IT, and mission stakeholders. The role emphasizes threat hunting, playbook maintenance, and clear reporting to drive security improvements.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS, or related field, or equivalent experience.
  • Typically 5–7 years in security operations and incident response in regulated environments.
  • Experience triaging alerts, investigating incidents, and supporting containment.
  • Hands-on with SIEM platforms and endpoint or network security tools.
  • Proven log analysis, basic malware analysis, and evidence preservation skills.
  • Active TS/SCI security clearance.
  • U.S. citizenship is required to support federal IT environments.

Responsibilities

  • Detect, triage, and validate security events from SIEM, endpoint, network, and cloud tools.
  • Lead containment and recovery efforts with system owners to minimize mission impact.
  • Conduct host and network forensics and malware analysis to determine root cause.
  • Maintain incident response playbooks, procedures, and tooling.
  • Participate in proactive threat hunting using telemetry and threat intel.
  • Tune SIEM rules and tooling to improve detection and reduce noise.
  • Generate incident reports, metrics, and post‑incident reviews.
  • Support tabletop exercises and incident communications to improve readiness.

Skills

Incident Response
Threat Hunting
Forensics
SIEM Knowledge

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Splunk
Elastic
QRadar

Job description

Dunhill Professional Search & Government Solutions is seeking an Incident Response Engineer Journeyman to detect, triage, and remediate security incidents affecting mission-critical systems in a highly regulated government environment.

You will analyze alerts, lead triage activities, and coordinate containment and recovery with operations, IT, and mission stakeholders. The role emphasizes threat hunting, playbook maintenance, and clear reporting to drive security improvements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Engineer - TS/SCI
Incident Response Engineer - TS/SCI

Dunhill Professional Search & Government Solutions • Arlington (VA)

On-site
USD 120,000 - 160,000
Senior Incident Response Lead: Threat Detection & Playbooks
Senior Incident Response Lead: Threat Detection & Playbooks

Dnb • Jacksonville (FL)

On-site
USD 110,000 - 150,000
Parental leave
Education assistance
Volunteer days
+3
Incident Response Engineer - TS/SCI
Incident Response Engineer - TS/SCI

Dunhill Solutions • Arlington (VA)

Hybrid
USD 125,000 - 142,000
Security Incident Response Engineer - Threat Hunter & IR
Security Incident Response Engineer - Threat Hunter & IR

Acrisure • Grand Rapids (MI)

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+2
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Senior Incident Response Lead: Threat Hunting & Automation
Senior Incident Response Lead: Threat Hunting & Automation

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Incident Responder & Threat Hunter
Senior Incident Responder & Threat Hunter

Halliburton • Houston (TX)

On-site
USD 120,000 - 180,000
Benefits package
Threat Hunter & Detection Engineer - Cyber Defense
Threat Hunter & Detection Engineer - Cyber Defense

Partner Forces LLC • Arlington (VA)

On-site
USD 110,000 - 140,000
Remote Threat Detection Engineer (SIEM & Threat Hunting)
Remote Threat Detection Engineer (SIEM & Threat Hunting)

Beacon Hill Staffing Group, LLC • Oklahoma City (OK)

On-site
USD 90,000 - 140,000
Detection Engineer - Threat Hunter
Detection Engineer - Threat Hunter

ECS Corporate Services • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Top Secret Clearance