Incident Response Engineer - TS/SCI

Dunhill Professional Search & Government Solutions

Arlington (VA)

On-site

USD 120,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Dunhill Professional Search & Government Solutions is seeking an Incident Response Engineer Journeyman to detect, triage, and remediate security incidents affecting mission-critical systems in a highly regulated government environment.

You will analyze alerts, lead triage activities, and coordinate containment and recovery with operations, IT, and mission stakeholders. The role emphasizes threat hunting, playbook maintenance, and clear reporting to drive security improvements.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, CS, or related field, or equivalent experience.
  • Typically 5–7 years in security operations and incident response in regulated environments.
  • Experience triaging alerts, investigating incidents, and supporting containment.
  • Hands-on with SIEM platforms and endpoint or network security tools.
  • Proven log analysis, basic malware analysis, and evidence preservation skills.
  • Active TS/SCI security clearance.
  • U.S. citizenship is required to support federal IT environments.

Responsibilities

  • Detect, triage, and validate security events from SIEM, endpoint, network, and cloud tools.
  • Lead containment and recovery efforts with system owners to minimize mission impact.
  • Conduct host and network forensics and malware analysis to determine root cause.
  • Maintain incident response playbooks, procedures, and tooling.
  • Participate in proactive threat hunting using telemetry and threat intel.
  • Tune SIEM rules and tooling to improve detection and reduce noise.
  • Generate incident reports, metrics, and post‑incident reviews.
  • Support tabletop exercises and incident communications to improve readiness.

Skills

Incident Response
Threat Hunting
Forensics
SIEM Knowledge

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Splunk
Elastic
QRadar

Job description

Job Description

The Incident Response Engineer Journeyman is a mid‑level cybersecurity professional responsible for detecting, investigating, and remediating security incidents affecting mission‑critical systems in a highly regulated government environment. This role analyzes security alerts, leads triage activities, and coordinates containment and recovery actions with operations, IT, and mission stakeholders. The engineer also contributes to threat hunting, maintains incident response playbooks and tooling, and produces clear reports and metrics to drive continuous improvement of security operations.

Key Responsibilities
  • Perform initial detection, triage, and validation of security events from SIEM, endpoint, network, and cloud security tools to distinguish true incidents from false positives and prioritize response.
  • Lead or support containment, eradication, and recovery efforts for cybersecurity incidents, coordinating with system owners and operations teams to minimize impact on mission‑critical systems.
  • Conduct host and network forensics, log analysis, and malware analysis to determine root cause, attack path, and data exposure, preserving evidence as needed.
  • Maintain and enhance incident response runbooks, playbooks, and standard operating procedures that align with organizational policies, regulatory frameworks, and evolving threat landscapes.
  • Participate in proactive threat hunting using security telemetry, threat intelligence, and behavioral analytics to identify stealthy or emerging threats in enterprise networks.
  • Configure, tune, and maintain incident response tooling and SIEM rules to improve detection fidelity, reduce noise, and enhance visibility across regulated environments.
  • Produce clear incident reports, metrics, and post‑incident reviews documenting timeline, impact, corrective actions, and recommendations for control improvements.
  • Collaborate with security training and awareness functions to support tabletop exercises, incident simulations, and communications that reinforce response readiness.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
  • Typically 5-7 years of experience in security operations and incident response with hands‑on exposure to forensics and SIEM in government or similarly regulated environments.
  • Demonstrated experience triaging security alerts, conducting incident investigations, and supporting containment and recovery activities.
  • Hands‑on experience with SIEM platforms and endpoint or network security tools used for incident detection and response.
  • Proven ability to perform log analysis, basic malware analysis, and evidence preservation to support reporting and potential regulatory needs.
  • Active TS/SCI security clearance
  • U.S. citizenship, as required to support a federal IT environment.
Preferred Qualifications
  • Experience with leading SIEM and incident response tools such as Splunk, Elastic, QRadar, or similar platforms.
  • Industry certifications such as GCIA, GCFA, GCIH, or equivalent incident response/forensics credentials.
  • Experience handling data spills or incidents involving sensitive or classified information under formal response frameworks.
  • Background participating in threat hunting operations and developing or refining incident response playbooks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Engineer - TS/SCI
Incident Response Engineer - TS/SCI

Dunhill Solutions • Arlington (VA)

Hybrid
USD 125,000 - 142,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Cybersecurity Incident Responder
Cybersecurity Incident Responder

DivIHN Integration Inc • Saint Paul (MN)

On-site
USD 70,000 - 100,000
Incident Response Analyst
Incident Response Analyst

Jobtailor • California (MO)

On-site
USD 110,000 - 150,000
Incident Manager II
Incident Manager II

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Incident Manager III
Incident Manager III

Solutions³ LLC • Arlington (VA)

On-site
USD 120,000 - 150,000
Incident Manager II
Incident Manager II

Solutions³ LLC • Virginia (MN)

On-site
USD 90,000 - 130,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Virginia (MN)

On-site
USD 85,000 - 105,000
Incident Manager I
Incident Manager I

Solutions³ LLC • Arlington (VA)

On-site
USD 90,000 - 130,000
Incident Response Expert - III
Incident Response Expert - III

Base One Technologies • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000