Incident Response Lead

Everforth ECS

Washington (District of Columbia)

Hybrid

USD 140,000 - 190,000

Full time

9 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS in Washington, DC seeks an experienced Incident Response Lead to join our security operations team. In this Tier 3 role, you own end-to-end incident response, drive containment and remediation, and report timelines to senior leadership.

You will hunt threats, develop detection mechanisms, refine playbooks, and mentor staff across Windows, Linux, and cloud environments such as AWS, Azure, and GCP to strengthen enterprise defenses.

Qualifications

  • 6+ years of progressive experience in security operations and incident response.
  • Experience leading incident response efforts in an enterprise environment.
  • Experience with MITRE ATT&CK and Cyber Kill Chain.
  • Ability to develop incident response playbooks and runbooks.

Responsibilities

  • Lead incident response efforts end to end: containment, remediation, and post‑incident reporting to senior leadership.
  • Hunt threats and develop detection mechanisms across enterprise environments.
  • Refine processes and incident investigation procedures to improve detection and response.
  • Collaborate with networking, systems, and technology support teams as the senior escalation SME.

Skills

Incident response
Threat hunting
Threat detection
Malware triage
Security operations
Executive communication

Education

Bachelor's degree in CS/Cybersecurity/IT

Tools

SIEM
EDR
IDS/IPS
Vulnerability scanners
Malware analyzers

Job description

WASHINGTON, District Of Columbia, United States

Job Description

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office /remote. The role is contingent upon additional funding.

We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.

Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.

  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures

Threat Hunting & Detection Engineering

  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes

Security Operations

  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks
  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.

Desired Skills
  • Experience with behavior-based analytics and anomaly detection techniques
  • Cloud forensics and incident response experience in SaaS or multi-tenant environments
  • Familiarity with threat modeling and development of countermeasures
  • Scripting and automation experience in Python, PowerShell, Bash, or Perl
  • Experience developing or refining detection logic, exclusions, and tuning within enterprise security tooling
  • Quality assurance and continuous improvement experience within a security operations context
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent hands-on experience
  • Relevant certifications such as GCIH, GCFA, GCFE, CISSP, or equivalent are strongly preferred

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment ofEverforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:

  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

undefined

Our Company

Our Culture

Employer Privacy Policy

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

Meet the challenge. Make a difference with Everforth ECS!

EEO is the Law

ADP Privacy Statement Artificial Intelligence Google Privacy Policy Google Terms of Service

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior DevOps / Cloud Engineer
Senior DevOps / Cloud Engineer

Everforth ECS • Arlington (VA)

Hybrid
USD 140,000 - 190,000
Health insurance
401(k) matching
Professional development
Field Operations Lead
Field Operations Lead

Everforth ECS • Merrifield (VA)

Hybrid
USD 120,000 - 180,000
Enterprise Vulnerability Assessment Program- AI Focused
Enterprise Vulnerability Assessment Program- AI Focused

ECS • Washington

On-site
USD 160,000 - 205,000
Cloud Engineer - MID
Cloud Engineer - MID

Everforth ECS • Merrifield (VA)

On-site
USD 110,000 - 150,000
Technical Project Manager
Technical Project Manager

Everforth ECS • Arlington (VA)

On-site
USD 150,000 - 190,000
Senior Security Engineer
Senior Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
Senior Cyber Incident Analyst
Senior Cyber Incident Analyst

ECS • Arlington (VA)

On-site
USD 170,000 - 180,000
Data Analyst
Data Analyst

Everforth ECS • Merrifield (VA)

On-site
USD 85,000 - 115,000
Sr. Mission Integration Strategist
Sr. Mission Integration Strategist

ECS • Arlington (VA)

On-site
USD 200,000 - 250,000