Incident Response Lead

ECS Corporate Services

Washington (District of Columbia)

Hybrid

USD 140,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. You will join the advanced security operations team as a Tier 3 analyst leading end-to-end incident response and threat hunting initiatives.

The role requires 6+ years in security operations, with strong experience in MITRE ATT&CK, kill chain concepts, and playbook development. Expect collaboration across security, networking, and IT teams to strengthen defenses.

Qualifications

  • 6+ years of progressive security operations and incident response experience at senior or Tier 3 level.
  • Experience leading incident response efforts and communicating findings to leadership.
  • Familiarity with Cyber Kill Chain, MITRE ATT&CK, and Diamond Model frameworks.
  • Ability to perform malware triage, network analysis, and live response during incidents.
  • Experience developing incident response playbooks, runbooks, and SOPs.

Responsibilities

  • Lead incident response end-to-end: containment, remediation, timelines, and post-incident review.
  • Develop and document structured hunt plans and repeatable detections.
  • Create and refine detection mechanisms across multiple log sources.
  • Collaborate with teams across networking, systems, and technology support.
  • Communicate risk and incident status to senior leadership.

Skills

Lead incident response
Triage & containment
Remediation
Post-incident reporting
MITRE ATT&CK
Diamond Model
Malware triage
Network analysis
Playbooks & SOPs
Threat hunting
Log analysis
Automation & scripting
OS security (Windows/Linux/macOS)
Cloud security (AWS/Azure/GCP)

Tools

SIEM
Vulnerability scanners
Malware analyzers
IDS/IPS
EDR

Job description

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding. We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function. Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.

Salary Range: $140,000 - $150,000

General Description of Benefits
Incident Response & Threat Operations
  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures
Threat Hunting & Detection Engineering
  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes
Security Operations
  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks
Leadership & Collaboration
  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior Incident Response Lead - Remote
Senior Incident Response Lead - Remote

ECS • Washington

Hybrid
USD 140,000 - 150,000
Tier-3 Incident Response Lead – Remote
Tier-3 Incident Response Lead – Remote

ECS Corporate Services • Washington

Hybrid
USD 140,000 - 150,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

ECS Corporate Services • Washington

Hybrid
USD 155,000 - 165,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Consulting/Principal Security Engineer
Consulting/Principal Security Engineer

RELX • Raleigh (NC)

On-site
USD 104,900 - 174,700