Incident Response Team Lead

Agile Defense

Reston (VA)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading cybersecurity firm is seeking an experienced Incident Response Team Lead in Reston, VA. The candidate will oversee the incident response lifecycle, develop standardized procedures, and enhance team performance metrics. Essential qualifications include a Bachelor's degree in a related field or equivalent experience and a CISSP certification. The ideal candidate should possess strong analytical skills and deep knowledge of cybersecurity tools and threats. A hybrid working model is offered.

Qualifications

  • 5+ years of experience in incident response or SOC analyst roles with a focus on cybersecurity.
  • Proficient in tools like SIEM and endpoint detection tools.
  • Strong understanding of cyber threats and TTPs.

Responsibilities

  • Drive the incident response lifecycle from detection to escalation and coordinated response.
  • Develop incident response standard operating procedures.
  • Monitor and improve key performance metrics for the response team.

Skills

Incident detection and response
Forensic investigations
SIEM tools
Cyber threat analysis
Communication skills

Education

Bachelor of Science in computer science, engineering, STEM or cybersecurity

Tools

Endpoint detection and response tools
Network analysis tools
CSOC ticketing platforms

Job description

Requisition #: 1435

Job Title: Incident Response Team Lead

Location: Reston, VA

Clearance Level: TS (SCI Eligible)

Active Certified Information System Security Professional (CISSP)

SUMMARY

Agile Defense is seeking an experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep‑dive forensic investigations (host‑based, cloud and network), identifies and implements countermeasures, and tracks and reports on incident activity to USG customers. To support this vital mission, Agile Defense staff are on the forefront of providing advanced CSOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. A strong work ethic, diligent time and attendance, written and verbal communication skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTPs, threat actors, campaigns, and observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.

JOB DUTIES AND RESPONSIBILITIES

Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions. Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation. Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.

QUALIFICATIONS

Required Certifications:

  • Certified Information System Security Professional (CISSP)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • SANS GIAC Certified Enterprise Defender (GCED)
  • Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1

Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security (or eight (8) years of relevant work experience in lieu of a degree).

ADDITIONAL SKILLS & QUALIFICATIONS

Required Skills:

  • Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle.
  • Proficient use of cyber tools, including but not limited to SIEM, network analysis, live response, endpoint detection and response tools, IPS/IDS and CSOC ticketing platforms.

Preferred Skills:

  • GFCA, GPEN, GREM, GFNA, GIAC
  • Familiarity with Cloud environments
WORKING CONDITIONS

Environmental Conditions: Hybrid onsite in Reston, VA

Strength Demands: Physical Requirements

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense • Reston (VA)

On-site
USD 120,000 - 150,000
Senior Cyber Incident Response Lead
Senior Cyber Incident Response Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Security Operations Center Manager
Security Operations Center Manager

Agile Defense • Reston (VA)

Hybrid
USD 120,000 - 150,000
Competitive benefits package
Supportive work culture
Mentorship opportunities
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Deputy Program Manager
Deputy Program Manager

Agile Defense • Ashburn (VA)

Hybrid
USD 120,000 - 180,000
Threat Hunt Lead
Threat Hunt Lead

Agile Defense • Reston (VA)

Hybrid
USD 165,000 - 200,000
Digital Forensics Lead
Digital Forensics Lead

Agile Defense • Reston (VA)

On-site
USD 110,000 - 150,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Eliassen Group • Alexandria (VA)

Hybrid
Confidential
Medical, Dental, and Vision benefits
401k with company matching
Life insurance
Program Manager
Program Manager

Agile Defense • Reston (VA)

Hybrid
USD 170,000 - 225,000