Incident Response Team Lead

Agile Defense, LLC

Reston (VA)

Hybrid

USD 155,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Agile Defense, LLC is seeking an experienced Cyber Incident Response Team Lead to support a 24/7/365 CSOC program. The role leads investigations, forensic analyses (host, cloud, network) and develops countermeasures to protect critical assets across USG customers.

The ideal candidate has CISSP and 5+ years in incident response, SOC operations, or digital forensics, with hands-on use of SIEM, EDR, IPS/IDS, and CSOC ticketing. Hybrid onsite in Reston, VA is expected.

Qualifications

  • Five years of progressive professional experience in incident response, SOC, hunts or digital forensics.
  • Proficient use of cyber tools including SIEM, EDR, IDS/IPS and CSOC ticketing.
  • Familiarity with threat intelligence, incident handling, and reporting.

Responsibilities

  • Drive the incident response lifecycle from detection, analysis, escalation, to coordinated response across CSOC functions.
  • Develop and standardize incident response runbooks, playbooks and communication protocols; ensure evidence handling and documentation.
  • Monitor and improve MTTA/MTTR; capture lessons learned and implement corrective actions for future incidents.

Skills

Incident response
SOC analysis
Threat hunting
Forensics
Endpoint detection
SIEM
CSOC ticketing
TTPs

Education

BSc in CS/Cybersecurity

Tools

SIEM tools
EDR tools
IPS/IDS
Forensic tools
Network analysis tools

Job description

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests.

Requisition #: 1435

Job Title: Incident Response Team Lead

Location: Reston, VA

Clearance Level: TS (SCI Eligible)

Active Certified Information System Security Professional (CISSP)

SUMMARY

Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers. To support this vital mission, Agile Defense staff are on the forefront of providing Advanced CSOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. To ensure the integrity, security and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, technical analysis and incident response lifecycle. A strong work ethic, diligent time and attendance, written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.

JOB DUTIES AND RESPONSIBILITIES

Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions. Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation. Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.

QUALIFICATIONS Required Certifications

Certified Information System Security Professional (CISSP) and

One or more of the following certifications:

GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH); GIAC Certified Forensic Analyst (GCFA); SANS GIAC Certified Enterprise Defender (GCED) or

Other Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1.

Education, Background, and Years of Experience

Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security (or eight (8) years of relevant work experience in lieu of a degree).

ADDITIONAL SKILLS & QUALIFICATIONS
Required Skills

Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle.

Candidates must also exhibit proficient use of cyber tools, including but not limited to Security Information and Event Management (SIEM), network analysis, live response, endpoint detection and response tools, Intrusion Prevention / Detections Systems (IPS / IDS) and CSOC ticketing platforms.

Preferred Skills

One or more of the following GFCA, GPEN, GREM, GFNA, GIAC

Familiarity with Cloud environments

WORKING CONDITIONS
Environmental Conditions

Hybrid onsite in Reston, VA

Strength Demands
Physical Requirements

$155,000 - $180,000 a year

Our Core Values
  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Team Lead
Incident Response Team Lead

Agile Defense • Reston (VA)

On-site
USD 100,000 - 130,000
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense • Reston (VA)

On-site
USD 120,000 - 150,000
Deputy Program Manager
Deputy Program Manager

Agile Defense • Ashburn (VA)

Hybrid
USD 120,000 - 180,000
Security Engineering Lead
Security Engineering Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 165,000 - 201,000
Security Operations Center Manager
Security Operations Center Manager

Agile Defense • Reston (VA)

Hybrid
USD 120,000 - 150,000
Competitive benefits package
Supportive work culture
Mentorship opportunities
Digital Forensics Lead
Digital Forensics Lead

Agile Defense • Reston (VA)

On-site
USD 110,000 - 150,000
Security Engineering Lead
Security Engineering Lead

Agile Defense • Reston (VA)

On-site
USD 120,000 - 150,000
Competitive benefits package
Hybrid work environment
Lead Tier 2 SOC Analyst
Lead Tier 2 SOC Analyst

Agile Defense • Washington

On-site
USD 110,000 - 130,000
Health Insurance
Life Insurance
Paid Time Off
+4
Lead Cyber Defense Incident Responder On-site - TS/SCI
Lead Cyber Defense Incident Responder On-site - TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 175,000 - 180,000
Professional certifications support
Leadership development
Regular company updates
+3