Lead Cyber Defense Incident Responder TS/SCI

S2i2, Inc

Arlington (VA)

On-site

USD 165,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Professional certification support
Leadership accessibility
Regular company updates
Team-building activities

Job summary

S2i2, Inc. is seeking a Lead Cyber Defense Incident Responder in Arlington, VA. This highly experienced role combines hands-on technical work with leadership of a security analytics team operating in TS/SCI and SAP environments.

Expect threat hunting, malware research, and development of advanced detection across enclaves. The role requires TS/SCI clearance, DoD 8570/8140 IAT Level II certifications, and a proactive, high-integrity approach to protecting highly secure networks.

Qualifications

  • Bachelor's degree in Computer Science, Digital Forensics, or a related major with emphasis on security preferred.
  • Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.
  • Demonstrated leadership skills, preferably in a formal leadership role.
  • Scripting experience.
  • TS/SCI clearance is required.

Responsibilities

  • Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients.
  • Serve as the primary technical point of contact for complex threat hunting issues and mentor new team members.
  • Engineer advanced detection rules for endpoints, cloud services, network devices, and other sources across classified enclaves.
  • Research new malware using hunting capabilities and through partnerships with security researchers, adhering to strict protocols.
  • Lead targeted phishing campaigns to educate the workforce on social engineering risks.
  • Lead purple and red teaming efforts as directed for highly classified networks.
  • Coordinate NOSC schedules to ensure on-call coverage for after-hours, weekends, and holidays.
  • Maintain the ID Team toolkit and evaluate new technologies for deployment.
  • Conduct investigations and communicate findings effectively to government clients.
  • Ensure that written communications are professional, high-quality, and actionable.

Skills

Threat hunting
Security research
Incident response
Leadership
Scripting

Education

Bachelor's degree in Computer Science or related security field

Tools

Splunk SPL
Kusto (KQL)
Elastic Kibana
Carbon Black
Snort

Job description

Job Title Lead Cyber Defense Incident Responder

Clearance TS/SCI (active, required)

Location Arlington, VA On-site

Salary Range $165,000 to $180,000

Certification Required DoD 8570 / DoD 8140 IAT Level II; One of the following: Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, or equivalent

Application Deadline September 30, 2026

The Cyber Defense Incident Responder (Advanced) is a highly experienced, analytical professional who performs hands-on technical work while guiding and directing senior and mid-level analysts. This role involves advanced threat detection, threat intelligence research, practical application of threat intelligence to operations, developing custom scripts, and understanding complex threat actor techniques used to compromise systems and evade detection. The ideal candidate has extensive operational experience defending highly secure enclaves, specifically navigating Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) networks.

Duties and Responsibilities
  • Lead a small team of advanced and mid-level security analysts to provide Incident Defense (ID) services for government clients, specifically tailored to the unique security constraints of TS/SCI and SAP environments.
  • Serve as the primary technical point of contact for complex threat hunting issues and mentor new ID team members to grow their skills and operational abilities.
  • Engineer advanced detection alerting rules for events reported by endpoints, cloud services, network devices, and other relevant event sources across classified enclaves. This includes utilizing Splunk SPL, Microsoft Kusto Query Language (KQL), Elastic Kibana Query Language, Carbon Black, Snort rules, or other pattern-matching detection tools.
  • Proactively research new malware using hunting capabilities on malware repository services (such as VirusTotal) and through established partnerships with other security researchers, ensuring all malware handling adheres to strict, classified network protocols.
  • Lead targeted phishing campaigns to help educate the workforce on the risks of social engineering and malicious attachments.
  • Lead purple and red teaming efforts as directed, conducting adversary emulation relevant to the architecture of highly classified networks.
  • Provide critical support to the NOSC and coordinate team schedules to ensure on-call coverage for after-hours, weekends, and holidays.
  • Maintain the toolkit utilized by the ID Team. Conduct research analysis on the latest cybersecurity tools, provide rationale to renew or deprecate current tools, and make recommendations for employing new technologies within the enterprise.
  • Perform comprehensive research and investigations with little to no oversight to locate information relevant to government requests, communicating findings effectively to clients (typically interfacing with government information security professionals).
  • Ensure that all written communication (reports, briefings, and alerts) is professional, high-quality, free of errors, and clearly delivers actionable intelligence.
Minimum Qualifications and Requirements
  • Bachelor's degree in Computer Science, Digital Forensics, or a related major with an emphasis on security preferred.
  • Six (6+) years of experience in Threat Hunting, Security Research, or Incident Response.
  • Demonstrated leadership skills, preferably in a formal leadership role.
  • Scripting experience.
  • TS/SCI clearance is required.
Knowledge, Skills, and Abilities
  • Advanced technical expertise in threat hunting, deep-dive malware analysis, and the operational application of threat intelligence within highly classified (TS/SCI and SAP) network enclaves.
  • Demonstrated leadership and industry contribution, recognized as a subject matter expert within the defense or broader information security community for advancing incident response methodologies.
  • Proven track record of excellence in leadership, specifically in guiding, mentoring, and directing mid-level and senior information security professionals during active cyber operations and crisis response.
  • Government/client service experience: extensive experience serving as a primary technical liaison, providing Incident Defense (ID) and threat resolution services directly to government stakeholders and technical clients.
  • Security engineering and architecture: knowledge of planning, designing, and implementing robust security controls, detection rules, and defensive systems tailored to secure network architectures.
  • Adversary emulation: skill in executing red team or purple team adversary simulations to test and validate defensive postures against Advanced Persistent Threats (APTs).
  • Technical mentorship: experience teaching, mentoring, and guiding junior and mid-level analysts in advanced digital forensics and malware analysis techniques.
  • Advanced forensics: deep technical understanding of host and network-based forensic analysis techniques, with the ability to accurately interpret complex artifacts and maintain data integrity during investigations.
  • Malware and script analysis: high-level skill in reverse-engineering and analyzing obfuscated, malicious scripts (e.g., PowerShell, VBA, JavaScript, .NET) utilized by sophisticated threat actors.
  • Superior research capabilities: exceptional technical analysis and research skills, capable of proactively identifying novel threats and vulnerabilities.
  • Executive communication: excellent written and verbal communication skills, capable of producing high-quality, error-free incident reports and briefings suitable for government leadership.
  • Technical translation: ability to clearly explain highly complex cybersecurity incidents, TTPs, and risks to both technical peers and non-technical decision-makers.
  • Project and case management: proven ability to independently manage multiple complex incident investigations or research projects simultaneously, demonstrating high accountability, personal initiative, and integrity.
  • Crisis management: ability to take ownership during high-stress cyber incidents, rapidly set triage priorities, multitask effectively, and meet tight government reporting deadlines.
  • Collaboration: well-developed problem-solving and interpersonal skills to facilitate seamless coordination with Network Operations and Security Centers (NOSCs), intelligence teams, and external partners.
  • Attention to detail: excellent organizational skills with acute attention to detail, critical for maintaining chain-of-custody, accurate incident logging, and operating within strict SAP compliance frameworks.
About S2i2

S2i2 is a growing company with a supportive and inclusive culture and many opportunities for professional development and growth. We have created a supportive, family-like work environment where contributions are recognized. Regular company updates and open lines of communication with leadership fosters collaboration within the company.

We are proud to include:
  • Support to achieve professional certifications and degrees
  • Leadership that is accessible to all employees
  • Regular company updates
  • Client networking social engagements
  • Monthly team-building activities (past examples: Top Golf)
  • Supporting our community - including veterans

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cyber Defense Incident Responder On-site - TS/SCI
Lead Cyber Defense Incident Responder On-site - TS/SCI

S2i2, Inc • Arlington (VA)

On-site
USD 175,000 - 180,000
Professional certifications support
Leadership development
Regular company updates
+3
Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Senior Cyber Defense Incident Responder (TS/SCI)
Senior Cyber Defense Incident Responder (TS/SCI)

S2i2, Inc • Arlington (VA)

On-site
USD 165,000 - 180,000
Professional certification support
Leadership accessibility
Regular company updates
+1
Senior Incident Response Analyst
Senior Incident Response Analyst

Leidos Inc • Arlington (VA)

On-site
USD 131,000 - 238,000
Competitive compensation
Health and wellness programs
Paid leave
+1
Cybersecurity Engineer
Cybersecurity Engineer

SSI • Virginia Beach (VA)

On-site
USD 120,000 - 150,000
Medical Insurance
Vision Insurance
Dental Insurance
+4
Security Engineering Lead
Security Engineering Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 165,000 - 201,000
Cybersecurity Engineer
Cybersecurity Engineer

Storage Strategies, Inc. (SSI) • Virginia Beach (VA)

On-site
USD 110,000 - 170,000
Medical Insurance
Vision Insurance
Dental Insurance
+9
Computer Network Defense Analyst
Computer Network Defense Analyst

Age Solutions • Columbus (OH)

On-site
USD 85,000 - 98,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+2
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Cyber Tier 1 Deputy Team Lead
Cyber Tier 1 Deputy Team Lead

Leidos • Mississippi

On-site
USD 87,000 - 157,000