SOC Incident Commander: 24/7 Detection & Response

ECS

Richmond (VA)

On-site

USD 140,000 - 160,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Everforth ECS seeks an Incident Detection/Response Manager to lead a 24/7 SOC supporting a major federal civilian agency, focusing on rapid detection, containment, and recovery. You will direct Tier I–III incident response and drive improvements with threat hunting teams and external providers.

You will act as incident commander, apply NIST SP 800-61 and MITRE ATT&CK, and present risk findings and metrics to technical and executive audiences, ensuring resilience of a large federal IT environment.

Qualifications

  • U.S. Citizenship required.
  • 8+ years IT experience with 4+ years in incident response/SOC.
  • Remote but near the NCR.
  • Active Public Trust 6c clearance or ability to obtain one.
  • At least one of GCIH, GCFA, GREM, or equivalent.
  • Hands-on with SIEM, SOAR, EDR, CDM and malware analysis tools.
  • Strong OS and networking fundamentals; log/traffic analysis, endpoint forensics.
  • Experience with AWS native services in federal/enterprise cloud.
  • Experience managing a SOC for large federal/enterprise IT systems.
  • Knowledge of NIST SP 800-61, SANS PICERL, MITRE ATT&CK.
  • Malware analysis basics: static analysis, sandboxing, IoC extraction.
  • Experience automating with SOAR to improve analyst efficiency.
  • Ability to translate technical findings for technical and executive audiences.
  • Strong written/verbal skills with federal security documentation.

Responsibilities

  • Manage SOC daily activities and ensure SOPs, Playbooks, and CONOPS are current.
  • Direct Tier I–III incident response across the federal enterprise.
  • Coordinate containment, eradication, and recovery during incidents as incident commander.
  • Lead post-incident reviews and root cause analysis for continuous improvement.
  • Ensure compliance with NIST SP 800-61 and federal IR procedures.
  • Manage SIEM event notables dashboards and triage security alerts.
  • Maintain 24x7x365 SOC coverage and call trees with partner CSPs.
  • Apply MITRE ATT&CK to map attacker TTPs during investigations.
  • Collaborate with threat hunting, CTI, engineering, and architecture teams.
  • Present incident findings and risk recommendations to technical and government leadership.

Skills

U.S. Citizenship
8+ years IT experience
Incident response
SOC operations
Public Trust 6c clearance
GCIH / GCFA / GREM
SIEM
SOAR
EDR
CDM
Malware analysis
Networking basics
AWS GovCloud / AWS
MITRE ATT&CK
NIST SP 800-61

Education

Bachelor's degree in Cybersecurity / IT / CS

Tools

SIEM
SOAR
EDR
CDM
Malware analysis tools

Job description

Everforth ECS seeks an Incident Detection/Response Manager to lead a 24/7 SOC supporting a major federal civilian agency, focusing on rapid detection, containment, and recovery. You will direct Tier I–III incident response and drive improvements with threat hunting teams and external providers.

You will act as incident commander, apply NIST SP 800-61 and MITRE ATT&CK, and present risk findings and metrics to technical and executive audiences, ensuring resilience of a large federal IT environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

24x7 Cybersecurity Incident Response Specialist
24x7 Cybersecurity Incident Response Specialist

(EDO) Entertainment Data Oracle, Inc. • St. Louis (MO)

On-site
USD 110,000 - 150,000
Flexible work environment
401(k) matching
Paid training and tuition
SOC Lead: Incident Command, Threat Detection & Automation
SOC Lead: Incident Command, Threat Detection & Automation

Qnity • Chestnut (AL)

On-site
USD 120,000 - 170,000
Senior Incident Response Lead - Remote
Senior Incident Response Lead - Remote

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior Cyber Defense Incident Responder - 24/7 SOC Lead
Senior Cyber Defense Incident Responder - 24/7 SOC Lead

Peraton • Fort Bragg (NC)

On-site
USD 80,000 - 128,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior Incident Response Lead — TS/SCI | 24x7 SOC
Senior Incident Response Lead — TS/SCI | 24x7 SOC

Leidos Inc • Ashburn (VA)

On-site
USD 108,000 - 195,000
Lead Incident Responder – 24/7 Security Operations
Lead Incident Responder – 24/7 Security Operations

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 158,000
SECOPS Program Manager — SOC & Incident Response
SECOPS Program Manager — SOC & Incident Response

Talanto • Northern (KY)

Hybrid
USD 1,116,000 - 2,192,000
Health benefits
401K retirement plan
Paid time off
+1
Senior SOC Manager – 24/7 Threat Detection & Response
Senior SOC Manager – 24/7 Threat Detection & Response

01400 Rocky Mountain Support Services • Jacksonville (FL)

On-site
USD 120,000 - 160,000
Medical/dental/vision/life/disability
401(k) matching
Employee stock purchase plan