Tier-3 Incident Response Lead – Remote

ECS Corporate Services

Washington (District of Columbia)

Hybrid

USD 140,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. You will join the advanced security operations team as a Tier 3 analyst leading end-to-end incident response and threat hunting initiatives.

The role requires 6+ years in security operations, with strong experience in MITRE ATT&CK, kill chain concepts, and playbook development. Expect collaboration across security, networking, and IT teams to strengthen defenses.

Qualifications

  • 6+ years of progressive security operations and incident response experience at senior or Tier 3 level.
  • Experience leading incident response efforts and communicating findings to leadership.
  • Familiarity with Cyber Kill Chain, MITRE ATT&CK, and Diamond Model frameworks.
  • Ability to perform malware triage, network analysis, and live response during incidents.
  • Experience developing incident response playbooks, runbooks, and SOPs.

Responsibilities

  • Lead incident response end-to-end: containment, remediation, timelines, and post-incident review.
  • Develop and document structured hunt plans and repeatable detections.
  • Create and refine detection mechanisms across multiple log sources.
  • Collaborate with teams across networking, systems, and technology support.
  • Communicate risk and incident status to senior leadership.

Skills

Lead incident response
Triage & containment
Remediation
Post-incident reporting
MITRE ATT&CK
Diamond Model
Malware triage
Network analysis
Playbooks & SOPs
Threat hunting
Log analysis
Automation & scripting
OS security (Windows/Linux/macOS)
Cloud security (AWS/Azure/GCP)

Tools

SIEM
Vulnerability scanners
Malware analyzers
IDS/IPS
EDR

Job description

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. You will join the advanced security operations team as a Tier 3 analyst leading end-to-end incident response and threat hunting initiatives.

The role requires 6+ years in security operations, with strong experience in MITRE ATT&CK, kill chain concepts, and playbook development. Expect collaboration across security, networking, and IT teams to strengthen defenses.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead - Remote
Senior Incident Response Lead - Remote

ECS • Washington

Hybrid
USD 140,000 - 150,000
Incident Response Lead
Incident Response Lead

ECS Corporate Services • Washington

Hybrid
USD 140,000 - 150,000
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Cybersecurity Operations Lead: Endpoint & Threat Intel
Cybersecurity Operations Lead: Endpoint & Threat Intel

ECS Corporate Services • Washington

Hybrid
USD 155,000 - 165,000
Cyber Ops Leader: Endpoint & Threat Intel
Cyber Ops Leader: Endpoint & Threat Intel

ECS • Washington

Hybrid
USD 155,000 - 165,000
Remote Incident Response Leader
Remote Incident Response Leader

TTEC • Austin (TX)

On-site
USD 120,000 - 140,000
Remote SOC Tier 2 Analyst: Threat Hunting & Incident Response
Remote SOC Tier 2 Analyst: Threat Hunting & Incident Response

your Jared • Northern (KY)

Hybrid
USD 90,000 - 120,000
Medical benefits
Paid time off
Paid holidays
+3
Lead Incident Responder – 24/7 Security Operations
Lead Incident Responder – 24/7 Security Operations

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 158,000
Incident Responder Shift Lead - Tier 2
Incident Responder Shift Lead - Tier 2

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 158,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

ECS Corporate Services • Washington

Hybrid
USD 155,000 - 165,000