More jobs:
Incident Response Lead
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-07-30
Listing for:
Electronic Consulting Services, Inc (ECS Federal)
Full Time
position Listed on 2026-07-30
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations
Job Description & How to Apply Below
Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote . The role is contingent upon additional funding.
We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.
Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.
Salary Range: $140,000 - $150,000
General Description of Benefits
Required Skills
Incident Response & Threat Operations
- Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
- Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
- Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
- Ability to perform malware triage, network analysis, and live response as part of incident handling
- Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures
- Ability to develop, document, and execute structured hunt plans against enterprise environments
- Experience creating custom detection mechanisms that correlate across multiple log sources
- Proficiency in log analysis and security event detection across diverse and complex environments
- Ability to translate hunt findings into actionable detections and repeatable operational processes
- Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
- Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
- Familiarity with cloud security operations across platforms such as AWS, Azure, or Google Cloud Platform
- Ability to identify new data sources and analysis techniques to improve detection of security events
- Experience with automation platforms and scripting to reduce manual, repetitive tasks
- Serves as the senior escalation point and subject matter expert for security operations personnel
- Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
- Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
- Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
- Able to collaborate across teams including networking, systems administration, and technology support partners
Desired Skills
- Experience with behavior-based analytics and anomaly detection techniques
- Cloud forensics and incident response experience in SaaS or multi-tenant environments
- Familiarity with threat modeling and development of countermeasures
- Scripting and automation experience in Python, Power Shell, Bash, or Perl
- Experience developing or refining detection logic, exclusions, and tuning within enterprise security tooling
- Quality assurance and continuous improvement experience within a security operations context
- Bachelor's degree in Computer Science, Cybersecurity, Information…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×