Cyber Incident Response Lead - TS Cleared

Reposted 12 Days Ago
Be an Early Applicant
Arlington, VA
In-Office
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The Cyber Incident Response Lead analyzes active incidents, provides strategic guidance for mitigation, and collaborates with various stakeholders to enhance cyber defense capabilities.
Summary Generated by Built In
Job Summary & Responsibilities

ECS is seeking a Cyber Incident Response Lead to work in a HYBRID setting out of our Arlington, VA office.  

 

ECS is seeking talented professionals to join our growing team in supporting the Joint Cyber Defense Collaborative (JCDC), CISA’s premier initiative for whole-of-nation cyber defense. JCDC brings together federal agencies, private sector leaders, and international partners to analyze emerging threats, share actionable intelligence, and coordinate strategic responses to protect critical infrastructure. 

Our team plays a vital role in enabling real-time collaboration, threat detection, and mitigation across sectors. We help shape the strategies and workflows that turn raw intelligence into decisive action—whether responding to active campaigns, developing joint defense plans, or strengthening national cyber resilience. We’re looking for driven professionals who thrive in a fast-paced, mission-focused environment where critical thinking, cyber expertise, and collaborative instincts are essential. A passion for cybersecurity, continuous learning, and public service is vital. 

We are looking for a Lead Cyber Incident Analyst for a team that provides deep technical analysis during active cyber incidents, including insights into vulnerabilities, adversarial tactics, and mitigation strategies across diverse environments like IT, OT/ICS, cloud, and AI systems.  This position will interface extensively with multiple organizations within CISA including Vulnerability Management (VM) and Threat Hunt (TH) to provide guidance and analysis on active cyber threats for JCDC partners. This position will define critical data sources for collection, inform processes, write detection rules, and analyze active and emerging cyber threats and incidents from across Federal Civilian Executive Branch (FCEB), Critical Infrastructure (CI) and State, Local, Tribal and Territorial (SLTT). 

The Lead Cyber Incident Analyst works closely with many stakeholders, including DHS CISA TH and VM, Agency security analysts / user groups, and the ECS team to ensure alignment between solution development and needs of stakeholders. The Analyst will perform research and provide solutions for specific IOCs and IOAs. The Analyst will aid in defining tools, processes, and procedures for advancing Threat Hunting and Incident Response capabilities within CISA, FCEB, CI and SLTT. The Lead Cyber Incident Analyst is required to present solutions to a variety of audiences from users to senior government leaders. The ideal candidate works effectively both independently, and as a member of one or more Agile teams to determine how to optimally satisfy customer requirements. 

 

Responsibilities: 

  • Create and guide the strategic direction for the team's work, ensuring all activities directly support the client’s mission and are aligned with broader goals 
  • Perform analysis on active cyber incidents, events and vulnerabilities to provide guidance and targeted recommendations for mitigation 
  • Create written guidance and recommendations to assist JCDC partners with solutions for active and ongoing cyber vulnerabilities 
  • Through hands-on analysis provide insights into vulnerabilities, adversarial tactics, and mitigation strategies across diverse environments like IT, OT/ICS, cloud, and AI systems 
  • Act as the Lead for the ECS Cyber Threat and Incident Response team in collaboration with Cyber Product Owner, Cyber Engagement Coordinator, and a Performance Monitoring team to meet JCDC requirements 
  • Oversee the translation of strategic products into clear, practical formats that are tailored to the specific needs and operational constraints of different stakeholder groups, including large and small jurisdictions and critical infrastructure (CI) partners 
  • Provide tailored vulnerability mitigation recommendations and contextualized examples to stakeholders to address implementation challenges and encourage rapid adoption 
Preferred Qualifications
  • Possess a TS security clearance and be SCI eligible at time of proposal submission 
  • Proven experience in a leadership role, managing technical or strategic teams  
  • 10+ Years of previous experience in a threat intelligence, cyber security, incident response, or similar role 
  • Proven understanding of computer and network fundamentals. 
  • Strong understanding of computer architecture, operating systems, vulnerabilities, encryption, or other areas of expertise. 
  • Proven experience defining data sources and writing detection rules for discovering malicious behavior 
  • Ability to perform in-depth research tasks and produce written summaries to include insights and predictions based on an analytical process. 
  • Excellent written and oral communication skills 
  • Understand current cyber threats/exploits, attack methodology, and detection techniques using a wide variety of security products including COTS and open source 
  • Familiarity with MITRE ATT&CK and/or similar frameworks 
  • Familiarity with AI/ML concepts and applications 

Top Skills

Ai Systems
Cloud
Cybersecurity
It
Ot/Ics
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries.

ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies.

Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Boeing Logo Boeing

Software Engineer

Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
In-Office
2 Locations
141000 Employees
128K-173K Annually

Cox Enterprises Logo Cox Enterprises

Technical Support

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Chesapeake, VA, USA
50000 Employees
16-24 Hourly

STR Logo STR

Associate Researcher

Machine Learning • Security • Software • Analytics • Defense
Easy Apply
In-Office
Arlington, VA, USA
800 Employees
91K-125K Annually

Anduril Logo Anduril

Senior Software Engineer

Aerospace • Artificial Intelligence • Hardware • Robotics • Security • Software • Defense
In-Office
Reston, VA, USA
6000 Employees
166K-220K Annually

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Idler Thumbnail
Artificial Intelligence
San Francisco, California
6 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account