Incident Response Lead

Reposted 20 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
140K-150K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Lead Tier 3 incident response efforts: hunt threats, triage and contain incidents, perform malware triage and network/live response, develop detections and playbooks, coordinate remediation, communicate with leadership, and improve security operations through detection engineering and automation.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote.  The role is contingent upon additional funding.


We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.


Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.


Salary Range: $140,000 - $150,000
General Description of Benefits

Preferred Qualifications

Incident Response & Threat Operations

  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures

Threat Hunting & Detection Engineering

  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes

Security Operations

  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks

Leadership & Collaboration

  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.

Skills Required

  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with Cyber Kill Chain, MITRE ATT&CK, Diamond Model or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures
  • Ability to develop, document, and execute structured threat hunt plans
  • Experience creating custom detection mechanisms correlating across multiple log sources
  • Proficiency in log analysis and security event detection across diverse environments
  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS from a security operations and response perspective
  • Familiarity with cloud security operations (AWS, Azure, or GCP)
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks
  • Serves as senior escalation point and subject matter expert; ability to lead capability implementation and collaborate across teams
  • Minimum of 6+ years progressive experience in security operations and incident response, with Tier 3 or senior-level experience

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elkhorn, NE
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

In-Office or Remote
2 Locations
16053 Employees
96K-181K Annually

Leidos Logo Leidos

Incident Response Lead

Information Technology • Software
In-Office
2 Locations
27104 Employees
108K-195K Annually

Accenture Federal Services Logo Accenture Federal Services

Incident Response and Forensics Lead

Artificial Intelligence • Information Technology • Consulting • Cybersecurity
In-Office
2 Locations
17634 Employees
100K-203K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account