1

Cyber Security Incident Responder Jobs (NOW HIRING)

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident ... You will respond to and investigate cybersecurity incidents, contain affected systems, limit ...

Incident Responder

Suitland, MD · On-site

$107K - $195K/yr

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident ... You will respond to and investigate cybersecurity incidents, contain affected systems, limit ...

$110 - $146/hr

The Lead Incident Responder of Cybersecurity Operations is responsible for investigating, containing, eradicating, and recovering from cybersecurity incidents across the Frontier enterprise ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

TCS035, T5, Band 8 Job-Specific Essential Duties and Responsibilities: - Respond to and investigate cybersecurity incidents. - Conduct incident response and evidence collection. - Contain, eradicate ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

TCS035, T5, Band 8 Job-Specific Essential Duties and Responsibilities: - Respond to and investigate cybersecurity incidents. - Conduct incident response and evidence collection. - Contain, eradicate ...

next page

Showing results 1-20

Cyber Security Incident Responder information

See salary details

$57K

$133K

$186K

How much do cyber security incident responder jobs pay per year?

As of Sep 6, 2026, the average yearly pay for cyber security incident responder in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What does a cyber security incident responder do?

A Cyber Security Incident Responder is responsible for identifying, analyzing, and responding to cyber security incidents within an organization. Their duties include investigating security breaches, containing threats, mitigating damage, and developing strategies to prevent future incidents. They work closely with IT teams and management to ensure that security protocols are followed and help restore normal operations after a cyber attack. Incident responders also document incidents and may contribute to training staff on security awareness.

What are the key skills and qualifications needed to thrive as a cyber security incident responder, and why are they important?

To thrive as a Cyber Security Incident Responder, you need expertise in network security, threat detection, forensic analysis, and incident handling, often supported by a degree in computer science or cybersecurity and relevant certifications such as CEH, CISSP, or GCIA. Familiarity with SIEM tools, intrusion detection/prevention systems, malware analysis platforms, and scripting languages is commonly required. Strong analytical thinking, effective communication, and the ability to remain calm under pressure are crucial soft skills in this role. These skills ensure rapid, accurate responses to cyber threats, minimizing damage and maintaining organizational security.

What are some common challenges cyber security incident responders face during an active incident, and how are they typically addressed?

Cyber Security Incident Responders often face the challenge of working under intense pressure to contain and investigate threats quickly, while ensuring minimal disruption to business operations. They must rapidly analyze incomplete or ambiguous data and coordinate with various teams, such as IT, legal, and management, to implement effective response measures. Communication and prioritization are key—successful responders routinely rely on established playbooks, clear escalation protocols, and ongoing training to stay prepared for evolving threats. Collaboration and adaptability are essential skills in this dynamic environment.

What is the difference between Cyber Security Incident Responder vs Cyber Security Analyst?

AspectCyber Security Incident ResponderCyber Security Analyst
CertificationsCompTIA Security+, GIAC GCIH, CISSP (preferred)CompTIA Security+, CISSP, CEH (preferred)
Work EnvironmentResponds to security incidents, often in real-time, during crisesMonitors security systems, analyzes threats, and implements security measures
Primary FocusHandling and mitigating security incidents and breachesAnalyzing security data, identifying vulnerabilities, and improving security posture
Employer & Industry UsageUsed in cybersecurity teams across various industries, especially in incident response teamsCommon in security operations centers (SOCs) and cybersecurity departments

While both roles require cybersecurity knowledge and certifications, the Cyber Security Incident Responder focuses on reacting to and managing security incidents in real-time, whereas the Cyber Security Analyst emphasizes monitoring, analyzing, and preventing threats proactively.

How much do cybersecurity incident responders make?

Cybersecurity incident responders typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, certifications, and location. Entry-level positions may start around $50,000, while experienced professionals with specialized skills can earn over $130,000 annually.
More about Cyber Security Incident Responder jobs

What states have the most Cyber Security Incident Responder jobs?

States with the most job openings for Cyber Security Incident Responder jobs include:

What job categories do people searching Cyber Security Incident Responder jobs look for?

The top searched job categories for Cyber Security Incident Responder jobs are:

Infographic showing various Cyber Security Incident Responder job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Cybersecurity Analyst, Incident Responder

Digital-Global-Connectors

Mclean, VA • On-site

$110 - $150/hr

Other

Posted 4 days ago


Job description

Cybersecurity Analyst, Incident Responder

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking an experienced Cybersecurity Analyst – Tier 2 (Incident Responder) to support a Federal information security program. The Tier 2 Incident Responder is responsible for investigating, containing, eradicating, and recovering from cybersecurity incidents affecting enterprise information systems, networks, cloud environments, and critical business operations.

This position performs advanced analysis of cybersecurity events, coordinates incident response activities, conducts forensic triage, analyzes malware and attacker tactics, and collaborates with Security Operations Center (SOC) personnel, Security Engineers, Threat Hunters, ISSOs, and System Owners to minimize operational impact and strengthen the organization's cybersecurity posture.

The successful candidate will possess strong technical investigative skills, experience responding to sophisticated cyber threats, and the ability to perform effective incident analysis within complex enterprise environments.

Essential Duties and ResponsibilitiesIncident Response
  • Investigate cybersecurity incidents affecting enterprise information systems, applications, cloud services, and networks.
  • Perform incident triage to determine scope, severity, and operational impact.
  • Execute containment, eradication, and recovery procedures in accordance with established incident response plans.
  • Coordinate response activities with technical teams and program leadership.
  • Validate successful remediation before incident closure.
  • Maintain incident timelines and documentation throughout the response lifecycle.
Security Investigation
  • Analyze suspicious network traffic, endpoint activity, authentication events, and system logs.
  • Identify indicators of compromise (IOCs), indicators of attack (IOAs), and attacker behaviors.
  • Determine root cause and attack vectors.
  • Assess the extent of compromise across affected systems.
  • Identify persistence mechanisms and unauthorized access.
  • Recommend remediation and long-term defensive improvements.
Digital Forensic Triage
  • Collect and preserve digital evidence in accordance with forensic best practices.
  • Perform preliminary forensic analysis of endpoints, servers, and cloud resources.
  • Review memory captures, event logs, registry artifacts, file systems, browser artifacts, and authentication records.
  • Support chain-of-custody documentation.
  • Coordinate with Digital Forensics Analysts for advanced forensic examinations when required.
Malware Analysis Support
  • Analyze suspicious files and malicious code using approved analysis tools.
  • Identify malware behavior and associated indicators.
  • Review sandbox analysis results.
  • Document malware characteristics and recommended detection signatures.
  • Coordinate with Threat Intelligence and Threat Hunting personnel regarding emerging threats.
Threat Detection and Analysis
  • Investigate alerts generated by SIEM, EDR, IDS/IPS, and XDR platforms.
  • Correlate data from multiple security tools to identify attack patterns.
  • Evaluate threat intelligence to determine relevance to ongoing investigations.
  • Recommend improvements to detection logic based on investigative findings.
  • Assist in developing new detection use cases.
Security Tool Operations

Utilize technologies including:

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud
  • CrowdStrike Falcon
  • Palo Alto Cortex XDR
  • Trellix
  • Cisco Secure
  • Wireshark
  • Velociraptor
  • Security Information and Event Management (SIEM)
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
Reporting and Documentation

Develop and maintain:

  • Incident Reports
  • After-Action Reports
  • Root Cause Analyses
  • Investigation Summaries
  • Lessons Learned
  • Security Recommendations
  • Executive Briefings
  • Incident Metrics
  • Threat Assessments
  • Standard Operating Procedures

Ensure documentation is complete, technically accurate, and suitable for operational and audit purposes.

Collaboration
  • Coordinate with Tier 1 SOC Analysts, Threat Hunters, Digital Forensics Analysts, Security Engineers, ISSOs, System Owners, and Government stakeholders.
  • Participate in incident response working groups.
  • Provide technical guidance during active cybersecurity incidents.
  • Support enterprise cybersecurity exercises and tabletop events.
  • Share investigative findings with cross-functional cybersecurity teams.
Continuous Improvement
  • Recommend improvements to incident response procedures and playbooks.
  • Participate in lessons-learned reviews following significant incidents.
  • Assist with development of new detection capabilities.
  • Monitor emerging attack techniques and defensive technologies.
  • Maintain technical proficiency through ongoing training and professional certification.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Digital Forensics, or a related discipline.
  • Minimum four (4) years of experience performing cybersecurity incident response or cyber defense operations.
  • Experience investigating enterprise cybersecurity incidents.
  • Experience using SIEM, EDR, XDR, and log analysis platforms.
  • Understanding of networking protocols, operating systems, malware behavior, and common attack techniques.
  • Strong analytical, investigative, documentation, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
  • Experience supporting a Federal civilian agency.
  • Experience performing digital forensic triage or malware analysis.
  • Experience supporting cloud incident response in Microsoft Azure or AWS environments.
  • Experience utilizing MITRE ATT&CK during investigations.
  • GIAC Certified Incident Handler (GCIH)
  • CompTIA CySA+
  • CompTIA Security+
  • GIAC Certified Forensic Analyst (GCFA)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Ethical Hacker (CEH) (preferred)
Knowledge, Skills, and Abilities
  • Incident Response
  • Cyber Defense Operations
  • Digital Forensic Triage
  • Malware Analysis
  • Threat Detection
  • Threat Intelligence
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Security Information and Event Management (SIEM)
  • Wireshark
  • Velociraptor
  • Log Analysis
  • Network Traffic Analysis
  • Windows Security
  • Linux Security
  • Cloud Security
  • MITRE ATT&CK Framework
  • NIST SP 800-61 Incident Response
  • NIST Cybersecurity Framework
  • Technical Documentation
  • Root Cause Analysis
  • Microsoft Office Suite
  • ServiceNow
  • Jira
Security Requirements
  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support incident response activities, emergency cybersecurity operations, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
  • Must maintain strict confidentiality while handling sensitive incident data, forensic evidence, investigative records, and Federal information systems.
  • Ability to respond effectively to cybersecurity incidents in a fast-paced operational environment while coordinating with Government stakeholders, technical teams, and program leadership to minimize risk and restore secure operations.
#J-18808-Ljbffr