1

Cyber Security Incident Responder Jobs (NOW HIRING)

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident ... You will respond to and investigate cybersecurity incidents, contain affected systems, limit ...

Incident Responder

Suitland, MD · On-site

$107K - $195K/yr

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident ... You will respond to and investigate cybersecurity incidents, contain affected systems, limit ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

TCS035, T5, Band 8 Job-Specific Essential Duties and Responsibilities: - Respond to and investigate cybersecurity incidents. - Conduct incident response and evidence collection. - Contain, eradicate ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

The Lead Incident Responder will maintain compliance with federal cybersecurity frameworks (NIST 800-series, RMF, TIC 3.0), lead investigations into complex threats, and deliver compliance reporting ...

TCS035, T5, Band 8 Job-Specific Essential Duties and Responsibilities: - Respond to and investigate cybersecurity incidents. - Conduct incident response and evidence collection. - Contain, eradicate ...

next page

Showing results 1-20

Cyber Security Incident Responder information

See salary details

$57K

$133K

$186K

How much do cyber security incident responder jobs pay per year?

As of Sep 2, 2026, the average yearly pay for cyber security incident responder in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What does a cyber security incident responder do?

A Cyber Security Incident Responder is responsible for identifying, analyzing, and responding to cyber security incidents within an organization. Their duties include investigating security breaches, containing threats, mitigating damage, and developing strategies to prevent future incidents. They work closely with IT teams and management to ensure that security protocols are followed and help restore normal operations after a cyber attack. Incident responders also document incidents and may contribute to training staff on security awareness.

What are the key skills and qualifications needed to thrive as a cyber security incident responder, and why are they important?

To thrive as a Cyber Security Incident Responder, you need expertise in network security, threat detection, forensic analysis, and incident handling, often supported by a degree in computer science or cybersecurity and relevant certifications such as CEH, CISSP, or GCIA. Familiarity with SIEM tools, intrusion detection/prevention systems, malware analysis platforms, and scripting languages is commonly required. Strong analytical thinking, effective communication, and the ability to remain calm under pressure are crucial soft skills in this role. These skills ensure rapid, accurate responses to cyber threats, minimizing damage and maintaining organizational security.

What are some common challenges cyber security incident responders face during an active incident, and how are they typically addressed?

Cyber Security Incident Responders often face the challenge of working under intense pressure to contain and investigate threats quickly, while ensuring minimal disruption to business operations. They must rapidly analyze incomplete or ambiguous data and coordinate with various teams, such as IT, legal, and management, to implement effective response measures. Communication and prioritization are key—successful responders routinely rely on established playbooks, clear escalation protocols, and ongoing training to stay prepared for evolving threats. Collaboration and adaptability are essential skills in this dynamic environment.

What is the difference between Cyber Security Incident Responder vs Cyber Security Analyst?

AspectCyber Security Incident ResponderCyber Security Analyst
CertificationsCompTIA Security+, GIAC GCIH, CISSP (preferred)CompTIA Security+, CISSP, CEH (preferred)
Work EnvironmentResponds to security incidents, often in real-time, during crisesMonitors security systems, analyzes threats, and implements security measures
Primary FocusHandling and mitigating security incidents and breachesAnalyzing security data, identifying vulnerabilities, and improving security posture
Employer & Industry UsageUsed in cybersecurity teams across various industries, especially in incident response teamsCommon in security operations centers (SOCs) and cybersecurity departments

While both roles require cybersecurity knowledge and certifications, the Cyber Security Incident Responder focuses on reacting to and managing security incidents in real-time, whereas the Cyber Security Analyst emphasizes monitoring, analyzing, and preventing threats proactively.

How much do cybersecurity incident responders make?

Cybersecurity incident responders typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, certifications, and location. Entry-level positions may start around $50,000, while experienced professionals with specialized skills can earn over $130,000 annually.
More about Cyber Security Incident Responder jobs

What states have the most Cyber Security Incident Responder jobs?

States with the most job openings for Cyber Security Incident Responder jobs include:

What job categories do people searching Cyber Security Incident Responder jobs look for?

The top searched job categories for Cyber Security Incident Responder jobs are:

Infographic showing various Cyber Security Incident Responder job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

$107K - $195K/yr

Full-time

Posted 12 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 152 frontline employees who took The Breakroom Quiz

80th of 500 rated business services


Job description

Incident Responder

Location: Suitland, MD
Clearance: Active TS/SCI

Leidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) in Suitland, MD.

In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will respond to and investigate cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities

  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
  • Maintain detailed and accurate incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.

Required Certifications

  • Must possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER).

NITESONI

DABAOPP1

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:August 20, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media