1

Cyber Security Incident Response Jobs (NOW HIRING)

MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most ...

next page

Showing results 1-20

Cyber Security Incident Response information

See salary details

$57K

$133K

$186K

How much do cyber security incident response jobs pay per year?

As of Aug 23, 2026, the average yearly pay for cyber security incident response in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is cyber security incident response?

Cyber security incident response refers to the process and procedures organizations use to detect, investigate, and respond to security incidents such as data breaches, malware attacks, or unauthorized access. The goal is to minimize damage, recover affected systems, and prevent future incidents by analyzing what happened and implementing corrective actions. Incident response teams follow structured plans that typically include preparation, identification, containment, eradication, recovery, and lessons learned. Effective incident response helps organizations protect sensitive information, maintain business continuity, and comply with legal or regulatory requirements.

What are the key skills and qualifications needed to thrive as a cyber security incident response specialist?

To thrive as a Cyber Security Incident Response specialist, you need expertise in network security, threat analysis, digital forensics, and a relevant degree or certifications such as CISSP, CEH, or GIAC. Familiarity with SIEM tools, intrusion detection systems, and forensic analysis software is essential for investigating and mitigating cyber threats. Strong problem-solving skills, attention to detail, and the ability to communicate complex issues clearly are standout soft skills in this role. These abilities are crucial for quickly detecting, analyzing, and responding to security incidents to protect organizational assets and minimize risk.

What are some common challenges faced by professionals in cyber security incident response roles?

Professionals in Cyber Security Incident Response often face challenges such as rapidly evolving threat landscapes, high-pressure situations requiring quick decision-making, and the need to coordinate across multiple departments during incidents. Handling large volumes of alerts and distinguishing between real threats and false positives can also be demanding. Additionally, staying up to date with the latest tools, techniques, and compliance requirements is essential for success and can require ongoing learning and adaptation.

What is the difference between Cyber Security Incident Response vs Cyber Security Analyst?

AspectCyber Security Incident ResponseCyber Security Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+, CEH
Work EnvironmentResponds to security incidents, investigates breachesMonitors networks, analyzes security data
Employer & Industry UsageIncident response teams in various sectorsSecurity teams across industries

Cyber Security Incident Responders focus on managing and mitigating security incidents, while Cyber Security Analysts monitor systems and analyze threats. Both roles require similar certifications and often work within the same security teams, but their core responsibilities differ: incident responders act during and after breaches, whereas analysts proactively identify vulnerabilities.

How much does a cyber security incident response make?

Cyber security incident response professionals typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Entry-level roles may start lower, while experienced analysts with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand areas.

How to become a cyber security incident response specialist?

To become a cyber security incident response specialist, individuals typically need a bachelor's degree in cybersecurity, computer science, or a related field, along with experience in network security and threat analysis. Certifications such as GIAC Certified Incident Handler (GCIH) or Certified Computer Security Incident Handler (CSIH) can enhance job prospects. Developing skills in intrusion detection, malware analysis, and familiarity with security tools like SIEM systems are also important for this role.

What does a cyber security incident response do?

A cyber security incident response professional is responsible for identifying, managing, and mitigating cybersecurity incidents such as data breaches, malware infections, or system intrusions. They analyze security alerts, coordinate response efforts, and implement measures to prevent future attacks, often using tools like intrusion detection systems and forensic analysis. This role requires strong problem-solving skills and knowledge of security frameworks and protocols.
More about Cyber Security Incident Response jobs

What cities are hiring for Cyber Security Incident Response jobs?

Cities with the most Cyber Security Incident Response job openings:

What states have the most Cyber Security Incident Response jobs?

States with the most job openings for Cyber Security Incident Response jobs include:

Infographic showing various Cyber Security Incident Response job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Cybersecurity Incident Response Lead

Eliassen Group

Alexandria, VA โ€ข On-site

$75 - $80/hr

Other

Medical, Dental, Vision, Life, Retirement

Posted 11 days ago


Job description

Description:
Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA
Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.
This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $80.00/hr. w2
Responsibilities:
  • Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
  • Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
  • Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
  • Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
  • Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
  • Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
  • Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
  • Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
  • Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization's security posture.
  • Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
  • Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
  • Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
  • Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
  • Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.

Experience Requirements:
  • ship required.
  • 10+ years in incident response, security operations, or penetration testing.
  • 5+ years managing incident response teams.
  • Strong knowledge of malware analysis, forensics, threat intelligence, and adversary TTPs.
  • Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst.
  • Ability to obtain and maintain a Public Trust clearance.

Education Requirements:
  • Master of Science degree in IT, Information Security, or related field.

Recruitment Transparency Notice

Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (, ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact .
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!

Eliassen Group logo

About Eliassen Group

Sourced by ZipRecruiter

Eliassen Group provides strategic consulting and talent solutions to drive our clients' innovation and business results. Our purpose is to positively impact the lives of our employees, clients, consultants, and the communities in which we operate. Leveraging over 30 years of success, our expertise in talent solutions, life sciences consulting, Agile consulting, cloud services, risk management, business optimization, and managed services enables us to partner with our clients to execute their business strategy and scale effectively. Headquartered in Reading, MA, and with offices from coast to coast, Eliassen Group offers local community presence and deep networks, as well as national reach.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

Reading, MA, US

Year founded

1989