1

Incident Commander Jobs in Virginia (NOW HIRING)

... Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense ... CSIH, GCIH, or GCFA preferred for incident handling. * Willingness and availability to work the day ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

Security Operations • Serve as incident commander or alternate incident commander during security incidents. • Direct threat intelligence efforts, monitoring emerging threats, vulnerabilities ...

Senior IT Security Engineer

Chesapeake, VA

$92K - $126K/yr

Security Operations • Serve as incident commander or alternate incident commander during security incidents. • Direct threat intelligence efforts, monitoring emerging threats, vulnerabilities ...

Drive containment, eradication, and recovery with affected entities and the command center. Build and maintain evidencebased incident timelines. Determine and document root cause when evidence ...

... and Incident Commander (IC) for hostage recovery, detainee affairs, and other portfolios, as neededThe candidate should identify mission-critical information sharing and information access ...

The candidate should support development and implementation of the policies, processes, and platforms enhancing effective information sharing and information access across Incident Command and ...

Showing results 21-40

Incident Commander information

See Virginia salary details

$30.7K

$53K

$60.5K

How much do incident commander jobs pay per year?

As of Sep 6, 2026, the average yearly pay for incident commander in Virginia is $52,997.00, according to ZipRecruiter salary data. Most workers in this role earn between $58,500.00 and $59,000.00 per year, depending on experience, location, and employer.

What does an incident commander do?

Incident commander (IC) jobs are positions of responsibility and authority to carry out emergency response plans. Incident commanders play a vital role in emergency response for natural disasters, acts of violence, and other emergencies, such as fires and bomb threats. More recently, the information technology (IT) sector adopted the IC role to manage disaster recovery and business continuity in the event of a computer systems failure or data breach. Whether in IT or other emergency response situations, as IC your duties include allocating resources, minimizing fallout, and supervising operations.

What are the key skills and qualifications needed to thrive as an incident commander, and why are they important?

An Incident Commander is the individual responsible for managing and directing response efforts during an emergency or critical incident, such as a natural disaster, cybersecurity breach, or other crisis. They oversee the incident response team, make key decisions, and coordinate communications between agencies or departments to ensure a swift and effective resolution. The Incident Commander is typically designated at the start of an incident and remains in charge until the situation is resolved or command is transferred. Their leadership is crucial for maintaining order, safety, and clear lines of authority during high-stress situations.

How does an incident commander typically interact with other teams during a major incident?

During a major incident, the Incident Commander serves as the central point of communication, coordinating efforts between technical teams, management, and stakeholders. They facilitate regular updates, assign clear responsibilities, and ensure that everyone is aligned on priorities and next steps. This role often requires quick decision-making, clear documentation, and the ability to manage high-pressure situations while fostering collaboration across departments to resolve issues efficiently.

What is the difference between Incident Commander vs Emergency Response Coordinator?

AspectIncident CommanderEmergency Response Coordinator
CertificationsICS certifications, First Aid/CPREmergency management certifications, First Aid/CPR
Work EnvironmentEmergency scenes, incident sitesEmergency planning offices, coordination centers
Employer & IndustryPublic safety, fire departments, disaster responseGovernment agencies, NGOs, corporate safety teams
Primary RoleLead incident response, make tactical decisionsCoordinate response efforts, plan emergency procedures

While both roles focus on emergency situations, the Incident Commander is responsible for leading on-site incident response and making tactical decisions. The Emergency Response Coordinator typically oversees planning and coordination efforts, ensuring effective response strategies are in place. Both roles require similar certifications and are vital in emergency management, but their day-to-day responsibilities and work environments differ.

What are popular job titles related to Incident Commander jobs in Virginia?

For Incident Commander jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Incident Commander jobs in Virginia look for?

The top searched job categories for Incident Commander jobs in Virginia are:

What are popular job titles related to Incident Commander jobs in VA?

For Incident Commander jobs in VA, the most frequently searched job titles are:

Infographic showing various Incident Commander job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $52,997 per year, or $25.5 per hour.

Cyber Incident Responder (24x7 Days)

asrcfh

Quantico, VA

Full-time

Re-posted 3 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

243rd of 453 rated engineering


Job description

ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the day shift (0600 – 1600), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA — no telework is available for this role.

The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.

Position Description:

The Cyber Incident Responder is a vital role responsible for executing the full incident response lifecycle during day shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).

The Incident Responder will collaborate with cross-functional IT and security teams to:

  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours

Minimum Requirements: 

  • At least Five (5) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire — IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.
  • Willingness and availability to work the day shift (0600 – 1600), including weekend and holiday rotations, fully on-site at Quantico, VA.

Required Skills:

  • Knowledge of computer network defense concepts, DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cybersecurity and Computer Network Defense Policies Cybersecurity and Computer Network Defense policies
  • Develop, maintain, and provide a weekly brief that captures all the cyber events including metrics and trends.
  • Ability to provide continuous monitoring, data to include but not limited to network and host vulnerability scanning IDS, firewall, network sensor tuning, net flow/packet capture (PCAP). Collect and keep audit data in order to conduct a technical analysis relating to misuse, penetration, or other incidents.
  • Document incidents, response actions, and remediation recommendations in accordance with government reporting requirements. 
  • Monitor multiple environments for malicious or anomalous activity using SIEM, SOAR, and on-prem security tooling. 
  • Analyze logs, telemetry, alerts, and audit data to identify indicators of compromise (IOCs) and attack patterns. 

Work Environment and Physical Demands: 

  • This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.
  • Must work the assigned day shift (0600 – 1600) and support weekend and holiday coverage as scheduled.
  • Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom