1

Incident Responder Jobs (NOW HIRING)

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence ...

Incident Responder

Suitland, MD · On-site

$107K - $195K/yr

Incident Responder Location: Suitland, MD Clearance: Active TS/SCI Leidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence ...

TCS035, T5, Band 8 Job-Specific Essential Duties and Responsibilities: - Respond to and investigate cybersecurity incidents. - Conduct incident response and evidence collection. - Contain, eradicate ...

General information Job Posting Title Incident Responder Date Wednesday, July 15, 2026 City San Antonio State TX Country United States Working time Full-time Description & Requirements Maximus ...

The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure environments. This role ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure environments. This role ...

Lead Incident Responder

Washington, DC · On-site

$160K - $185K/yr

The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure environments. This role ...

The Lead Incident Responder serves as the central point of accountability for day-to-day incident response operations, providing leadership and direction in high-pressure environments. This role ...

Job Summary As a Security Incident Responder, you will be at the forefront of our organization's cyber defense efforts, responsible for monitoring, detecting, and responding to security incidents in ...

Job Summary As a Security Incident Responder, you will be at the forefront of our organization's cyber defense efforts, responsible for monitoring, detecting, and responding to security incidents in ...

$125 - $150/hr

The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments.

BlackCloak is seeking a seasoned and highly skilled Senior Incident Responder to join our Technical Success Team. This is a senior, client-facing individual contributor role for someone who has spent ...

Cyber Incident Responder

Chicago, IL · Hybrid

$95K - $115K/yr

The role sits between frontline incident response and global leadership, providing experienced operational oversight, guidance to junior responders and consistent service delivery across the global ...

WI · On-site

$125 - $150/hr

The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments.

next page

Showing results 1-20

Incident Responder information

See salary details

$41K

$127.2K

$199.5K

How much do incident responder jobs pay per year?

As of Sep 8, 2026, the average yearly pay for incident responder in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What does an incident responder do?

An Incident Responder is a cybersecurity professional responsible for identifying, analyzing, and mitigating security threats and incidents. They monitor networks, investigate breaches, and implement containment and recovery strategies to minimize damage. Incident Responders also document incidents, conduct post-mortem analysis, and refine security protocols to prevent future attacks. Their role is critical in maintaining an organization's cybersecurity posture and ensuring swift responses to potential threats.

What does a typical day look like for an incident responder?

A typical day for an Incident Responder involves monitoring security alerts, investigating potential threats, and collaborating with IT and security teams to contain or remediate incidents. You’ll often analyze logs, conduct digital forensics, and document your findings for reporting and future prevention. Expect to participate in regular training and mock incident exercises to keep skills sharp. The work is fast-paced and can involve on-call responsibilities, but it offers the chance to make a tangible impact on an organization’s overall security posture.

What are the key skills and qualifications needed to thrive as an incident responder?

To thrive as an Incident Responder, you need a solid foundation in cybersecurity principles, threat analysis, and digital forensics, often backed by a degree in computer science or related fields. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and certifications like CompTIA Security+ or GIAC Certified Incident Handler (GCIH) are highly valued. Strong problem-solving skills, attention to detail, and the ability to communicate clearly under pressure set top performers apart. These skills are crucial for identifying, mitigating, and reporting security incidents swiftly and effectively to protect organizational assets.

How much does an incident responder make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries or regions with a high cost of living.

How to become an incident responder?

To become an incident responder, individuals typically need a bachelor's degree in cybersecurity, computer science, or a related field, along with experience in network security and threat analysis. Earning certifications such as Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH) can enhance job prospects, and familiarity with security tools like SIEM systems is often required.
More about Incident Responder jobs

What cities are hiring for Incident Responder jobs?

Cities with the most Incident Responder job openings:

Who are the top companies hiring for Incident Responder jobs?

The top employers for Incident Responder jobs are:

What states have the most Incident Responder jobs?

States with the most job openings for Incident Responder jobs include:

What are popular job titles related to Incident Responder jobs?

For Incident Responder jobs, the most frequently searched job titles are:

Infographic showing various Incident Responder job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Incident Responder

Suitland, MD

Leidos
IT Services • 10K+ employees

$107K - $195K/yr

Full-time

Posted 19 days ago


Key responsibilities

  • Respond to and investigate cybersecurity incidents, including detection, analysis, containment, eradication, and recovery.

  • Coordinate and communicate with internal and external stakeholders regarding incident response activities.

  • Maintain detailed incident documentation and participate in incident response meetings and security exercises.


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 153 frontline employees who took The Breakroom Quiz

81st of 500 rated business services


Job description

Incident Responder

Location: Suitland, MD
Clearance: Active TS/SCI

Leidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) in Suitland, MD.

In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will respond to and investigate cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities

  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
  • Maintain detailed and accurate incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.

Required Certifications

  • Must possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER).

NITESONI

DABAOPP1

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:August 20, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media