1

Incident Responder Jobs (NOW HIRING)

Yes Position Summary The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies.

The role sits between frontline incident response and global leadership, providing experienced operational oversight, guidance to junior responders and consistent service delivery across the global ...

Principal Incident Responder

Austin, TX · On-site +1

$275K - $344K/yr

Lead incident response end to end across corporate, cloud, and data center environments, from detection and containment through eradication and post-incident review. * Build the detection logic ...

Showing results 41-60

Incident Responder information

See salary details

$41K

$127.2K

$199.5K

How much do incident responder jobs pay per year?

As of Sep 8, 2026, the average yearly pay for incident responder in the United States is $127,177.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,000.00 and $172,000.00 per year, depending on experience, location, and employer.

What does an incident responder do?

An Incident Responder is a cybersecurity professional responsible for identifying, analyzing, and mitigating security threats and incidents. They monitor networks, investigate breaches, and implement containment and recovery strategies to minimize damage. Incident Responders also document incidents, conduct post-mortem analysis, and refine security protocols to prevent future attacks. Their role is critical in maintaining an organization's cybersecurity posture and ensuring swift responses to potential threats.

What does a typical day look like for an incident responder?

A typical day for an Incident Responder involves monitoring security alerts, investigating potential threats, and collaborating with IT and security teams to contain or remediate incidents. You’ll often analyze logs, conduct digital forensics, and document your findings for reporting and future prevention. Expect to participate in regular training and mock incident exercises to keep skills sharp. The work is fast-paced and can involve on-call responsibilities, but it offers the chance to make a tangible impact on an organization’s overall security posture.

What are the key skills and qualifications needed to thrive as an incident responder?

To thrive as an Incident Responder, you need a solid foundation in cybersecurity principles, threat analysis, and digital forensics, often backed by a degree in computer science or related fields. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and certifications like CompTIA Security+ or GIAC Certified Incident Handler (GCIH) are highly valued. Strong problem-solving skills, attention to detail, and the ability to communicate clearly under pressure set top performers apart. These skills are crucial for identifying, mitigating, and reporting security incidents swiftly and effectively to protect organizational assets.

How much does an incident responder make?

Incident responders typically earn a median annual salary between $70,000 and $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or GIAC can earn higher salaries, especially in high-demand industries or regions with a high cost of living.

How to become an incident responder?

To become an incident responder, individuals typically need a bachelor's degree in cybersecurity, computer science, or a related field, along with experience in network security and threat analysis. Earning certifications such as Certified Incident Handler (GCIH) or Certified Ethical Hacker (CEH) can enhance job prospects, and familiarity with security tools like SIEM systems is often required.
More about Incident Responder jobs

What cities are hiring for Incident Responder jobs?

Cities with the most Incident Responder job openings:

Who are the top companies hiring for Incident Responder jobs?

The top employers for Incident Responder jobs are:

What states have the most Incident Responder jobs?

States with the most job openings for Incident Responder jobs include:

What are popular job titles related to Incident Responder jobs?

For Incident Responder jobs, the most frequently searched job titles are:

Infographic showing various Incident Responder job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $127,177 per year, or $61.1 per hour.

Cyber Incident Responder (24x7 Days)

Quantico, VA • On-site

$125K - $153K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 6 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

244th of 454 rated engineering


Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™
ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the day shift (0600 - 1600), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA - no telework is available for this role.
The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.
Position Description:
The Cyber Incident Responder is a vital role responsible for executing the full incident response lifecycle during day shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Incident Responder will collaborate with cross-functional IT and security teams to:
  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours

Minimum Requirements:
  • At least Five (5) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
  • Bachelor's degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire - IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.
  • Willingness and availability to work the day shift (0600 - 1600), including weekend and holiday rotations, fully on-site at Quantico, VA.

Required Skills:
  • Knowledge of computer network defense concepts, DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cybersecurity and Computer Network Defense Policies Cybersecurity and Computer Network Defense policies
  • Develop, maintain, and provide a weekly brief that captures all the cyber events including metrics and trends.
  • Ability to provide continuous monitoring, data to include but not limited to network and host vulnerability scanning IDS, firewall, network sensor tuning, net flow/packet capture (PCAP). Collect and keep audit data in order to conduct a technical analysis relating to misuse, penetration, or other incidents.
  • Document incidents, response actions, and remediation recommendations in accordance with government reporting requirements.
  • Monitor multiple environments for malicious or anomalous activity using SIEM, SOAR, and on-prem security tooling.
  • Analyze logs, telemetry, alerts, and audit data to identify indicators of compromise (IOCs) and attack patterns.

Work Environment and Physical Demands:
  • This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.
  • Must work the assigned day shift (0600 - 1600) and support weekend and holiday coverage as scheduled.
  • Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
EEO Statement
ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom