1

Incident Response Lead Jobs (NOW HIRING)

Incident Response Lead

Washington, DC ยท On-site

$140K - $150K/yr

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote . The role is contingent upon additional funding. We are seeking a senior-level Incident Response Lead ...

Incident Response Lead

Boston, MA ยท On-site

$130K - $170K/yr

We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for ...

Lead Cybersecurity Incident Response * Act as incident lead for major cybersecurity incidents, establishing severity, objectives, workstreams, decision rights, communication cadence, and escalation ...

Lead Cybersecurity Incident Response * Act as incident lead for major cybersecurity incidents, establishing severity, objectives, workstreams, decision rights, communication cadence, and escalation ...

next page

Showing results 1-20

Incident Response Lead information

See salary details

$17

$41

$66

How much do incident response lead jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for incident response lead in the United States is $41.73, according to ZipRecruiter salary data. Most workers in this role earn between $29.33 and $47.60 per hour, depending on experience, location, and employer.

What are the primary challenges an Incident Response Lead faces during a major security incident?

An Incident Response Lead often encounters the challenge of quickly coordinating cross-functional teams under pressure while maintaining clear communication with stakeholders. They must rapidly analyze incomplete or evolving information to make critical decisions, all while ensuring containment and minimizing business impact. Balancing technical remediation with regulatory and reporting requirements can also be demanding. Adaptability and the ability to remain calm and organized are key to effectively managing these high-stress situations.

What does an Incident Response Lead do?

An Incident Response Lead is responsible for managing and coordinating an organization's response to cybersecurity incidents. They lead a team of specialists to detect, analyze, and mitigate threats, ensuring that security breaches are contained and investigated thoroughly. The Incident Response Lead also develops response plans, conducts training, and communicates with stakeholders to minimize the impact of incidents. Their role is critical in protecting sensitive data and maintaining business continuity.

What are the key skills and qualifications needed to thrive as an Incident Response Lead?

To thrive as an Incident Response Lead, you need a strong background in cybersecurity, experience in threat analysis, and often a degree in computer science or a related field. Expertise with security information and event management (SIEM) tools, forensic analysis software, and relevant certifications like CISSP, CISM, or GIAC are typically required. Exceptional problem-solving abilities, leadership, and clear communication are vital soft skills for coordinating teams and managing high-pressure situations. These skills ensure rapid, effective responses to security threats, minimizing business impact and maintaining organizational resilience.

What is the difference between Incident Response Lead vs Security Analyst?

AspectIncident Response LeadSecurity Analyst
CertificationsGCIH, CISSP, CISACISSP, Security+
Work EnvironmentLeads incident response teams, manages response strategiesMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommon in security operations centers (SOCs)

The Incident Response Lead focuses on managing and leading incident response efforts, coordinating teams during security breaches. In contrast, a Security Analyst primarily monitors systems, detects threats, and analyzes security data. While both roles require cybersecurity certifications and work within similar environments, the Lead has a leadership and strategic focus, whereas the Analyst is more operational and technical.

More about Incident Response Lead jobs
What cities are hiring for Incident Response Lead jobs? Cities with the most Incident Response Lead job openings:
Who are the top companies hiring for Incident Response Lead jobs? The top employers for Incident Response Lead jobs are:
What states have the most Incident Response Lead jobs? States with the most job openings for Incident Response Lead jobs include:
What are popular job titles related to Incident Response Lead jobs? For Incident Response Lead jobs, the most frequently searched job titles are:
Infographic showing various Incident Response Lead job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 10% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $86,808 per year, or $41.7 per hour.

Incident Response Lead

ECS

Washington, DC โ€ข On-site

$140K - $150K/yr

Full-time

Posted 8 days ago


Job description

Everforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon additional funding.
We are seeking a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the most complex and high-priority cybersecurity challenges facing the enterprise. This is a Tier 3 position, meaning you are the last line of defense and the highest level of technical escalation within the security operations function.
Day to day, you will operate as a senior security operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the capabilities of the team around you. When an incident strikes, you step forward. You will be called upon to lead incident response efforts end to end: coordinating containment, driving remediation, communicating timelines, and ensuring the organization emerges from each event with stronger defenses than it had before.
Salary Range: $140,000 - $150,000
General Description of Benefits
Incident Response & Threat Operations
  • Proven ability to lead incident response efforts including triage, containment, remediation, and post-incident reporting
  • Deep familiarity with the Cyber Kill Chain, MITRE ATT&CK, Diamond Model of Intrusion Analysis, or equivalent frameworks
  • Experience investigating security incidents, developing timelines, and communicating findings to both technical teams and senior leadership
  • Ability to perform malware triage, network analysis, and live response as part of incident handling
  • Experience developing and documenting incident response playbooks, runbooks, and standard operating procedures

Threat Hunting & Detection Engineering
  • Ability to develop, document, and execute structured hunt plans against enterprise environments
  • Experience creating custom detection mechanisms that correlate across multiple log sources
  • Proficiency in log analysis and security event detection across diverse and complex environments
  • Ability to translate hunt findings into actionable detections and repeatable operational processes

Security Operations
  • Experience with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems, and EDR tools
  • Proficiency working across Windows, Linux, and macOS operating systems from a security operations and response perspective
  • Familiarity with cloud security operations across platforms such as AWS, Azure, or GCP
  • Ability to identify new data sources and analysis techniques to improve detection of security events
  • Experience with automation platforms and scripting to reduce manual, repetitive tasks

Leadership & Collaboration
  • Serves as the senior escalation point and subject matter expert for security operations personnel
  • Ability to work with staff to develop a vision and independently lead the implementation of new capabilities
  • Experience participating in the development of technical security standards, monitoring standards, and incident investigation procedures
  • Comfortable interacting with executive management to communicate risk and support enterprise-level security decisions
  • Able to collaborate across teams including networking, systems administration, and technology support partners

A minimum of 6+ years of progressive experience in security operations and incident response is required, with demonstrated experience operating at a senior or Tier 3 analyst level. Candidates who have previously led or co-led incident response efforts in an enterprise environment will be strongly preferred.