1

Incident Response Manager Jobs in Virginia (NOW HIRING)

Manager, Incident Response

Mclean, VA · On-site +1

$150K - $175K/yr

About the Role As the Manager, Incident Response at Pondurance, you will help manage our Incident Response Consulting Team. You should have a strong desire to mentor our consultants and deliver ...

The Incident Response Technician will operate an emergency response vehicle to perform roadside ... You will be dispatched by the I-66 Traffic Management Center, occasionally assisting maintenance ...

The Incident Response Technician will operate an emergency response vehicle to perform roadside ... You will be dispatched by the I-66 Traffic Management Center, occasionally assisting maintenance ...

Incident Response Analyst

Alexandria, VA · On-site

$87K - $157K/yr

The Incident Response Analyst will investigate and respond to cybersecurity events and incidents ... Analyze security information from Security Information and Event Management (SIEM) platforms ...

The Incident Response Analyst will investigate and respond to cybersecurity events and incidents ... Analyze security information from Security Information and Event Management (SIEM) platforms ...

Incident Response Analyst

Alexandria, VA · On-site

$100 - $125/hr

The Incident Response Analyst will investigate and respond to cybersecurity events and incidents ... Analyze security information from Security Information and Event Management (SIEM) platforms ...

Posted today

The Incident Response Analyst will investigate and respond to cybersecurity events and incidents ... Analyze security information from Security Information and Event Management (SIEM) platforms ...

Incident Response Lead

Ashburn, VA · On-site

$150 - $200/hr

Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise * Significant ...

Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise * Significant ...

next page

Showing results 1-20

Incident Response Manager information

See Virginia salary details

$40.6K

$126.1K

$197.8K

How much do incident response manager jobs pay per year?

As of Sep 7, 2026, the average yearly pay for incident response manager in Virginia is $126,086.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,200.00 and $170,500.00 per year, depending on experience, location, and employer.

What is an incident response manager?

An incident response manager supervises a team of IT professionals who respond to cyber attacks, network intrusions, and computer crimes. Your responsibilities are to direct security personnel as they investigate security breaches and implement counter-measures. Prior to any breach or incident, your duties require you to analyze the activity on your organization’s servers and networks, locating vulnerabilities and implementing safeguards and procedural changes to prevent possible attack.

What does an incident response manager do?

An Incident Response Manager is responsible for leading an organization's efforts to detect, respond to, and recover from cybersecurity incidents such as data breaches, malware infections, or unauthorized access. They coordinate response teams, develop incident response plans, and ensure that incidents are properly documented and analyzed to prevent future occurrences. Their role also involves communicating with stakeholders, providing training, and keeping up to date with the latest cyber threats and best practices.

What are the key skills and qualifications needed to thrive as an incident response manager, and why are they important?

To thrive as an Incident Response Manager, you need expertise in cybersecurity principles, risk assessment, incident handling, and often a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, forensic analysis platforms, and certifications like CISSP, CISM, or GIAC are typically required. Strong leadership, decision-making, and communication skills are crucial for coordinating teams and managing high-pressure situations. These competencies are vital to effectively detect, contain, and mitigate security incidents while minimizing organizational impact.

What are some common challenges faced by incident response managers, and how can they effectively address them?

Incident Response Managers often encounter challenges such as rapidly evolving security threats, coordinating cross-functional teams under pressure, and ensuring clear communication during high-stress incidents. To effectively address these challenges, they focus on regular training and simulations, establish comprehensive incident response plans, and foster strong relationships with IT, legal, and executive teams. Emphasizing documentation and post-incident reviews also helps in continuously improving processes and adapting to new threats.

What is the difference between Incident Response Manager vs Security Analyst?

AspectIncident Response ManagerSecurity Analyst
CertificationsGCIH, CISSP, CISMCISSP, Security+
Work EnvironmentLeads incident response teams, manages response plansMonitors security systems, analyzes threats
Employer & Industry UsageUsed in cybersecurity teams across various industriesCommonly employed in security operations centers (SOCs)

The Incident Response Manager focuses on leading and coordinating incident response efforts, managing teams, and developing response strategies. In contrast, the Security Analyst primarily monitors security alerts, analyzes threats, and supports incident detection. Both roles require cybersecurity certifications and are integral to organizational security, but they differ in scope and responsibilities.

What are the most commonly searched types of Incident Response jobs in Virginia?

The most popular types of Incident Response jobs in Virginia are:

What are popular job titles related to Incident Response Manager jobs in Virginia?

For Incident Response Manager jobs in Virginia, the most frequently searched job titles are:

What cities in Virginia are hiring for Incident Response Manager jobs?

Cities in Virginia with the most Incident Response Manager job openings:

Infographic showing various Incident Response Manager job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 13% Part Time, and 1% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $126,086 per year, or $60.6 per hour.

Incident Detection/Response Manager (SOC Manager) with Security Clearance

ECS

Hampton, VA • On-site

$140K - $160K/yr

Other

Re-posted 26 days ago


Job description

Job Description Everforth ECS is seeking an Incident Detection/Response Manager (SOC Manager) who lives in close proximity to the National Capital Region (NCR) to join a premier, enterprise-scale cybersecurity program supporting a major federal civilian agency. Please Note: This position is contingent upon contract award. Salary Range: $140,000 - $160,000 This flagship initiative unifies 24x7x365 Security Operations (SOC), proactive threat hunting, and advanced Security Engineering and Architecture into a cohesive defensive mission. As a key leader on this program, you will drive the protection of highly sensitive, national-level financial, and personally identifiable information (PII). You will be at the forefront of modernizing the agency's cyber posture, implementing advanced automation, and ensuring continuous operational resilience across a massive, highly complex federal IT enterprise. As the Incident Detection/Response Manager, you will serve as the operational commander of a high-performing, around-the-clock Security Operations Center supporting a major federal civilian agency. You will direct Tier I, II, and III incident response operations, ensuring rapid detection, containment, and recovery across a large-scale federal IT enterprise. Working closely with threat hunting teams, security engineers, agency stakeholders, and external service providers, you will lead the SOC's day-to-day operations while driving continuous improvement in detection capabilities, response procedures, and overall security posture. When incidents occur, you become the incident commander, orchestrating response from the moment a threat is detected through containment, eradication, and recovery. Position Responsibilities: * Manage SOC daily activities, including building and maintaining shift schedules and ensuring all documentation, including SOPs, Playbooks, and CONOPS, are current. * Manage Tier I, II, and III incident response operations across the federal enterprise, ensuring consistent, high-quality response at every level. * Coordinate containment, eradication, and recovery activities during active security incidents, serving as the primary incident commander and coordinating between the SOC team, IT operations, and relevant stakeholders. * Lead post-incident reviews and root cause analysis to identify lessons learned and drive continuous improvement in SOC processes and detection capabilities. * Ensure compliance with NIST SP 800-61 and federal incident response standard operating procedures across all SOC operations. * Manage SIEM event "notables" dashboards, ensuring timely triage, escalation, and resolution of security alerts. * Maintain the SOC coverage schedule per shift to ensure 24x7x365 operational readiness. * Maintain the call tree, including current contact information for all partner organizations and Cloud Service Providers (CSPs). * Apply MITRE ATT&CK framework to map attacker tactics, techniques, and procedures (TTPs) during investigations and incident response activities. * Encourage team collaboration by fostering a positive team culture, managing workloads effectively, and supporting professional development. * Collaborate with threat hunting, CTI, engineering, and architecture teams to ensure SOC operations are informed by the latest threat intelligence and detection capabilities. * Present incident findings, risk recommendations, and SOC performance metrics to both technical teams and senior government officials in a clear, actionable format. Support the development and continuous improvement of a comprehensive enterprise information security program grounded in the latest laws, regulations, and industry best practices. Required Skills * U.S. Citizenship required. * 8+ years of IT experience, with 4+ years of dedicated incident response and SOC operations experience. * Remote but within close proximity to the NCR. * Active Public Trust 6c clearance, or the ability to obtain and maintain one. * At least one of the following certifications: GCIH, GCFA, GREM, or equivalent. * Hands-on experience with SIEM, SOAR, EDR, CDM, and malware analysis tools and platforms. * Strong experience with operating systems and networking fundamentals, including log analysis, traffic analysis, and endpoint forensics. * Experience with AWS native services and tools in a federal or enterprise cloud environment. * Demonstrated experience managing a SOC overseeing complex, large-scale federal or enterprise IT systems. * Strong command of incident response frameworks including NIST SP 800-61, SANS PICERL, and MITRE ATT&CK. * Practical malware analysis fundamentals, including static analysis, sandboxing, and Indicator of Compromise (IoC) extraction. * Experience with SOAR platforms to automate repetitive elements of incident response and improve analyst efficiency. * Proven ability to translate complex technical findings into clear, actionable language for both technical and executive audiences. * Strong written and verbal communication skills, with a track record of producing high-quality federal security documentation. Desired Skills * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent professional experience. * At least one of the following certifications: * Certified Information Systems Security Professional (CISSP) * GIAC Certified Intrusion Analyst (GCIA) * GIAC Security Expert (GSE) * Certified Information Security Manager (CISM) * AWS Cloud Practitioner or higher, with AWS GovCloud experience desired * Familiarity with federal cybersecurity frameworks including NIST SP 800-53, NIST RMF, IRS Publication 1075, FedRAMP, and OMB compliance requirements. * Experience supporting continuous monitoring programs and coordinating with stakeholders on POA&M remediation tracking. * Prior experience working on large-scale federal civilian agency programs with complex, multi-stakeholder environments. * Experience with cloud-native security operations in AWS GovCloud or Azure Government environments. * Familiarity with scripting languages such as Python or PowerShell for log parsing and investigation acceleration. * Experience integrating CDM program data into SOC workflows and using CDM dashboards to inform incident response priorities. * Ability to provide strategic guidance that enhances and optimizes the agency's overall SOC and incident response posture. * Knowledge of DevSecOps pipelines and experience supporting security operations within CI/CD environments. ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value: * Attracting and developing top talent and high-performing teams * Fostering a culture that is engaging, accountable, and mission-driven Meet the challenge. Make a difference with Everforth ECS!