Talent.com
Cyber Incident Response Analyst

Cyber Incident Response Analyst

Leidos IncAshburn, VA, United States
job_description.job_card.1_day_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

Leidos is seeking a highly skilled Cyber Incident Response Analyst to support a high-visibility cybersecurity contract providing 24x7x365 Security Operations Center (SOC) support, cyber analysis, and application development.

This role supports the DHS SOC, which is responsible for monitoring, detecting, analyzing, mitigating, and responding to cyber threats across the DHS Enterprise. The SOC leads incident detection and response at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP), coordinating efforts across Component SOCs via a shared incident tracking system and other communication channels.

Primary Responsibilities

Provide expert investigative support for large-scale and complex security incidents, including those lacking technical detection

Ensure SOC compliance with relevant cybersecurity regulations and standards

Identify threat actor TTPs, post-compromise behaviors, and insider threats through data analysis

Create and modify SIEM dashboards to visualize findings and monitor activity

Drive implementation and enhancement of tools, frameworks, and methodologies

Promote best practices in incident response, cybersecurity analysis, case management, and SOC operations

Monitor external sources (e.g., CERTs, vendor sites) to stay current on cyber threat conditions

Advocate for automation and process efficiency improvements

Mentor junior analysts to elevate team capabilities and deliver high-quality work

Build trust and maintain relationships with customers and stakeholders

Basic Qualifications

Active TS / SCI clearance ; must also obtain a favorable DHS Entry on Duty (EOD) determination

Bachelor's degree in IT, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET or NCAE-C designated institution

Minimum 8-12 of experience in incident detection / response, malware analysis, or cyber forensics

A bachelor's degree may substitute for up to 1 year of experience

A master's degree may substitute for up to 2 years of experience

At least two certifications from the following : Security+, PenTest+, Cloud+, GSEC, CEH, CCE, CFR, CySA+, GCFA, GCIA, GCIH, GDSA, GICSP

Advanced experience in CIRT and / or SOC operations for large enterprises

Deep understanding of the Incident Response lifecycle

Familiarity with Intelligence Driven Defense, Cyber Kill Chain, and MITRE ATT&CK frameworks

Knowledge of enterprise network architecture, protocols (DHCP, DNS, HTTP), and devices (firewalls, proxies, VPNs)

Expertise in Windows and Linux operating systems and artifacts

Strong grasp of industry standards and best practices for incident response and SOC operations

Excellent analytical, troubleshooting, and communication skills

Ability to work independently with minimal supervision

Must be a U.S. Citizen

Preferred Qualifications

In-depth knowledge of current and emerging cybersecurity technologies

Hands-on experience in Protect, Detect, Respond, and Sustain functions within a CIRT

Strong understanding of cyber threat lifecycle, attack vectors, and adversary TTPs

Experience monitoring and responding to threats in cloud environments (AWS, Azure, etc.)

Completion of military cyber training courses : 4-11-C32-255S (CP), 4C-255N (CP), or 4C-255A (CP)

Come break things (in a good way). Then build them smarter.

We're the tech company everyone calls when things get weird. We don't wear capes (they're a safety hazard), but we do solve high-stakes problems with code, caffeine, and a healthy disregard for "how it's always been done."

Original Posting : October 6, 2025

For U.S. Positions : While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $104,650.00 - $189,175.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

serp_jobs.job_alerts.create_a_job

Incident Response Analyst • Ashburn, VA, United States

Job_description.internal_linking.related_jobs
Tier 3 Incident Response Senior Analyst

Tier 3 Incident Response Senior Analyst

Resource Management Concepts, Inc.Quantico, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government'...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Senior Consultant, Cyber Incident Response

Senior Consultant, Cyber Incident Response

Control RisksWashington, DC, US
serp_jobs.job_card.full_time +1
serp_jobs.filters_job_card.quick_apply
The Senior Consultant is responsible for delivering Incident Response support to our clients by helping them investigate and remediate the impacts of cyber attacks quickly and comprehensively.This ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Senior Cyber Intrusion Detection Analyst

Senior Cyber Intrusion Detection Analyst

Vets HiredWashington, D.C., District of Columbia, United States
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Associate Director, Cyber Incident Response

Associate Director, Cyber Incident Response

Control RisksWashington, DC, US
serp_jobs.job_card.full_time +1
serp_jobs.filters_job_card.quick_apply
The Associate Director is responsible for managing the Cyber Response Team in the US and leading overall delivery of incident response cases in the region. This role involves leading the technical a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Cybersecurity Metrics & Exercise Analyst

Cybersecurity Metrics & Exercise Analyst

Network Designs Inc.Washington, DC, USA
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly de...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cybersecurity Vulnerability Analyst (Incident Manager III)

Cybersecurity Vulnerability Analyst (Incident Manager III)

Solutions³ LLCArlington, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cybersecurity Vulnerability Analyst (Incident Manager III ) Description : Solutions³ LLC is supporting our prime contractor and their U. Government customer to provide cybersecurity vulne...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cyberecurity Intelligence Analyst

Cyberecurity Intelligence Analyst

Evolver FederalCamp Springs, MD, USA
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
We are seeking a highly skilled and experienced.Cybersecurity Intelligence Analyst.The ideal candidate will have a strong background in both traditional and cyber intelligence analysis, with expert...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cyber Incident Manager / Incident Manager

Cyber Incident Manager / Incident Manager

Node.DigitalArlington, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cyber Incident Manager / Incident Manager.Must have an active Top Secret Security Clearance.Government customer to provide support for onsite incident response to civilian Government agencies and cr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Cybersecurity Vulnerability Analyst

Cybersecurity Vulnerability Analyst

Node.DigitalArlington, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cybersecurity Vulnerability Analyst.Must have an active Top Secret Security Clearance.Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cybersecurity Analyst

Cybersecurity Analyst

Idea EntityHerndon, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cybersecurity / Compliance Analyst.Belcamp, MD, Orlando, FL, Camden, AR, Fullerton, CA, Santa Clarita, CA, Rustburg, VA.Notes : No C2C, must be US Citizen. We are seeking a detail-oriented Compliance A...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.new
Cyber Analyst - Mid

Cyber Analyst - Mid

Nalley ConsultingWashington, DC, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Join the Nalley Consulting team as a Cyber Analyst at DIA HQ.Cyber Analyst LCAT : Mid Location : DIA HQ, Washington, DC Clearance requirement : TS / SCI clearance. CI poly or willingness to take ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
RMF Cybersecurity Analyst - TS / SCI with CI Poly

RMF Cybersecurity Analyst - TS / SCI with CI Poly

ENS Solutions, LLCReston, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities.As a RMF Cybersecurity Analyst supporting the Federal Government and the Inte...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cybersecurity Risk Management Analyst

Cybersecurity Risk Management Analyst

Evolver FederalSpringfield, VA, USA
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Cybersecurity Risk Management Analyst.Federal client in Springfield, VA in managing all aspects of cybersecurity risk and compliance including, but not limited to : maintaining an accurate FISMA Inv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Director, Incident Response, Cybersecurity | Forensic and Litigation Consulting

Director, Incident Response, Cybersecurity | Forensic and Litigation Consulting

FTI Consulting, IncWashington, DC, United States
serp_jobs.job_card.full_time
Director, Incident Response, Cybersecurity | Forensic and Litigation Consulting.FTI Consulting is the leading global expert firm for organizations facing crisis and transformation.We work with many...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Cybersecurity Analyst

Cybersecurity Analyst

Spectrum Comm IncFalls Church, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
The Cybersecurity Analyst protects organizational networks and systems by identifying, analyzing, and mitigating cybersecurity threats. This position uses advanced security tools to monitor vulnerab...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Network Incident Management Quality Assurance Analyst

Network Incident Management Quality Assurance Analyst

CACI InternationalHamilton, VA, United States
serp_jobs.job_card.full_time
Network Incident Management Quality Assurance Analyst.Job Category : Information Technology.Minimum Clearance Required to Start : TS / SCI with Polygraph. Percentage of Travel Required : Up to 10%.Type o...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Cyber Threat Analysis Division Task Lead

Cyber Threat Analysis Division Task Lead

Clearance JobsArlington, VA, US
serp_jobs.job_card.full_time
Seize your opportunity to make a personal impact as a Project / Task Manager supporting our program.GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding ca...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Incident Responder / Incident Response Coordinator

Incident Responder / Incident Response Coordinator

Nationwide IT ServicesArlington, VA, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Incident Responder / Incident Response Coordinator Location : .Onsite – Arlington, VA or Mechanicsburg, PA Clearance Requirement : Active Secret Clearance Employment Type : Full-time Company : Nat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Cyber Analyst - Vulnerability Manager

Cyber Analyst - Vulnerability Manager

ConnsciGaithersburg, MD, USA
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Vulnerability & Compliance Testing : .Conduct authenticated vulnerability scans and compliance evaluations across networks, systems, endpoints, and cloud platforms. Evaluate system, network, and i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
Incident Report Lead

Incident Report Lead

ISI EnterprisesHerndon, VA, US
serp_jobs.job_card.temporary
serp_jobs.filters_job_card.quick_apply
ISI Defense is seeking a cleared, mission-driven Incident Response Lead to lead and scale our IR operations across both internal environments and our Managed Services client base.This role combines...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30