> Markdown version of [/jobs/ext/1465570-incident-response-engineer](https://www.wearedevelopers.com/jobs/ext/1465570-incident-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Engineer - **Company:** DUNHILL PROFESSIONAL SEARCH - **Location:** Arlington, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $125,000.0 - $142,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Network Security, Log Analysis, Network Forensics, Security Information and Event Management, Computer Networking Systems, QRadar, Malware, Cyber Threat Analysis, Information Technology, Splunk - **Published:** July 28, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9060113/incident-response-engineer ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience. * Typically 5-7 years of experience in security operations and incident response with hands-on exposure to forensics and SIEM in government or similarly regulated environments. * Demonstrated experience triaging security alerts, conducting incident investigations, and supporting containment and recovery activities. * Hands-on experience with SIEM platforms and endpoint or network security tools used for incident detection and response. * Proven ability to perform log analysis, basic malware analysis, and evidence preservation to support reporting and potential regulatory needs. * Active TS/SCI security clearance * U.S. citizenship, as required to support a federal IT environment., * Experience with leading SIEM and incident response tools such as Splunk, Elastic, QRadar, or similar platforms. * Industry certifications such as GCIA, GCFA, GCIH, or equivalent incident response/forensics credentials. * Experience handling data spills or incidents involving sensitive or classified information under formal response frameworks. * Background participating in threat hunting operations and developing or refining incident response playbooks. #cjpost ## Description Job Description: The Incident Response Engineer Journeyman is a mid-level cybersecurity professional responsible for detecting, investigating, and remediating security incidents affecting mission-critical systems in a highly regulated government environment. This role analyzes security alerts, leads triage activities, and coordinates containment and recovery actions with operations, IT, and mission stakeholders. The engineer also contributes to threat hunting, maintains incident response playbooks and tooling, and produces clear reports and metrics to drive continuous improvement of security operations., * Perform initial detection, triage, and validation of security events from SIEM, endpoint, network, and cloud security tools to distinguish true incidents from false positives and prioritize response. * Lead or support containment, eradication, and recovery efforts for cybersecurity incidents, coordinating with system owners and operations teams to minimize impact on mission-critical systems. * Conduct host and network forensics, log analysis, and malware analysis to determine root cause, attack path, and data exposure, preserving evidence as needed. * Maintain and enhance incident response runbooks, playbooks, and standard operating procedures that align with organizational policies, regulatory frameworks, and evolving threat landscapes. * Participate in proactive threat hunting using security telemetry, threat intelligence, and behavioral analytics to identify stealthy or emerging threats in enterprise networks. * Configure, tune, and maintain incident response tooling and SIEM rules to improve detection fidelity, reduce noise, and enhance visibility across regulated environments. * Produce clear incident reports, metrics, and post-incident reviews documenting timeline, impact, corrective actions, and recommendations for control improvements. * Collaborate with security training and awareness functions to support tabletop exercises, incident simulations, and communications that reinforce response readiness. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [WeAreDevelopers LIVE - Yes, CSS Can Do That!](https://www.wearedevelopers.com/videos/1819-wearedevelopers-live-yes-css-can-do-that) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)