> Markdown version of [/jobs/ext/1919747-incident-response-ir-manager](https://www.wearedevelopers.com/jobs/ext/1919747-incident-response-ir-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response (IR) Manager - **Company:** Edgewater Federal Solutions - **Location:** Bethesda, MD, United States - **Experience:** Expert - **Salary:** $120,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Data Analysis, CompTIA Security+, Cyber Security, Computer Networks, Microsoft PowerPoint, Power BI, Microsoft SharePoint, Microsoft Power Automate - **Published:** August 4, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17807618?backUrl=%2Fcareer%2F17807618%2FIncident-Response-Ir-Manager-Maryland-Bethesda ## About the Role * 5+ years' experience comprehensive cybersecurity operations leadership and management. * Bachelor's Degree or higher in relevant cybersecurity-related major. * Demonstrated expert-level delivery experience and knowledge of IR concepts, operations, outputs, and maturity levels. * Demonstrated expert-level delivery experience and knowledge of Forensics concepts, operations, outputs, and maturity levels. * Demonstrated expert-level delivery experience and knowledge of ticket management tools and practices; troubleshooting; investigations; computer networking; and operating systems. * Demonstrated expert-level technical ability/aptitude, demonstrated through prior technical experience and accomplishment. * Excellent critical thinking, analytic skills, and experience. * Excellent time management skills and experience. * Excellent management, teamwork, and interpersonal skills against difficult due dates and timelines. * Excellent customer service focus to meet the needs of internal and external customers. * Excellent presentation development and delivery skills. * Excellent program management, project management, and task tracking skills. * Ability to work on occasional weekends and holidays. * Ability to pass an HHS Tier-2 security clearance background investigation. Desired: * One or more certifications in information security (such as CISSP, CISM, CompTIA Advanced Security Practitioner, CompTIA Security Analytics Expert, CCTHP, CySA+, Security+, etc.). * Project Management Certifications (such as CAPM, PMP, ITIL etc.). * Current Security clearance ## Description Edgewater Federal Solutions is currently seeking a Incident Response (IR) Manager to provide IR leadership, management, and support to an Incident Response team comprised of IR Tier-1, IR Tier-2, and Forensics specialists on a Federal government contract. This role will also serve as the "Right-of-Boom" Deputy to the Cybersecurity Operations Task Lead. Responsibilities Provide oversight, leadership, management, work assignment, organization, and administrative duties for a combined team of around 20 cyber security specialists specializing in Incident Response and Forensics. * Provide robust operational management, planning, oversight, metrics, and reporting for the IR team and support audits, assessments, and capability maturity efforts in various tools including Microsoft SharePoint, Excel, PowerPoint, Power Automate, and Power BI. * Ensure the complete, accurate, and timely delivery and/or maintenance of all relevant contract Deliverables and ad hoc work products including briefings, artifacts such as strategy documentation, playbooks, incident tickets and reports, after action reports, shift change and daily mitigation reports, chain of custody forms, forensics reports, shift schedules, and select ad hoc reports and executive briefings as required. * Ensure the IR team supports the Client's incident response (IR) capabilities including incident response policy, plan, process, procedures, guidelines for communications, team structure, relationship management between incident response teams, service creation or enhancement with scope definitions, on-going training needs and documentation creation and maintenance. * Ensure the IR team provides Tier-1 cybersecurity detection and response operational support to identify and respond to potentially malicious, misuse and abuse of anomalous activities across the Client's operating environments, including initial detection, identification, triage, and mitigation of security related incidents impacting the confidentiality, integrity and availability of the Client's network and systems. * Ensure the IR team provides Tier-1 cybersecurity detection and response operational support to identify and accurately categorize cyber security incidents, integrate, and utilize other NIH enterprise security capabilities, support threat mitigation techniques and incident response, minimize ticket/incident backlog in NIH ticketing systems, and notify appropriate authorities of incidents and their severity within established timeframes and guidelines. * Ensure the IR team provides Tier-2 and Forensics. This also includes counterintelligence/insider threat support and research and development. * Ensure the contract team provides forensics services to the Client, including host and appliance based, mobile devices, network, cloud, and malware forensics. * Ensure the contract team provides Counterintelligence (CI) and Insider Threat (InTh) services to the Client, including internal investigations, law enforcement investigations, and active monitoring. * Proactively enable, coordinate, collaborate, integrate, and recommend on-going improvements for IR capabilities and provide guidance to Federal (Client) leadership. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)