Incident Responder - Shift

ICS, Inc.
Quantico, VA, United States
8 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Shift work
Job source

Tech stack

CompTIA Security+ Cyber Security Computer Networks Domain Name System (DNS) Intrusion Detection and Prevention Intrusion Detection Systems Network Security Security Information and Event Management Cyberark Malware Information Technology Cybercrime

Job description

ICS Nett, Inc is hiring a Cyber Incident Responder to join our dynamic team on the 2 positions, One swing shifts from 2.00 PM to Midnight and One overnight shift 9.00 PM to 7.00 AM to provide support to include weekend and holiday on rotations. This is an on-site position at Quantico, VA.

The candidate will provide as a front-line defender, detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.

The Cyber Incident Responder will play an important role responsible for executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS)., *

  • The Incident Responder will collaborate with cross-functional IT and security teams to:
  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours, * Incident Detection & Triage: Monitor security alerts and events from SIEM, EDR, IDS/IPS, firewall, DNS, and ESS sources to rapidly detect, triage, and prioritize potential security incidents.
  • Incident Response Lifecycle: Execute the full incident response lifecycle - preparation, detection and analysis, containment, eradication, recovery, and post-incident activity - in accordance with NIST SP 800-61.
  • Containment & Eradication: Take decisive containment and eradication actions on compromised endpoints, accounts, and systems to limit incident impact.
  • Cyber Task Management: Process and handle JFHQ-DODIN cyber-related tasks, orders, and incident reporting requirements to completion within required timelines.
  • Investigation & Forensics: Identify evidence of illegal activity involving cybercrime offenses; examine computers potentially involved in crime or malware infection and preserve forensic evidence following chain-of-custody procedures.
  • Malware Analysis: Use forensic tools and investigative methods to identify, isolate, and analyze specific electronic data associated with complex malware infections.
  • Incident Documentation: Develop and maintain incident response playbooks, standard operating procedures (SOPs), and detailed incident case documentation.
  • Reporting & Escalation: Provide timely incident reports and escalations to senior leadership and deliver daily/weekly/monthly summaries on incident trends and key indicators of network security.

Must be flexible to work on the assigned in the shift he is assigned:

  • Swing shift from 2.00 PM - Midnight must be willing to support weekend and holiday coverage as scheduled, consisting of four 10-hour shifts per work week.

  • Overnight shift from 9.00 PM to 7.00 AM (overnight) must be willing to support weekend and holiday coverage as scheduled, consisting of four 10-hour shifts per work week.

Requirements

  • At least Two (2) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies., Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form., * Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience., * Must meet DoD 8570 certification requirements at time of hire - IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:34 min

Assigning strict roles for incident response teams

Martin Beránek · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all