Cyber Incident Responder (24x7 Days)

ASRC FEDERAL
Quantico, VA, United States
8 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work

Tech stack

CompTIA Security+ Cyber Security Computer Networks Computer Literacy Intrusion Detection Systems Pcap Log Analysis Packet Analyzer Security Information and Event Management Cyberark Firewalls (Computer Science) SC Clearance
+3 more
Information Technology Cybercrime Vulnerability Analysis

Job description

The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions., The Cyber Incident Responder is a vital role responsible for executing the full incident response lifecycle during day shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).

The Incident Responder will collaborate with cross-functional IT and security teams to:

  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours, * Develop, maintain, and provide a weekly brief that captures all the cyber events including metrics and trends.
  • Ability to provide continuous monitoring, data to include but not limited to network and host vulnerability scanning IDS, firewall, network sensor tuning, net flow/packet capture (PCAP). Collect and keep audit data in order to conduct a technical analysis relating to misuse, penetration, or other incidents.
  • Document incidents, response actions, and remediation recommendations in accordance with government reporting requirements.
  • Monitor multiple environments for malicious or anomalous activity using SIEM, SOAR, and on-prem security tooling.
  • Analyze logs, telemetry, alerts, and audit data to identify indicators of compromise (IOCs) and attack patterns.

Work Environment and Physical Demands:

  • This is a fully on-site position at DCSA facilities, Quantico Marine Corps Base, VA. Telework is not offered for this shift.
  • Must work the assigned day shift (0600 - 1600) and support weekend and holiday coverage as scheduled.
  • Must be able to communicate complex technical ideas to a diverse customer base, both verbally and in written form.

Requirements

ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the day shift ( 0600 - 1600 ), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA - no telework is available for this role., * At least Five (5) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.

  • Active Top-Secret Clearance REQUIRED , eligible to be upgraded to TS/SCI.
  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire - IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP); CSIH, GCIH, or GCFA preferred for incident handling.
  • Willingness and availability to work the day shift ( 0600 - 1600 ), including weekend and holiday rotations, fully on-site at Quantico, VA., * Knowledge of computer network defense concepts, DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cybersecurity and Computer Network Defense Policies Cybersecurity and Computer Network Defense policies

Benefits & conditions

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

About the company

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:05 min

Maximizing global incident coverage through asynchronous remote team distribution

Hazal Mestci +1 · Coffee With Developers

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

46 sec

Using LLMs to reverse engineer undocumented legacy code

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all