> Markdown version of [/jobs/ext/208639-cyber-incident-management-lead](https://www.wearedevelopers.com/jobs/ext/208639-cyber-incident-management-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Management Lead - **Company:** Gunnison Consulting Group Inc - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $145,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Security Management, Intrusion Detection and Prevention, Red Team (Cyber Security), Software Vulnerability Management, Malware, Cyber Threat Analysis, Purple Team (Cyber Security), Cyber Warfare - **Published:** May 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=25c711b6baa6bc94 ## About the Role Do you have experience in Threat intelligence?, Do you have a Master of Science?, * US Citizenship required * Master of Science degree in IT, Information Security, or related field * 10+ years in incident response/security operations/penetration testing * 5+ years managing IR teams * Strong knowledge of malware analysis, forensics, threat intel, and adversary TTPs * Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst (mandatory) Clearance Requirement: Ability to obtain and maintain a Public Trust. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT). * Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. * Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements. * Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities. * Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution. * Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities. * Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines. * Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events. * Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization's security posture. * Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures. * Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification. * Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes. * Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders. * Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)