> Markdown version of [/jobs/ext/2168800-nincident-responder](https://www.wearedevelopers.com/jobs/ext/2168800-nincident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # nIncident Responder - **Company:** Nabout Leidos - **Location:** United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), JavaScript (Programming Language), Software System Penetration Testing, Burp Suite, C++ (Programming Language), Cyber Security, Information Leak Prevention, Perl (Programming Language), Issue Tracking Systems, Python (Programming Language), Network Intrusion Detection Systems, Nmap, Windows PowerShell, Red Team (Cyber Security), Ruby, Security Software, Security Information and Event Management, Scripting, Tanium Platform Expertise, Information Technology, Metasploit, Firepower, Splunk, Cisco, Programming Languages - **Published:** August 21, 2026 - **Apply:** https://jobs.military.com/career/315278/incident-responder-maryland-md-suitland ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.\n * 15+ years of relevant professional experience without a degree.\n * Active TS/SCI security clearance.\n * 10 years of concentrated experience in the CND discipline.\n * 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.\n * Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.\n * Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.\n * Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.\n * Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.\n * Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.\n ## Description * Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.\n * Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.\n * Receive and respond to incident notifications from customers via telephone and email.\n * Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.\n * Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.\n * Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.\n * Maintain detailed and accurate incident documentation and timelines throughout the response process.\n * Participate in incident response meetings, briefings, and after action reviews.\n * Support the execution and evaluation of annual security exercises.\n ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)