> Markdown version of [/jobs/ext/2542950-incident-response-ir-and-forensics-lead-q-clearance](https://www.wearedevelopers.com/jobs/ext/2542950-incident-response-ir-and-forensics-lead-q-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response (IR) and Forensics Lead (Q Clearance) - **Company:** ShorePoint, Inc - **Location:** Germantown, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Digital Forensics, Identity and Access Management, Network Security, Malware, Cyber Warfare - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e732974258946cd4 ## About the Role * Knowledge of IR and digital forensics principles and practices. * Understanding of cybersecurity operations, including cloud security, endpoint security, access management and secure networking. * Knowledge of security risk assessment and cyber incident analysis. Must have's: * Bachelor's degree or Associate's degree plus an additional 2+ years of experience. * 7+ years of relevant experience. * Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking. * Applicants must currently hold and maintain an active DOE Q or equivalent DoD Top Secret clearance. Beneficial to have: * Industry recognized certifications. ## Description As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 144 hours of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more. Who we're looking for: We are seeking an Incident Response (IR) and Forensics Lead to manage day-to-day team operations while performing hands-on cyber incident investigations, forensic analysis and response activities. This role provides technical support across cybersecurity areas including cloud security, endpoint security, access management, secure networking and IR. The IR and Forensics Lead position coordinates IR activities, provides technical support across the enterprise and communicates incident findings and responses to customers and federal leadership. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. What you'll be doing: * Manage day-to-day operations of the IR and forensics team. * Conduct briefings, coordinate directly with customers and develop IRs for senior federal leadership. * Collect and analyze intrusion artifacts, including source code, malware and trojans, to support mitigation of potential cyber defense incidents across the enterprise. * Coordinate and provide expert technical support to enterprise-wide cyber defense technicians to resolve cyber defense incidents. * Coordinate IR functions. * Monitor external data sources, including cyber defense vendor sites and Computer Emergency Response resources, to support IR activities. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Blockchains: One Size doesn't Fit All](https://www.wearedevelopers.com/videos/409-blockchains-one-size-doesn-t-fit-all) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)