> Markdown version of [/jobs/ext/2677932-cyber-defense-incident-responder-senior](https://www.wearedevelopers.com/jobs/ext/2677932-cyber-defense-incident-responder-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense Incident Responder Senior - **Company:** Lockheed Martin - **Location:** Hanover, MD, United States - **Experience:** Expert - **Salary:** $135,700.0 - $251,900.0 - **Contract:** Permanent contract - **Skills:** Network Analysis, Cyber Security, Information Systems, Computer Networks, Computer Forensics, Issue Tracking Systems, Security Information and Event Management, Software Engineering, Traffic Analysis, Wireshark, Mitre Att&ck, QRadar, Information Technology, Cyber Warfare, Splunk, Doctrine (orm) - **Published:** September 1, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9131644/cyber-defense-incident-responder-senior ## About the Role * High School Diploma plus 13 years of relevant experience is required OR Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or related discipline from an accredited college or university, plus 10 years of relevant experience is required OR Master's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, Software Engineering, or related discipline from an accredited college or university, plus 8 years of relevant experience is required. * Experience leading major breach investigations and directed cross-functional response teams, ensuring rapid containment and coordinated remediation with network and system owners and experience performing real-time traffic analysis, executed run-book procedures to isolate affected hosts, and developed containment strategies that limited lateral movement. * Experience capturing and preserved forensic artifacts for potential legal use while documenting every action in the incident ticketing system to maintain auditability and traceability and managing incident-response staffing, training, and post-incident lessons-learned workshops that captured findings and drove continuous process improvements. * Experience producing concise incident summary reports for senior management and key stakeholders, highlighting root-cause analysis, remediation status, and recommendations. * Must possess a current U.S. TS/SCI security clearance with polygraph. Desired Skills * Certifications: CISSP, GCIH, GCFA, CISA, or equivalents. * Proficiency with network analysis tools (Wireshark, Zeek), forensic suites, and SIEM platforms (Splunk, QRadar). * Strong written and oral communication skills; ability to produce concise executive reports. * Strategic thinking aligned with mission objectives. * Ability to lead multidisciplinary teams under pressure. * Expertise in MITRE ATT&CK framework and incident-response playbooks. * Experience in DoD or intelligence-community cyber environments. ## Description The scope of this effort encompasses tasks that provide USCYBERCOM with the sustained ability to fulfill its mission to direct, synchronize, and coordinate cyberspace planning and operations to defend and advance national interests in collaboration with domestic and international partners. These tasks include coordinating, synchronizing, deconflicting, and integrating operational planning efforts for full-spectrum cyberspace operations., As a Cyber Defense Incident Responder - Senior you will provide Cyberspace Operations Support Services (COSS) aligned with the following core disciplines: Cyberspace Operations, Cyberspace Planning, Cyberspace Training and Exercises, Strategy/Policy/Doctrine Development and Campaign, Assessments, Information Technology (IT)/Communications, Business Area Support and Project Management Engagement Activities. You will provide the customer with the sustained ability to fulfill its mission to direct, synchronize, and coordinate cyberspace planning and operations to defend and advance national interests in collaboration with domestic and international partners. These tasks include coordinating, synchronizing, deconflicting, and integrating operational planning efforts for full-spectrum cyberspace operations. You will meet the evolving cyberspace operations mission in support of the Joint warfighter. WHY JOIN US Join a global technology leader where your ideas can make a difference and your contributions are valued. Work on exciting projects that challenge you to push boundaries and innovate. Grow your career in an environment that encourages learning, development, and creativity. We support our employees, so they can support our mission. Solves complex problems related to computer network defense, incident response, insider threat, and computer forensics. Monitors, analyzes, and validates threat intelligence to identify, mitigate, and report cyber security threats. Provides timely detection, alerting, and response of malicious network activity originating from external and internal threat actors. Identifies, develops, and implements resilient countermeasures to reduce risk to the enterprise. Responsible for the creation of fused intelligence products based on full analysis and methodologies. USE OF THIS CLASSIFICATION REQUIRES AUTHORIZATION FROM THE BUSINESS AREA CYBER DIRECTOR OR DELEGATE ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)