> Markdown version of [/jobs/ext/2709444-senior-cybersecurity-incident-response-administrator](https://www.wearedevelopers.com/jobs/ext/2709444-senior-cybersecurity-incident-response-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Incident Response Administrator - **Company:** NCI Information Systems Inc. - **Location:** Radford, VA, United States - **Experience:** Expert - **Salary:** $87,320.0 - **Contract:** Permanent contract - **Skills:** Audit Trail, Business Systems, Configuration Management, CompTIA Security+, Cyber Security, Monitoring of Systems, Information Systems Security Engineering Professional, Network Security, Public Key Infrastructure, Web Application Security, Security Information and Event Management, Information Technology, Data Management - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/job/us2031c361b0a42770f132130c47559a49/eaa ## About the Role This is a remote-eligible position. Local candidates in the Roanoke and Radford, Virginia area are encouraged to apply, and work may be performed locally for those who prefer an on-site or hybrid arrangement. The ideal candidate will bring deep cybersecurity incident response and SIEM engineering expertise, strong DoD cybersecurity compliance knowledge, and the ability to support mission-critical Army IT services across enterprise data centers and cloud-hosted environments, * Cybersecurity Certification (such as CISSP, ISSEP, Security+, CEH, or equivalent). * Bachelor's degree in Computer Science is preferred; equivalent years of cybersecurity and incident response experience will be considered in lieu of a degree. * Active DoD Secret Security Clearance. * 10 or more years' experience with Cybersecurity and Incident Response or related areas. * Extensive experience managing SIEM systems, including ingesting relevant data into the SIEM. * Proficiency in creating and managing SIEM dashboards for security event visualization. * Strong ability to monitor and investigate security events and anomalies. * Experience developing reporting requirements for audits and security controls. * Knowledge of Public Key Infrastructure (PKI) and managing SSL/TLS certificates. * Familiarity with DoD and Army web application security standards and best practices. * Ability to review and respond to Army Cyber Tasking Orders (CTOs). * Experience coordinating with Cyber Security Service Providers for audit logs and incident response. * Participation in Software Assurance reviews for application audit log validation. * Ability to review and evaluate Information Systems Design Plans and related documents for security compliance. Preferred: * Bachelor's degree in Computer Science or equivalent years of experience. * Familiarity with Army enterprise monitoring tools and practices. * Strong analytical and problem-solving skills. * Excellent communication and coordination skills. * Experience with incident response activities. * Knowledge of engineering change proposals and configuration management. * Understanding of Continuity of Operations Plans and Communication Plans. * Experience with security regulations and best industry practices. * Ability to work effectively in a team environment and collaborate with various stakeholders. ## Description The Senior Cybersecurity Incident Response Administrator manages Security Information and Event Management (SIEM) systems, including deployment, installation, infrastructure management, and event monitoring in accordance with Army Business System Log Data Policy and other DoD/Army requirements. This role creates SIEM dashboards for clear, concise visualization of security-related events, enabling near real-time detection of anomalies and investigation of threats., * Deploy, install, manage infrastructure, and monitor events within SIEM systems in accordance with Army Business System Log Data Policy and other DoD/Army requirements. * Create SIEM dashboards for visualization of security-related events and near real-time anomaly detection. * Monitor SIEM dashboards to detect threats and anomalies, investigate events, and escalate as necessary. * Assess and develop reporting requirements to support audits and security controls. * Provide Public Key Infrastructure (PKI) support and monitor DoD/Army web application security standards. * Review Army Cyber Tasking Orders (CTOs) and coordinate with Army Cyber Security Service Providers. * Participate in Software Assurance reviews and evaluate Information Systems Design Plans for compliance with security regulations, policies, and best practices., The Senior Cybersecurity Network Defense Administrator performs a variety of network defense activities in accordance with established guidelines and best practices, managing ACAS … + 15 hours ago, The Senior Storage Administrator supports a mixed and growing environment of enterprise storage hardware, working with the existing OS and Storage teams to manage, maintain, deploy… + 16 hours ago ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [It's all about the Data](https://www.wearedevelopers.com/videos/425-it-s-all-about-the-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)