> Markdown version of [/jobs/ext/2953656-incident-responder-onsite](https://www.wearedevelopers.com/jobs/ext/2953656-incident-responder-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Responder, Onsite - **Company:** Deloitte T.T.L. - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Salary:** $113,000.0 - $188,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Apple Mac Systems, Border Gateway Protocol, Cyber Security, Computer Networks, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Event Logging, Monitoring of Systems, Hypertext Transfer Protocols (HTTP), Internet Control Message Protocol, Multi-protocol Systems, Pcap, Log Analysis, Simple Mail Transfer Protocols, Routing, Packet Analyzer, Security Information and Event Management, SQL Databases, Transmission Control Protocol (TCP), Web Applications, Computer Networking Systems, Malware, Cyber Threat Analysis, Information Technology, Data Analytics, Operational Systems, Cyber Warfare - **Published:** September 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=610b5d69bbfdf62a ## About the Role * Ability to work independently and collaborate as part of a team * Effective written and verbal communication skills * Meticulous attention to detail and quality of work product * Ability to build and sustain professional relationships * Ability to lead projects or workstreams * Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment * Strong interpersonal skills and professional demeanor * Ability to meet deadlines * Ability to mentor and provide clear guidance to others, * Bachelor's degree * Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future * Active Secret security clearance required * Ability to work onsite up to 5 days a week in Herndon, VA. * 2+ years of experience within the following: * + Analyzing information technology, IoT, and OT security events to discern legitimate security incidents from non-incidents. This includes identifying malicious code and activities present within computer systems and/or enterprise networks. + Working knowledge of various operating systems (e.g., Windows, OS X, Linux) commonly deployed in enterprise networks. A conceptual understanding of Windows Active Directory is also required. + Working knowledge of network communications and routing protocols (e.g., TCP, UDP, Internet Control Message Protocol (ICMP), Border Gateway Protocol (BGP), Multi-Protocol Label Switching (MPLS)), as well as common internet applications and standards (e.g., Simple Mail Transfer Protocol (SMTP), DNS, DHCP, SQL, Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS)). + Experience working with various event logging systems and proficiency in security event log analysis. Previous experience with SIEM platforms that perform log collection, analysis, correlation, and alerting is also required. + Proficiency in utilizing various Packet Capture (PCAP) applications/engines and in the analysis of PCAP data. + Experience with the identification and implementation of countermeasures or mitigating controls for deployment in enterprise network environments. The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $113,000 to $188,400. You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance. ## Description As a Project Delivery PROJECT - Security Engineer III on the project, you will: * The Incident Responder will execute the client Incident Response Management Program in accordance with client requirements and in alignment with the six-phase Incident Response process: planning, identification and declaration, containment, eradication, recovery, and follow-up. * The Incident Responder will perform incident response activities related to Internet of Things (IoT) and Operational Technology (OT) devices, including coordinating and managing end-to-end responses to security events and incidents identified by the SOC or reported to the SOC; performing initial malware analysis and triage support; operating incident analysis tools and systems; and adhering to reporting requirements for all declared significant incidents., Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions. The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals. ## Related Videos - [Why Your Next Best Talent Might Not Be in Your Neighborhood](https://www.wearedevelopers.com/videos/1861-why-your-next-best-talent-might-not-be-in-your-neighborhood) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Recruitment Reinvented: Bold strategies and the $10K signing incentive](https://www.wearedevelopers.com/videos/1068-recruitment-reinvented-bold-strategies-and-the-10k-signing-incentive) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)