Computer Network Defense Incident Manager III

Argo Cyber Systems
Arlington, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$95,000.0 - $115,000.0
Working hours
Shift work
Job source

Tech stack

Cyber Security Information Systems Computer Networks Computer Forensics Monitoring of Systems Intrusion Detection and Prevention Intrusion Detection Systems Information Systems Security Architecture Professional Network Security Log Analysis Packet Analyzer Phishing
+12 more
Security Information and Event Management Mitre Att&ck Malware Cyber Threat Analysis Falcon Platform Information Technology Cybercrime Cyber Warfare Splunk SentinelOne Expertise Servicenow Vulnerability Analysis

Job description

Argo Cyber Systems is seeking an experienced Cyber Incident Manager - Computer Network Defense to lead and coordinate incident response operations for a high-profile U.S. Government customer. The Incident Manager will oversee the triage, analysis, and resolution of cybersecurity events across federal civilian networks and critical assets. This role requires a mix of technical depth, investigative skill, and the ability to synthesize complex data into actionable recommendations for both technical and executive audiences., * Lead and manage incident response and cyber defense operations, ensuring timely containment, eradication, and recovery.

  • Correlate and analyze incident data to identify trends, adversary tactics, and systemic vulnerabilities.
  • Conduct Computer Network Defense (CND) triage, assessing scope, urgency, and operational impact of security events.
  • Develop and recommend Defense-in-Depth strategies, layered defense architectures, and resilience improvements.
  • Research and document resolutions and mitigations to support enterprise recovery and strengthen future defenses.
  • Apply cybersecurity and threat intelligence concepts to detect, analyze, and respond to intrusions in both small and large-scale network environments.
  • Monitor and assess external threat data sources to maintain situational awareness and anticipate potential impacts to the enterprise.
  • Lead the investigation of incident root causes, infection vectors, and attacker methodologies.
  • Receive, analyze, and validate security alerts from enterprise monitoring tools, escalating as appropriate.
  • Track and document all incident response activities from detection through closure, ensuring comprehensive reporting and lessons learned.
  • Support continuous improvement by refining processes, updating playbooks, and mentoring junior analysts.

Requirements

Do you have experience in Triage?, Do you have a Bachelor’s degree?, * U.S. Citizenship (required)

  • Active TS/SCI clearance (required)
  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Systems, or related discipline
  • Ability to obtain DHS Entry on Duty (EOD) Suitability
  • 5+ years of hands-on experience in cyber incident management or SOC/DFIR operations
  • Deep understanding of incident response methodologies, containment strategies, and recovery workflows
  • Working knowledge of NIST SP 800-61 Rev.2 (Computer Security Incident Handling Guide) and FISMAincident reporting standards
  • Strong ability to analyze, prioritize, and document incidents, including phishing, lateral movement, and privilege escalation cases
  • Comprehensive understanding of cyberattack lifecycle stages and adversary tactics, techniques, and procedures (TTPs)
  • Proficiency in identifying vulnerabilities, threat vectors, and exploitation patterns
  • Knowledge of operating system hardening, network defense, and system administration fundamentals
  • Familiarity with nation-state, criminal, and opportunistic threat actor profiles and their operational tradecraft
  • Excellent communication, coordination, and leadership skills in high-pressure, mission-driven environments

Additional Desires and Considerations

  • Proficiency with enterprise SIEM, EDR, and incident management platforms (e.g., Splunk, SentinelOne, CrowdStrike, ServiceNow)
  • Experience leading shift-based operations or 24x7 response teams
  • Deep knowledge of malware, intrusion detection, and threat hunting techniques
  • Familiarity with log analysis, packet capture, and intrusion detection systems (IDS/IPS)
  • Strong understanding of MITRE ATT&CK framework and cyber kill chain methodology
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Certified Intrusion Analyst (GCIA/GCED)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Cyber Forensics Professional (CCFP) or equivalent

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance, * Shift work position; schedule determined upon start.
  • ECP-1 rates apply.
  • Must be available for onsite support during active incidents or surge operations.

About the company

Argo Cyber Systems provides mission-critical cybersecurity support to U.S. Government agencies and critical infrastructure owners nationwide. Our teams deliver rapid incident response, advanced forensics, and coordinated recovery operations to protect vital systems from evolving cyber threats. We combine technical precision with operational agility-helping federal partners identify, contain, and recover from complex cyber incidents with speed and confidence., As part of Argo Cyber Systems, you will serve at the forefront of national cyber defense-protecting civilian agencies and high-value assets from persistent and emerging threats. You’ll join a veteran-founded, mission-driven team dedicated to operational excellence, collaboration, and innovation in the cyber domain.

Company Benefits

ARGO Cyber Systems provides industry competitive employee benefits to include medical, dental, vision, life insurance, and 401K.

Argo Cyber Systems is a Federal Contractor and an Equal Opportunity Employer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all