> Markdown version of [/jobs/ext/512535-computer-network-defense-incident-manager-iii](https://www.wearedevelopers.com/jobs/ext/512535-computer-network-defense-incident-manager-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Computer Network Defense Incident Manager III - **Company:** Argo Cyber Systems - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $95,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Computer Networks, Computer Forensics, Monitoring of Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Network Security, Log Analysis, Packet Analyzer, Phishing, Security Information and Event Management, Mitre Att&ck, Malware, Cyber Threat Analysis, Falcon Platform, Information Technology, Cybercrime, Cyber Warfare, Splunk, SentinelOne Expertise, Servicenow, Vulnerability Analysis - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e631ef4a9a6f52d6 ## About the Role Do you have experience in Triage?, Do you have a Bachelor's degree?, * U.S. Citizenship (required) * Active TS/SCI clearance (required) * Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related discipline * Ability to obtain DHS Entry on Duty (EOD) Suitability * 5+ years of hands-on experience in cyber incident management or SOC/DFIR operations * Deep understanding of incident response methodologies, containment strategies, and recovery workflows * Working knowledge of NIST SP 800-61 Rev.2 (Computer Security Incident Handling Guide) and FISMAincident reporting standards * Strong ability to analyze, prioritize, and document incidents, including phishing, lateral movement, and privilege escalation cases * Comprehensive understanding of cyberattack lifecycle stages and adversary tactics, techniques, and procedures (TTPs) * Proficiency in identifying vulnerabilities, threat vectors, and exploitation patterns * Knowledge of operating system hardening, network defense, and system administration fundamentals * Familiarity with nation-state, criminal, and opportunistic threat actor profiles and their operational tradecraft * Excellent communication, coordination, and leadership skills in high-pressure, mission-driven environments Additional Desires and Considerations * Proficiency with enterprise SIEM, EDR, and incident management platforms (e.g., Splunk, SentinelOne, CrowdStrike, ServiceNow) * Experience leading shift-based operations or 24x7 response teams * Deep knowledge of malware, intrusion detection, and threat hunting techniques * Familiarity with log analysis, packet capture, and intrusion detection systems (IDS/IPS) * Strong understanding of MITRE ATT&CK framework and cyber kill chain methodology * GIAC Certified Incident Handler (GCIH) * GIAC Certified Forensic Analyst (GCFA) * GIAC Certified Intrusion Analyst (GCIA/GCED) * Certified Information Systems Security Professional (CISSP) * Certified Cyber Forensics Professional (CCFP) or equivalent ## Description Argo Cyber Systems is seeking an experienced Cyber Incident Manager - Computer Network Defense to lead and coordinate incident response operations for a high-profile U.S. Government customer. The Incident Manager will oversee the triage, analysis, and resolution of cybersecurity events across federal civilian networks and critical assets. This role requires a mix of technical depth, investigative skill, and the ability to synthesize complex data into actionable recommendations for both technical and executive audiences., * Lead and manage incident response and cyber defense operations, ensuring timely containment, eradication, and recovery. * Correlate and analyze incident data to identify trends, adversary tactics, and systemic vulnerabilities. * Conduct Computer Network Defense (CND) triage, assessing scope, urgency, and operational impact of security events. * Develop and recommend Defense-in-Depth strategies, layered defense architectures, and resilience improvements. * Research and document resolutions and mitigations to support enterprise recovery and strengthen future defenses. * Apply cybersecurity and threat intelligence concepts to detect, analyze, and respond to intrusions in both small and large-scale network environments. * Monitor and assess external threat data sources to maintain situational awareness and anticipate potential impacts to the enterprise. * Lead the investigation of incident root causes, infection vectors, and attacker methodologies. * Receive, analyze, and validate security alerts from enterprise monitoring tools, escalating as appropriate. * Track and document all incident response activities from detection through closure, ensuring comprehensive reporting and lessons learned. * Support continuous improvement by refining processes, updating playbooks, and mentoring junior analysts. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)