Cyber Incident Response SME

Kforce Inc.
Arlington, VA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Cyber Security Identity and Access Management Intrusion Detection and Prevention Network Architecture Information Technology Cybercrime ArcSight Event Correlation Cyber Warfare

Job description

We are seeking a highly skilled Cyber Incident Response Expert to support a mission-critical federal cybersecurity program focused on protecting national infrastructure. This role sits on a front-line team responsible for proactive threat hunting and rapid response to sophisticated cyber incidents across enterprise and critical environments. This is a high-impact opportunity to work alongside elite cybersecurity professionals conducting advanced investigations, containment, and remediation of complex threats., Serve as a subject matter expert (SME) for cyber hunt and incident response activities Analyze threat actor tactics, techniques, and procedures (TTPs) to detect and mitigate risks Lead and support incident response efforts, including containment, eradication, and recovery Conduct deep analysis of endpoint and network data to identify indicators of compromise Produce executive-level summaries and detailed technical reports Develop and recommend targeted mitigation and remediation strategies Provide technical guidance to stakeholders and response teams during active incidents Support proactive threat hunting across enterprise environments Document findings and contribute to internal knowledgebases Collaborate across distributed teams and advise on countermeasure implementation

Requirements

Active TS/SCI clearance Ability to obtain additional federal suitability as required 7+ years of relevant cybersecurity experience 3+ years supporting or developing cyber response capabilities Strong experience in incident response and threat hunting Solid understanding of network architecture and security principles Experience analyzing system and application vulnerabilities Knowledge of attack methods, kill chains, and adversarial behaviors Proficiency with Windows and Linux/Unix environments Strong written and verbal communication skills Ability to work independently and collaboratively in fast-paced environments Willingness to travel domestically on short notice, Experience leading or mentoring technical teams Knowledge of cyber defense policies and operational frameworks Familiarity with a range of threat environments, including advanced adversaries Hands-on experience with intrusion detection, event correlation, and threat analysis Exposure to identity and access management (IAM) tools Ability to assess enterprise environments from a security architecture perspective Understanding of defense-in-depth strategies Background in network or system administration

Education

Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field OR High School Diploma with 7+ years of relevant technical experience

Certifications (Preferred) One or more of the following:

DoD 8140-aligned certifications (IAT Level II, IASAE II, CSSP Analyst/Incident Responder) GIAC certifications (GCIA, GCIH, GNFA) CEH or equivalent Other advanced cybersecurity certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all