> Markdown version of [/jobs/ext/530315-cyber-incident-response-sme](https://www.wearedevelopers.com/jobs/ext/530315-cyber-incident-response-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Response SME - **Company:** Kforce Inc. - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Network Architecture, Information Technology, Cybercrime, ArcSight Event Correlation, Cyber Warfare - **Published:** June 13, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8974253/cyber-incident-response-sme ## About the Role Active TS/SCI clearance Ability to obtain additional federal suitability as required 7+ years of relevant cybersecurity experience 3+ years supporting or developing cyber response capabilities Strong experience in incident response and threat hunting Solid understanding of network architecture and security principles Experience analyzing system and application vulnerabilities Knowledge of attack methods, kill chains, and adversarial behaviors Proficiency with Windows and Linux/Unix environments Strong written and verbal communication skills Ability to work independently and collaboratively in fast-paced environments Willingness to travel domestically on short notice, Experience leading or mentoring technical teams Knowledge of cyber defense policies and operational frameworks Familiarity with a range of threat environments, including advanced adversaries Hands-on experience with intrusion detection, event correlation, and threat analysis Exposure to identity and access management (IAM) tools Ability to assess enterprise environments from a security architecture perspective Understanding of defense-in-depth strategies Background in network or system administration Education Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field OR High School Diploma with 7+ years of relevant technical experience Certifications (Preferred) One or more of the following: DoD 8140-aligned certifications (IAT Level II, IASAE II, CSSP Analyst/Incident Responder) GIAC certifications (GCIA, GCIH, GNFA) CEH or equivalent Other advanced cybersecurity certifications ## Description We are seeking a highly skilled Cyber Incident Response Expert to support a mission-critical federal cybersecurity program focused on protecting national infrastructure. This role sits on a front-line team responsible for proactive threat hunting and rapid response to sophisticated cyber incidents across enterprise and critical environments. This is a high-impact opportunity to work alongside elite cybersecurity professionals conducting advanced investigations, containment, and remediation of complex threats., Serve as a subject matter expert (SME) for cyber hunt and incident response activities Analyze threat actor tactics, techniques, and procedures (TTPs) to detect and mitigate risks Lead and support incident response efforts, including containment, eradication, and recovery Conduct deep analysis of endpoint and network data to identify indicators of compromise Produce executive-level summaries and detailed technical reports Develop and recommend targeted mitigation and remediation strategies Provide technical guidance to stakeholders and response teams during active incidents Support proactive threat hunting across enterprise environments Document findings and contribute to internal knowledgebases Collaborate across distributed teams and advise on countermeasure implementation ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)