> Markdown version of [/jobs/ext/640792-cyber-incident-manager](https://www.wearedevelopers.com/jobs/ext/640792-cyber-incident-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Manager - **Company:** Quantum Science Solutions - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Networks, Computer Forensics, Computer Literacy, Information Systems Security Architecture Professional, Network Security, Phishing, PL-SQL, Software Security, Cybercrime, Cyber Warfare - **Published:** June 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8996449/cyber-incident-manager ## About the Role * U.S. Citizenship. * Active TS/SCI clearance. * Ability to obtain DHS Suitability. * Minimum of 5+ years of directly relevant experience in cyber incident management, incident response, or cybersecurity operations. * Knowledge of incident response and incident handling methodologies. * Familiarity with NIST 800-62 and FISMA standards as they relate to incident reporting. * Ability to prioritize incidents based on scope, urgency, and potential impact. * Experience investigating and describing tactics used in phishing campaigns. * Ability to recognize gaps in incident reporting and recommend corrective actions. * Knowledge of general attack stages, including footprinting, scanning, enumeration, gaining access, privilege escalation, maintaining access, network exploitation, and covering tracks. * Skill in recognizing and categorizing vulnerabilities and associated attack types. * Knowledge of basic system administration and operating system hardening techniques. * Knowledge of Computer Network Defense policies, procedures, and regulations. * Knowledge of operational threat environments, including non-nation-state and nationstate sponsored threats. * Knowledge of system and application security threats and attack methods, including buffer overflow, mobile code, cross-site scripting, PL/SQL and injection attacks, race conditions, covert channels, replay attacks, return-oriented attacks, and malicious code. Preferred Skills * Additional experience with operational threat environments, including first generation, second generation, and third generation threat actors. * Additional knowledge of system and application security threats and attack methods. * Experience supporting cyber operations centers, incident response teams, or enterprise security operations. * Experience performing event correlation, IOC research, and cyber incident escalation. * Strong written and verbal communication skills. * Strong analytical, documentation, and problem-solving abilities., * Bachelor's degree in Incident Management, Operations Management, Cybersecurity, or a related discipline. OR * High School Diploma with 7-9 years of incident management or cybersecurity experience. Desired Certifications * GIAC Certified Incident Handler (GCIH) * GIAC Certified Forensic Analyst (GCFA) * GIAC Information Security Professional (GISP) * GIAC Certified Enterprise Defender (GCED) * Certified Cyber Forensics Professional (CCFP) * Certified Information Systems Security Professional (CISSP) ## Description Quantum Science Solutions (QSS) is seeking an experienced Cyber Incident Manager to support mission-critical cybersecurity operations through incident triage, analysis, documentation, coordination, and resolution. This role is responsible for managing Computer Network Defense (CND) incidents from initial detection through final resolution while supporting enterprise cyber defense activities and incident reporting requirements. The selected candidate will analyze network alerts, correlate incident data, identify trends, determine incident scope and urgency, and coordinate with internal teams to support timely mitigation and response. This position requires strong knowledge of incident response methodologies, cybersecurity operations, attack stages, vulnerability categories, and Federal incident reporting standards., * Perform Computer Network Defense incident triage to determine incident scope, urgency, severity, and potential enterprise impact. * Receive, review, and analyze network alerts from multiple enterprise sources to determine possible causes and required response actions. * Correlate incident data to identify trends, recurring issues, and patterns in reported cybersecurity incidents. * Track and document CND incidents from initial detection through final resolution. * Coordinate with internal components and stakeholders to gather information related to ongoing incidents. * Research and compile known resolution steps, workarounds, and mitigation actions to support incident response efforts. * Apply cybersecurity concepts to detect, analyze, and defend against intrusions across small and large-scale IT networks. * Conduct cursory analysis of log data to identify potential indicators of compromise or suspicious activity. * Monitor external data sources to maintain awareness of current CND threat conditions and assess potential enterprise impact. * Identify incident causes and determine key information needed from external entities regarding infection vectors and background details. * Prioritize incidents and support escalation to specialized analysts when advanced investigation is required. * Analyze phishing-related activity and describe tactics, techniques, and indicators associated with phishing campaigns. * Recognize gaps in incident reporting and recommend improvements to support accurate and complete documentation. * Recommend defense-in-depth principles and practices, including layered defenses, security robustness, and defense in multiple places. * Support shift-based cyber operations, incident triage, IOC research, and escalation workflows as assigned. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)