Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details
Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Eliassen Group

• Cyber Incident Management Lead

Career Insights for Incident Analyst / Responder

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Virginia data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.

$121,633 / year median in Virginia

+7% projected growth

Explore Career

Job Description

Job Requirements Alexandria, VA Public Trust Polygraph not specified Senior Level Career (10+ yrs experience) $185,000 - $225,000 Job Description Cybersecurity Incident Response and Penetration Testing Lead Client Description Hybrid 2-3 days per week on-site in Alexandria, VA. Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance. Responsibilities Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT). Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments. Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements. Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities. Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution. Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities. Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines. Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events. Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization's security posture. Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures. Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification. Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes. Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders. Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams. Experience Requirements US Citizenship required. 10+ years in incident response, security operations, or penetration testing. 5+ years managing incident response teams. Strong knowledge of malware analysis, digital forensics, threat intelligence, and adversary TTPs.
Certifications:
CEH or EC-Council Certified Security Analyst. Ability to obtain and maintain a Public Trust clearance. Education Requirements Master of Science degree in IT, Information Security, or related field.
group id:
10106647 Log in to view the job poster Apply now