user avatar

Cybersecurity Incident Response Lead

Eliassen Group

Posted today

Job Requirements

Alexandria, VA
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Description:
Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA

Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.

Due to federal security clearance requirements, applicant must be a United States Citizen with ability to obtain Public Trust clearance. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $75.00 to $80.00/hr. w2

Responsibilities:
  • Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
  • Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
  • Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
  • Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
  • Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
  • Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
  • Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
  • Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
  • Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization's security posture.
  • Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
  • Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
  • Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
  • Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
  • Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.

Experience Requirements:
  • US Citizenship required.
  • 10+ years in incident response, security operations, or penetration testing.
  • 5+ years managing incident response teams.
  • Strong knowledge of malware analysis, forensics, threat intelligence, and adversary TTPs.
  • Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst.
  • Ability to obtain and maintain a Public Trust clearance.

Education Requirements:
  • Master of Science degree in IT, Information Security, or related field.
group id: 10106647
Find Eliassen Group on Social Media
Recruiters
user avatar
About Us
Eliassen is the go-to partner for human-powered solutions for those seeking to push the limits of what’s possible. We enable organizations to stretch beyond their capacity and capability and confidently advance the mission critical – while positively impacting the lives of our employees, clients, consultants, and the communities in which we operate.

Eliassen Group Jobs


Job Category
IT - Security
Clearance Level
Public Trust