Skip to content
Location Arlington, VA Job type Full-time

Job Description:
The position of Incident Manager is vital to the smooth and reliable functioning of operations. As the Incident Manager, you will coordinate and lead the response to critical incidents that may affect government agencies and asset owners targeted by cyber-attacks. Your primary duties include conducting immediate investigations to evaluate the extent of the breach, devising plans to mitigate the issue, and providing assistance in recovering services. Your ultimate objective is to resolve the problem as quickly as possible, minimize any disruption, and prevent similar incidents from happening in the future. Your role is of utmost importance in ensuring the security of the organization’s assets and maintaining its reputation.


  • Researching and compiling known steps to mitigate potential Computer Network Defense incidents within the enterprise.
  • Identifying and validating threats by applying knowledge of various threat actors’ tactics, techniques, and procedures, including criminal, insider, hacktivist, and nation-state.
  • Conducting cursory log data analysis and using cybersecurity concepts to detect and defend against intrusions into small and large-scale IT networks.
  • Monitoring external data sources (e.g., Computer Network Defense vendor sites, Computer Emergency Response Teams [CERTs], SANS, Security Focus) to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise
  • Identifying the cause of an incident and recognizing the key elements to ask external entities when learning the background and potential infection vector of an incident
  • Receiving and analyzing network alerts from various sources within the enterprise and determining possible causes of such alerts
  • Tracking and documenting Computer Network Defense (CND) incidents from initial detection through final resolution
  • Working with other components within the organization to obtain and coordinate information on ongoing incidents

Incident Manager III – 7+ years of experience

Incident Manager II – 4-6 years of experience

Required Skills:

  • US Citizenship
  • Must have an active TS/SCI clearance and be able to obtain DHS Suitability
  • Directly relevant experience in cyber incident management or cybersecurity operations
  • Knowledge of incident response and handling methodologies
  • Knowledge of the NCCIC National Cyber Incident Scoring System
  • Understanding general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.)

Required Education:
BS Incident Management, Operations Management, Cybersecurity or related degree. HS Diploma with incident management or cyber security experience.