Incident Response Team Lead

Agile Defense
United States
Workplace: HybridFull timeFunction: Administration & Executive AssistanceExperience: 5+ yearsEducation: bachelorsSkills: ["Communication","Teamwork","Problem-solving"]

Lead the Cyber Incident Response Team in a 24/7 SOC, overseeing investigations, forensics, and countermeasures across host, cloud, and network environments for USG customers, ensuring incident lifecycle management, playbooks, communications, and metrics improvements.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Agile Defense
Agile Defense
6 months ago

Incident Response Team Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 hours agoStatus: Live

Job Summary

Lead the Cyber Incident Response Team in a 24/7 SOC, overseeing investigations, forensics, and countermeasures across host, cloud, and network environments for USG customers, ensuring incident lifecycle management, playbooks, communications, and metrics improvements.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Sr. Manager level

Key Responsibilities

  • •Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions.
  • •Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation.
  • •Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.

Key Requirements

  • •CISSP required; active certification
  • •One or more of: GCIA, GCIH, GCFA, GCED, or IAT Level III per DoD 8570.1
  • •Five (5) years of progressive professional experience in incident response, SOC analyst, or digital forensics
  • •Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security (or eight years of relevant work experience in lieu of a degree)
  • •Proficient use of cyber tools: SIEM, network analysis, live response, endpoint detection and response tools, IPS/IDS, CSOC ticketing platforms
Experience:5+ yearsCybersecurityIncident responseSOCDigital forensicsCSOC
Education:Bachelor's
Skills:CommunicationTeamworkProblem-solving
Certifications:CISSPGCIAGCIHGCFAGCEDIAT Level III
Tech Stack:SIEMEDRIPSIDSCSOC ticketingCloud environments

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.
Security Clearance:TS

Company Brief

Agile Defense
Provides cybersecurity services including managed detection and response, incident response, vulnerability assessments, and security operations to help organizations detect, respond to, and remediate cyber threats while meeting regulatory and compliance requirements.
Industry: Cybersecurity
Website