Cybersecurity Incident Response and Penetration Testing Lead

Alexandria, VA


Apply Save

Type: Contract-to-Hire

Category: Security

Industry: Government

Reference ID: JN -082026-108227

Date Posted: 08/10/2026

Shortcut: http://careers.eliassen.com/Dx6Ecu


Description:

Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA

 

Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.

 

Due to federal security clearance requirements, applicant must be a United States Citizen or Permanent Resident with an active Public Trust clearance. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

 

Rate: $75.00 to $80.00/hr. w2


Responsibilities:
  • Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
  • Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
  • Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
  • Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
  • Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
  • Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
  • Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
  • Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
  • Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization’s security posture.
  • Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
  • Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
  • Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
  • Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
  • Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.

Experience Requirements:
  • US Citizenship required.
  • 10+ years in incident response, security operations, or penetration testing.
  • 5+ years managing incident response teams.
  • Strong knowledge of malware analysis, digital forensics, threat intelligence, and adversary TTPs.
  • Certifications: CEH, EC-Council Licensed Penetration Tester, and EC-Council Certified Security Analyst.
  • Ability to obtain and maintain a Public Trust clearance.

Education Requirements:
  • Master of Science degree in IT, Information Security, or related field.

Recruitment Transparency Notice
 
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (noreply@eliassen.com, 781-808-2924) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
 

Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.

If you have any indication of fraudulent activity, please contact fraud@eliassen.com.

 
About Eliassen Group:
 
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
 
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
 
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
 

  • Senior Security Engineer

    Los Angeles, CA

    Description: Hybrid Fully Remote until West LA office opens - then 3x a week onsite in Los Angeles, CA Our client is seeking an experienced Senior Security Engineer with a focus on security architecture assessments across on-premises and Azure environm...

    Date Posted: 08/20/2026 Recommended

  • Cybersecurity Operations Lead

    Alexandria, VA

    Description: Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site in Alexandria, VA in Alexandria, VA Our client seeks a Cybersecurity Operations Lead to provide hands-on technical leadership across c...

    Date Posted: 08/09/2026 Recommended

  • Sr. Security Engineer (Trellix)

    Washington dc, DC

    Description: On-site in Washington, DC As a Sr. Security Engineer (Trellix), you will serve as the technical lead for our client's endpoint security and data protection ecosystem. You will balance day-to-day operational support with strategic cybersecu...

    Date Posted: 08/25/2026 Recommended

  • Digital Forensics Specialist

    Alexandria, VA

    Description: Hybrid 2-3 days per week on-site in Alexandria, VA. Our client seeks a digital forensics specialist to conduct network and media investigations that support incident response, threat analysis, and enterprise security operations. The role w...

    Date Posted: 08/30/2026 Recommended

  • Senior Software Engineer

    Los Angeles, CA

    Description: Hybrid: Fully Remote until West LA office opens - then 3x a week onsite in Los Angeles, CA Our client seeks a Senior Software Engineer to build scalable, secure, and resilient platform services. You will design backend services and APIs, e...

    Date Posted: 08/11/2026 Recommended

  • Full Stack Software Engineer - API Platform Engineering

    Greenwood Village, CO

    Description: Hybrid 4 days onsite, 1 remote in Greenwood Village, CO Our client seeks a Full Stack Software Engineer to build and operate a modern API platform. The team treats APIs as products with clear contracts, observability, documentation, and ow...

    Date Posted: 08/24/2026 Recommended

  • Senior Cybersecurity GRC Analyst

    King of Prussia, PA

    Description: On-site in either King of Prussia, PA or Denver, PA Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within...

    Date Posted: 08/06/2026 Recommended

  • Microsoft Dynamics CRM Administrator/Developer

    St. Louis, MO

    Description: Hybrid in St. Louis, MO Our client seeks a Microsoft Dynamics CRM Administrator/Developer to lead technical implementation and serve as system administrator for selected CRM instances. The role will architect, implement, and support Micros...

    Date Posted: 08/08/2026 Recommended

  • Senior Software Engineer

    Concord, CA

    Description: Hybrid 3 days onsite in either Concord, CA or Charlotte, NC or Dallas, TX Our client is seeking a Sr Software Engineer to support, enhance, and modernize its enterprise Kafka streaming platforms. This role combines technical expertise with...

    Date Posted: 08/21/2026 Recommended

  • ETL DataStage Consultant

    Culver City, CA

    Description: Hybrid 4 days onsite in Culver City, CA Our client seeks an ETL DataStage Consultant to deliver development, administration, production support, and maintenance across data integration platforms. The consultant will implement and optimize ...

    Date Posted: 08/27/2026 Recommended

  • Lead Software Engineer

    Los Angeles, CA

    Description: Hybrid Fully Remote until West LA office opens - then 3x a week onsite in Los Angeles, CA Our client is seeking a highly skilled and motivated Lead Software Engineer to join their BaaS team, supporting partner onboarding and BaaS platform ...

    Date Posted: 08/20/2026 Recommended

  • Principal Software Engineer

    Los Angeles, CA

    Description: On-site in Los Angeles, CA Our client seeks a Principal Software Engineer to lead backend services and APIs for a payment processing platform supporting prominent technology partners. The role will drive technical leadership across release...

    Date Posted: 08/08/2026 Recommended

  • Senior Exchange Administrator

    Quantico, VA

    Description: On-site in Quantico, VA Our client seeks a Senior Exchange Administrator to support a large-scale hybrid Microsoft Exchange 2019 and Microsoft 365 environment serving over 260,000 users across classified and unclassified networks. The role...

    Date Posted: 08/04/2026 Recommended

  • Client Risk Analyst

    Anywhere

    Description: Remote The Client Risk Analyst serves as a critical liaison between clients, sales teams, product teams, and information security stakeholders to evaluate client control requirements, assess risk implications, and provide defensible, compl...

    Date Posted: 08/26/2026 Recommended

  • SharePoint Migration Engineer

    Pittsburgh, PA

    Description: Hybrid 4 days onsite in either Pittsburgh, PA or Lake Mary, FL Our client seeks a SharePoint Migration Engineer to lead strategy and execution for a large-scale Microsoft 365 migration. The role will analyze legacy collaboration platforms,...

    Date Posted: 08/12/2026 Recommended

  • Business Continuity Analyst

    Anywhere

    Description: Remote Our client seeks a Business Continuity Analyst to modernize Business Continuity and Operational Resilience. The role will leverage existing continuity plans, recovery documentation, vendor data, policies, and operational knowledge t...

    Date Posted: 08/26/2026 Recommended

  • Service Team Specialist

    Boston, MA

    Description: On-site in Boston, MA Our client seeks a Service Team professional who will resolve customer requests and incidents with high standards of technical quality and customer service. The role will also support projects that address emerging te...

    Date Posted: 08/09/2026 Recommended

  • AI Scanning Product Owner

    Anywhere

    Description: Remote Our client seeks a Senior Product Owner to define, prioritize, and drive the roadmap for an AI-driven code vulnerability detection and reporting capability. The product leverages large language models and automation to identify pote...

    Date Posted: 08/26/2026 Recommended

  • IT Compliance - Manager/Director

    Waltham, MA

    Description: Hybrid 3-4 days onsite in Waltham, MA Our client is a clinical-stage biotechnology company seeking an IT Compliance and Controls Consultant to strengthen governance, documentation, and audit readiness across key systems. The role will part...

    Date Posted: 08/30/2026 Recommended

  • Lead Support Analyst

    Anywhere

    Description: Remote Our client seeks a Lead Support Analyst to oversee support, stability, and performance of mission-critical scheduling applications across global media operations. The role leads a team of Application Support Analysts, coordinates cr...

    Date Posted: 08/06/2026 Recommended

  • Sr. MuleSoft Platform Developer

    Anywhere

    Description: Remote Our client is seeking an experienced Senior MuleSoft Engineer to join the integration platform team. This is a hands-on, technical role serving as the platform owner for a MuleSoft portfolio, driving technical delivery and moderniza...

    Date Posted: 08/25/2026 Recommended

  • Information Technology Risk & Controls Audit Manager

    San Francisco, CA

    Description: Hybrid in San Francisco, CA Our client is seeking an experienced IT Risk & Controls Audit Manager to lead audit, risk, and compliance initiatives within a dynamic environment. The role will evaluate technology and business controls, manage...

    Date Posted: 08/28/2026 Recommended

  • Project Manager

    Cleveland, OH

    Description: On-site 5 days/week in Cleveland, OH Our client seeks an experienced Project Manager to lead a high-priority Oracle security remediation initiative addressing audit findings and control exceptions. The PM will coordinate SMEs across Oracle...

    Date Posted: 08/29/2026 Recommended

  • Senior Oracle Fusion GL Security & Technical Consultant

    Dallas, TX

    Description: On-site in Dallas, TX Our client seeks a hands-on senior Oracle Fusion GL Security and Technical Consultant to stabilize the Oracle security model, correct role and user-assignment issues, resolve production and hypercare tickets, and help...

    Date Posted: 08/06/2026 Recommended

  • Cloud Operations Engineer

    Anywhere

    Description: Remote Our client seeks a Cloud Operations Engineer to manage and execute cloud infrastructure, application, and data rehydration activities across Azure and AWS. The role supports business continuity, enterprise security standards, disast...

    Date Posted: 09/01/2026 Recommended

  • DAT Senior Associate

    Anywhere

    Description: Remote in San Francisco, CA Our client seeks a DAT Senior Associate who will work directly with clients and engagement teams to assess the design and operating effectiveness of controls related to financial reporting, compliance, and infor...

    Date Posted: 08/17/2026 Recommended

  • Workday Security Architect SME (Workday HCM)

    Anywhere

    Description: Remote Our client seeks a Workday Security Architect Consultant to assess a mature Workday HCM security environment, identify gaps and best-practice opportunities, and deliver actionable recommendations for a future-state security model. T...

    Date Posted: 08/23/2026 Recommended

  • Applications Developer/Analyst

    Anaheim, CA

    Description: On-site in Anaheim, CA Our client seeks an Applications Developer/Analyst to support and enhance enterprise business applications in a municipal IT environment. The role includes application development, maintenance, upgrades, troubleshoot...

    Date Posted: 08/12/2026 Recommended

  • Computer Systems Analyst

    Woodlawn, MD

    Description: Hybrid 1 day per month (1st Monday of each mo) in Woodlawn, MD Transform technology into opportunity as a Systems Analyst for our client. A career in enterprise IT means connecting and enhancing the systems that matter most. You will help ...

    Date Posted: 08/30/2026 Recommended

  • Change Management Senior Consultant

    Charlotte, NC

    Description: Hybrid 2 Days onsite in Charlotte, NC Our client seeks a Senior Change Management Consultant to support change efforts tied to acquisitions and technology integrations. The role partners with M&A teams, IT, business leaders, and security t...

    Date Posted: 08/20/2026 Recommended

Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.


Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.

Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group

If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contact fraud@eliassen.com.

Please ensure that you are working directly with us by confirming the following:

  • When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
  • Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above