Cybersecurity Incident Response Lead
Alexandria, VA
Category: Security
Industry: Government
Reference ID: JN -082026-108227
Date Posted: 08/10/2026
Shortcut: http://careers.eliassen.com/QcGmdP
Description:
Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA
Our client seeks a seasoned leader to direct enterprise cybersecurity incident response and offensive security initiatives. The role will manage CSIRT operations across infrastructure, applications, systems, and cloud, maintain and test incident response plans, and drive continuous improvement through metrics, exercises, and integrated vulnerability management. The position will also lead penetration testing and adversary emulation programs, align procedures with federal and organizational requirements, and deliver executive-ready reporting and remediation guidance.
Due to federal security clearance requirements, applicant must be a United States Citizen with ability to obtain Public Trust clearance. This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $75.00 to $80.00/hr. w2
Responsibilities:
- Lead and coordinate enterprise cybersecurity incident response activities in support of the Cybersecurity Incident Response Team (CSIRT).
- Manage incident response operations for cybersecurity events affecting enterprise infrastructure, applications, systems, and cloud environments.
- Review, maintain, and update the Enterprise Incident Response Plan and supporting Standard Operating Procedures (SOPs) to ensure alignment with federal and organizational requirements.
- Direct incident response efforts including triage, containment, eradication, recovery, and post-incident remediation activities.
- Coordinate with internal stakeholders, third-party vendors, security teams, and leadership during cybersecurity incidents to ensure effective communication and response execution.
- Conduct annual incident response exercises, tabletop events, and testing activities to validate operational readiness and improve response capabilities.
- Perform incident information gathering, analysis, distribution, and stakeholder notification activities in accordance with established response procedures and reporting timelines.
- Develop and publish incident reports, executive summaries, after-action reports, lessons learned, and remediation recommendations following cybersecurity events.
- Lead penetration testing, red team, purple team, adversary emulation, and breach-and-attack simulation activities to assess and improve the organization’s security posture.
- Develop and maintain penetration testing concepts of operations, rules of engagement, test plans, and standard operating procedures.
- Coordinate penetration testing activities including onboarding, active assessments, vulnerability validation, findings analysis, remediation tracking, and patch verification.
- Integrate incident response and penetration testing activities with vulnerability management, threat modeling, continuous monitoring, event detection, and compliance reporting processes.
- Track and report incident response and penetration testing metrics, trends, findings, and remediation activities to cybersecurity leadership and stakeholders.
- Support continuous improvement of incident management, threat detection, and cyber defense capabilities through collaboration with security operations, engineering, and compliance teams.
Experience Requirements:
- US Citizenship required.
- 10+ years in incident response, security operations, or penetration testing.
- 5+ years managing incident response teams.
- Strong knowledge of malware analysis, forensics, threat intelligence, and adversary TTPs.
- Certifications: CEH, EC-Council Licensed Penetration Tester, EC-Council Certified Security Analyst.
- Ability to obtain and maintain a Public Trust clearance.
Education Requirements:
- Master of Science degree in IT, Information Security, or related field.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact fraud@eliassen.com.
-
Penetration Tester
Alexandria, VA
Description: Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA Our client seeks an experienced penetration testing professional to plan and execute comprehensive security assessme...
Date Posted: 08/11/2026 Recommended
-
Cybersecurity Operations Lead
Alexandria, VA
Description: Hybrid Hybrid, 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site in Alexandria, VA Our client seeks a Cybersecurity Operations Lead to provide hands-on technical leadership across cybersecurit...
Date Posted: 08/09/2026 Recommended
-
Cybersecurity Audit Manager
Alexandria, VA
Description: Hybrid 2-3 days per week on-site in Alexandria, VA. The first 30 days of work will be full-time on-site. in Alexandria, VA Our client seeks a cybersecurity audit management professional to drive compliance with federal regulations and info...
Date Posted: 08/10/2026 Recommended
-
Senior Software Engineer
Los Angeles, CA
Description: Hybrid: Fully Remote until West LA office opens - then 3x a week onsite in Los Angeles, CA Our client seeks a Senior Software Engineer to build scalable, secure, and resilient platform services. You will design backend services and APIs, e...
Date Posted: 08/11/2026 Recommended
-
Systems Administrator – Enterprise IT Operations
Frisco, TX
Description: On-site 5 days/week in Frisco, TX Our client seeks a Systems Administrator to support, secure, and optimize enterprise IT operations. The role focuses on end-user support and endpoint deployment across Mac, Windows, and Linux, with respons...
Date Posted: 07/20/2026 Recommended
-
Systems Administrator – Enterprise IT Operations
San Diego, CA
Description: On-site in San Diego, CA Our client seeks a Systems Administrator to support, secure, and optimize enterprise IT operations. The role includes end-user system support and endpoint deployment for a modern, scalable, and secure environment. ...
Date Posted: 07/20/2026 Recommended
-
Cyber Digital Forensics Analyst
Orange County, CA
Description: On-site in Orange County, CA Our client seeks a Cyber Digital Forensics Analyst to support a 24x7x365 Security Operations Center. The analyst will conduct digital media forensics, contribute to incident response, maintain and enhance the S...
Date Posted: 07/21/2026 Recommended
-
Senior Exchange Administrator
Quantico, VA
Description: On-site in Quantico, VA Our client seeks a Senior Exchange Administrator to support a large-scale hybrid Microsoft Exchange 2019 and Microsoft 365 environment serving over 260,000 users across classified and unclassified networks. The role...
Date Posted: 08/04/2026 Recommended
-
Email Cyber Security Engineer
Rockville, MD
Description: Hybrid 3 days onsite / 2 days remote in either Rockville, MD or Tysons Corner, VA Our client seeks a Security Engineer responsible for designing, implementing, and maintaining controls that protect enterprise systems and data from unauthor...
Date Posted: 07/28/2026 Recommended
-
Cloud Database Reliability Engineer
St. Louis, MO
Description: Hybrid 2-3 days in office/week in St. Louis, MO Our client seeks a Cloud Database Reliability Engineer to design, build, and evolve automated database infrastructure for a cloud-native enterprise platform supporting mission-critical applic...
Date Posted: 07/16/2026 Recommended
-
Systems Administrator – Enterprise IT Operations
Arlington, VA
Description: On-site in Arlington, VA Our client seeks a Systems Administrator to support, secure, and optimize enterprise IT operations. The role covers end-user system support and endpoint deployment across Mac, Windows, and Linux. The administrator ...
Date Posted: 07/20/2026 Recommended
-
SailPoint Senior Systems Engineer
Washington, DC
Description: On-site in Washington, DC Our client seeks a SailPoint Senior Systems Engineer to enhance cybersecurity and identity management capabilities. The role will coordinate with external stakeholders, including DHS CISA integrators, to implement...
Date Posted: 08/04/2026 Recommended
-
Mid Systems Engineer, CyberArk
Washington, DC
Description: Onsite in Washington, DC Our client seeks a Mid Systems Engineer, CyberArk, to support a Privileged Access Management program for a federal environment. The role will assist senior engineers with CyberArk deployment, operations, reporting,...
Date Posted: 08/10/2026 Recommended
-
Lead Support Analyst
Anywhere
Description: Remote Our client seeks a Lead Support Analyst to oversee support, stability, and performance of mission-critical scheduling applications across global media operations. The role leads a team of Application Support Analysts, coordinates cr...
Date Posted: 08/06/2026 Recommended
-
Information Technology Risk & Controls Audit Manager
San Francisco, CA
Description: Hybrid in San Francisco, CA Our client is seeking an experienced IT Risk & Controls Audit Manager to lead audit, risk, and compliance initiatives within a dynamic environment. The role will evaluate technology and business controls, manage...
Date Posted: 07/29/2026 Recommended
-
Project Manager
Cleveland, OH
Description: On-site 5 days/week in Cleveland, OH Our client seeks an experienced Project Manager to lead a high-priority Oracle security remediation initiative addressing audit findings and control exceptions. The PM will coordinate SMEs across Oracle...
Date Posted: 07/30/2026 Recommended
-
Active Directory Administrator IV
Quantico, VA
Description: On-site in Quantico, VA Our client seeks an experienced Active Directory Administrator IV to support a large-scale enterprise environment with over 265,000 user accounts and 140,000 computer accounts across multiple Active Directory domain...
Date Posted: 08/04/2026 Recommended
-
Senior Oracle Fusion GL Security & Technical Consultant
Dallas, TX
Description: On-site in Dallas, TX Our client seeks a hands-on senior Oracle Fusion GL Security and Technical Consultant to stabilize the Oracle security model, correct role and user-assignment issues, resolve production and hypercare tickets, and help...
Date Posted: 08/06/2026 Recommended
-
Senior Full Stack React.js / Node.js Developer
Greenwood Village, CO
Description: On-site in Greenwood Village, CO Our client seeks a Senior Full Stack React.js / Node.js Developer for a long-term contract on the internal build and tools team. You will contribute core features across multiple web applications that serve...
Date Posted: 07/16/2026 Recommended
-
Agentic AI Architect
Alpharetta, GA
Description: Hybrid 3 days/week onsite, 2 days/week remote in Atlanta, GA Our client is seeking an experienced Agentic AI Architect to design and build an AI-powered software testing framework. The role will contribute to architecture, design, and impl...
Date Posted: 07/20/2026 Recommended
-
PACS Admin
Charlotte, NC
Description: Hybrid 3 on in Charlotte, NC Our client is seeking a PACS Administrator to administer and support enterprise physical access control systems that protect people, facilities, and assets. The role focuses on AMAG Symmetry and comparable PACS...
Date Posted: 08/03/2026 Recommended
-
Lead Agilist
Farmington Hills, MI
Description: On-site in Farmington Hills, MI Our client seeks a Lead Agilist to support an Agentic AI engineering team. The role will coach and facilitate Agile Squad practices, foster servant leadership, and partner with Product Owners and developers ...
Date Posted: 07/31/2026 Recommended
-
Software Test Engineer
San Diego, CA
Description: Hybrid in San Diego, CA Our client seeks a Software Test Engineer to lead and execute advanced software testing for web applications and instrument systems with a focus on C# and TypeScript solutions. The role includes designing and implem...
Date Posted: 08/10/2026 Recommended
-
Senior Software Engineer
Pittsburgh, PA
Description: Hybrid 4 days onsite in Pittsburgh, PA Our client seeks a Senior Software Engineer to build a secure, fault-tolerant Azure-based platform for high-volume data ingestion, ledger-style recordkeeping, and analytics for a small internal user b...
Date Posted: 07/20/2026 Recommended
-
Senior Software Developer
St. Louis, MO
Description: Hybrid 2-3 days on-site in St. Louis, MO Our client seeks a Senior Software Developer to support modernization and maintenance of a mission-critical enterprise application in AWS for the U.S. Treasury. The role requires full-stack developm...
Date Posted: 07/31/2026 Recommended
-
Lead Software Engineer
Boston, MA
Description: Hybrid at least 2 days per week in office in Wakefield, MA Our client seeks a Lead Software Engineer for the CDP team to drive design, delivery, technical strategy, and execution for critical data systems. You will define engineering stand...
Date Posted: 08/10/2026 Recommended
-
Sr. DevSecOps Engineer I
Washington, DC
Description: On-site in Washington, DC Our client seeks a Sr. DevSecOps Engineer I to design, implement, and maintain secure and efficient software development and deployment pipelines. The role collaborates with cross-functional teams to integrate sec...
Date Posted: 08/10/2026 Recommended
-
Lead Software Engineer
Chicago, IL
Description: Hybrid At least 2 days per week in office in Chicago, IL Our client seeks a Lead Software Engineer to drive the design, delivery, and technical strategy for cloud-native data platforms within a Customer Data Platform team. The role will de...
Date Posted: 08/10/2026 Recommended
-
Infrastructure Project Manager
Anywhere
Description: Remote Our client is seeking an Infrastructure Project Manager to support the information security function and broader infrastructure initiatives. The role will partner with stakeholders across business and technology to define scope, man...
Date Posted: 07/22/2026 Recommended
-
Full Stack Software Engineer
Anywhere
Description: Remote Our client is seeking a Full Stack Software Engineer to join the U.S.-based Enterprise Services engineering team focused on sustaining, enhancing, and modernizing business-critical enterprise applications. The role rotates across pr...
Date Posted: 08/11/2026 Recommended
Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.
Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.
Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group
If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contact fraud@eliassen.com.
Please ensure that you are working directly with us by confirming the following:
- When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
- Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above