Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Interim Secret
Clearance Level Must Be Able to Obtain:
Top Secret/SCI
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Cyber Incident Response, Monitoring Tools, Network Forensics
Certifications:
None
Experience:
5 + years of related experience
US Citizenship Required:
Yes
Job Description:
Position Summary
The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high-value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on-site operations, collaborating with hunt and intelligence teams, and surging during high-tempo events.
Key Responsibilities
Incident Response Execution
• Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent.
• Drive containment, eradication, and recovery with affected entities and the command center.
• Build and maintain evidence-based incident timelines.
• Determine and document root cause when evidence supports it.
Deployed & Remote Engagement Support
• Support on-site incident response, including travel as needed.
• Conduct remote engagements when deployment is not required or feasible.
• Operate within available monitoring and tooling, clearly noting visibility limitations.
• Work directly with affected technical staff, translating findings into actionable steps.
Technical Analysis
• Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement.
• Use outputs from commercial detection and monitoring tools in environments outside organizational control.
• Triage suspicious files and artifacts; escalate items requiring deeper analysis.
• Document indicators of compromise and share with intelligence and hunt teams.
Coordination Across Mission Functions & Agencies
• Maintain accurate incident status and ensure required notifications.
• Collaborate with hunt teams to align response findings with hunt operations.
• Work with intelligence teams to enrich findings and support broader threat understanding.
• Coordinate with external responders such as federal law enforcement, National Guard, and state teams.
Documentation, Reporting & After-Action
• Produce technical documentation, findings, and actionable reports meeting customer standards.
• Support case file completion aligned with NCISS requirements.
• Ensure rationale for response actions is preserved.
• Contribute to after-action reviews and procedural improvements.
Surge Readiness
• Maintain readiness to deploy or surge on short notice for major cyber events.
• Support crisis action team operations during elevated tempo.
• Stay current on tools, tradecraft, and mission-relevant environments.
Required Qualifications
• Hands-on enterprise incident response experience, including scoping, containment, eradication, and recovery.
• Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity.
• Experience using commercial detection and monitoring tools in external environments.
• Experience producing technical incident documentation for external stakeholders.
• Ability to work directly with affected organizations during active incidents.
• Willingness and ability to travel and support surge operations.
• Relevant technical training, certification, or degree, plus 5 years of experience.
• Active Top Secret clearance.
Preferred Qualifications
• National-level incident response experience.
• Experience with ICS/OT or critical infrastructure environments.
• Experience coordinating multi-agency or multi-jurisdictional response.
• Malware triage and basic reverse engineering skills.
• Experience with flyaway kits or deployable response tooling.
• Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.
The likely salary range for this position is $131,750 - $178,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
25-50%
Telecommuting Options:
Hybrid
Work Location:
USA VA Arlington
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.