Incident Response / Digital Forensic Lead

Antietam Technologies Inc.

$150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity focusing on incident response and digital forensics.
  • Demonstrated leadership skills in managing cybersecurity operations and teams.
  • Strong technical skills in handling and analyzing digital evidence.
  • Proficiency in Windows and Linux operating systems and security technologies.
  • Excellent communication abilities to convey technical findings to non-technical stakeholders.

Responsibilities

  • Lead daily operations of a cybersecurity incident response team.
  • Conduct technical investigations and forensic analyses on cyber incidents.
  • Coordinate with stakeholders and technical teams during response activities.
  • Prepare briefings and reports for senior federal leadership on incident findings.
  • Mentor team members in investigative and technical standards.

Benefits

  • Hybrid work arrangement with 1-2 days per week onsite.
  • Opportunity to support high-security federal clients.
  • Engagement in hands-on technical work alongside leadership responsibilities.
  • Potential for professional development and certifications in cybersecurity.
Full Job Description

Job description

Incident Response & Digital Forensics Lead

Work arrangement: Hybrid (1-2 days a week onsite)

Location: Germantown, Maryland

Employment type: Full-Time

Clearance requirement: Top Secret/RD

Position Overview

We are seeking an experienced Incident Response & Digital Forensics Lead to manage the day-to-day operations of a cybersecurity response team while remaining actively involved in technical investigations.

This is a hands-on leadership role supporting a federal customer. The successful candidate will lead incident response and digital forensic activities, coordinate directly with customer stakeholders, and translate complex findings into clear briefings and recommendations for senior federal leadership.

The role also provides technical support across cloud security, endpoint security, identity and access management, secure networking, and incident response. The ideal candidate has strong incident handling and forensic investigation experience, combined with the organizational and stakeholder-management skills of a mid-level project or program manager. This position requires some on-site work.

Key Responsibilities

  • Manage the team’s daily operations, priorities, workload, assignments, and deliverables.
  • Lead and participate directly in cyber incident investigations, forensic examinations, analysis, containment, eradication, and recovery activities.
  • Coordinate incident response functions across technical teams, business stakeholders, vendors, and customer leadership.
  • Serve as a primary point of contact for the customer during active incidents and related investigative activities.
  • Prepare and deliver incident briefings, executive summaries, technical findings, status reports, and recommended courses of action to senior federal leadership.
  • Collect, preserve, document, and analyze intrusion artifacts, including malware, malicious code, scripts, executables, logs, system images, and network evidence.
  • Use investigative findings and threat intelligence to support containment, mitigation, remediation, and prevention of cyber defense incidents across the enterprise.
  • Provide expert technical guidance to enterprise cyber defense analysts, engineers, administrators, and technicians working to resolve security incidents.
  • Conduct or oversee forensic acquisition and analysis of endpoints, servers, mobile devices, cloud environments, and other relevant digital evidence.
  • Maintain evidentiary integrity, chain-of-custody records, investigation notes, timelines, and other case documentation.
  • Monitor relevant external information sources, including cybersecurity vendors, government advisories, Computer Emergency Response Teams, information-sharing organizations, and threat-intelligence providers.
  • Assess emerging vulnerabilities, threats, tactics, techniques, and procedures for potential impact on the customer environment.
  • Develop and improve incident response plans, playbooks, escalation procedures, forensic processes, reporting templates, and operational metrics.
  • Coordinate lessons-learned reviews and ensure corrective actions are documented, assigned, and tracked through completion.
  • Support technical cybersecurity activities involving cloud platforms, endpoint protection, identity and access management, network security, logging, and monitoring.
  • Mentor team members and promote consistent investigative, technical, and documentation standards.
  • Support incident response exercises, tabletop exercises, readiness assessments, and after-action reviews.


Required Qualifications

  • Demonstrated professional experience in cybersecurity incident response, incident handling, and digital forensic investigations.
  • Experience leading or coordinating a cybersecurity operations, incident response, or forensic investigation team.
  • Ability and willingness to perform hands-on technical work while managing team operations and customer deliverables.
  • Experience collecting, preserving, analyzing, and documenting digital evidence and intrusion artifacts.
  • Working knowledge of Windows and Linux operating systems, enterprise networks, endpoint technologies, cloud environments, authentication systems, and security logging.
  • Familiarity with common attacker tactics, techniques, and procedures, including the phases of an intrusion and methods used to establish persistence, evade detection, and exfiltrate data.
  • Ability to assess technical evidence, determine incident scope and impact, and recommend appropriate containment and remediation measures.
  • Strong written and verbal communication skills, including the ability to explain complex technical findings to executives and nontechnical stakeholders.
  • Experience preparing formal incident reports, executive briefings, investigation summaries, and corrective-action recommendations.
  • Strong organizational, project-management, and stakeholder-coordination skills.
  • Ability to manage competing priorities and operate calmly and effectively during high-severity incidents.
  • Ability to work on-site at the designated customer location.
  • Ability to satisfy applicable federal customer suitability, background investigation, and clearance requirements.


Preferred Qualifications:

  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Network Forensic Analyst (GNFA)
  • Certified Information Systems Security Professional (CISSP)
  • Hands-on experience with forensic and investigative tools such as Magnet AXIOM, Magnet Graykey, OpenText EnCase, and Cellebrite.
  • Experience performing mobile-device acquisition and forensic analysis.
  • Experience supporting federal agencies or other regulated, high-security environments.
  • Familiarity with NIST incident response guidance and the MITRE ATT&CK framework.
  • Experience with endpoint detection and response, security information and event management, cloud-security, network-analysis, malware-analysis, or threat-intelligence platforms.
  • Experience managing projects, schedules, risks, customer communications, and multidisciplinary technical teams.
  • Knowledge of legal, regulatory, privacy, and evidentiary considerations associated with forensic investigations.


Education and Experience

  • Bachelor’s degree in cybersecurity, computer science, information technology, digital forensics, engineering, or a related field; equivalent relevant experience may be considered.
  • 5+ years of cybersecurity experience, including substantial experience in incident response or digital forensics.
  • Prior technical leadership, team-lead, project-management, or program-coordination experience.


Success in This Role

The successful candidate will be a credible technical investigator, a steady incident leader, and an effective customer-facing communicator. This individual must be comfortable moving between detailed forensic analysis, team coordination, and executive-level reporting—often during time-sensitive and high-impact events.

Additional Information

This role may require participation in an on-call rotation and work outside normal business hours during significant cyber incidents. Any travel, scheduling, citizenship, clearance, or other customer-specific requirements will be communicated during the recruiting process.

Antietam Technologies Inc. is an equal opportunity employer. Employment decisions are made without regard to legally protected characteristics and in accordance with applicable law.

Similar Jobs

More Jobs at Antietam Technologies Inc.

More Information Technology Jobs

Find similar Incident Response / Digital Forensic Lead jobs: