Incident Response Lead

Leidos

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Washington, DCAshburn, VA
Salary
$107,900–$195,050 / yr
Employment
Full-time
Posted
37 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $180k
This role $151k
$94k most similar roles pay here $233k

This role pays less than 75% of similar roles. Most pay $151,700–$208,850 — the shaded band above. At the midpoint, this role pays about $151k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 340 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 294 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Incident Response Lead

The Incident Response Lead joins the Digital Modernization Sector to support a high-visibility cybersecurity program providing security operations center services and cyber analysis. This role involves managing the incident response lifecycle, identifying suspicious activity based on attacker TTPs, and performing logical analysis to determine root causes of incidents. The individual will drive the implementation of new tools, automation, and process efficiencies while mentoring analysts to ensure high-quality work products. Key technical requirements include expertise in Windows and Linux operating systems, enterprise network architectures including routing, switching, and protocols like DNS and HTTP, and familiarity with the Cyber Kill Chain and ATT&CK Framework. The role requires a deep understanding of SOC operations and incident handling within a complex enterprise environment to mitigate cyber threats and adversarial activity across various infrastructure components.

What you'll do

  • Lead and manage Computer Incident Response Team (CIRT) and Security Operations Center (SOC) operations for a large enterprise.
  • Manage, mentor, and supervise analysts of various technical skill levels to ensure high-quality work products.
  • Identify suspicious activity and perform logical analysis to determine the root cause and scope of incidents.
  • Drive the implementation of new tools, capabilities, frameworks, and automation to improve process efficiencies.
  • Enforce industry best practices in incident response, cybersecurity analysis, case management, and SOC operations.
  • Create technical reports based on analytical findings for stakeholders and customers.
  • Coordinate detection and response activities across multiple components using shared tracking systems.

What we're looking for

  • Must be a US Citizen.
  • Must hold an active TS/SCI security clearance.
  • Bachelor's Degree and 8-12 years of experience in a technical discipline.
  • 4+ years of supervising and/or managing teams.
  • 5+ years of intrusion detection and/or incident handling experience.
  • CISSP and SANS GCIH or GCIA certifications required upon start.
  • Advanced knowledge in planning, directing, and managing CIRT and SOC operations for a large enterprise.
  • Deep technical understanding of core current cybersecurity technologies and emerging capabilities (preferred).

More like this

Similar roles

Senior Incident Response Analyst

Leidos

Arlington, VA 11 days ago $131,300–$237,350
Incident Response EDR IDS SIEM Python PowerShell Bash Windows Linux Malware Analysis Computer Forensics Cyber Kill Chain Firewalls Proxies Load Balancers VPN Case Management Systems
10+ yrs exp

Senior Incident Response Analyst

Booz Allen Hamilton

Bethesda, MD 20 days ago
Splunk SIEM EDR IDS IPS SOAR Microsoft Defender Packet Analysis Malware Triage Digital Forensics Threat Hunting Behavioral Analytics Threat Intelligence Vulnerability Management Firewalls Identity and Access Management Container Security API Security
5+ yrs exp

Incident Response Analyst, Mid

Booz Allen Hamilton

Bethesda, MD 28 days ago
Splunk SIEM EDR IDS/IPS SOAR Digital Forensics Packet Analysis Malware Triage Threat Hunting Behavioral Analytics Threat Intelligence Identity and Access Management Container Security API Security Vulnerability Management Firewalls Log Analysis
2+ yrs exp

Security Engineer, Incident Response

F5 Inc

Remote 27 days ago $132,000–$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Defensive Cyber Operations Analyst

Leidos

Washington, DC 51 days ago $87,100–$157,450
Cyber Network Defense Security Operations Center (SOC) SIEM Splunk Elastic IDS/IPS Firewalls PCAP Cyber Kill Chain Data Correlation Technical Writing
2+ yrs exp Hybrid

Lead, Incident Response

Salesforce

Remote (Mclean, VA) 27 days ago
Incident Response SOAR Detection-as-Code AWS Azure GCP CI/CD Network Forensics Malware Analysis Detection Engineering MITRE ATT&CK Linux Windows macOS Security Orchestration
8+ yrs exp Remote