Incident Response Engineer Journeyman

Arlington, VA, US • Posted 1 day ago • Updated 5 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • Continuous Improvement
  • Network
  • Cloud Security
  • Network Forensics
  • ROOT
  • Standard Operating Procedure
  • Threat Analysis
  • Analytics
  • Enterprise Networks
  • Collaboration
  • Cyber Security
  • Information Technology
  • Computer Science
  • Security Operations
  • Recovery
  • Network Security
  • Log Analysis
  • Malware Analysis
  • Reporting
  • SIEM
  • Splunk
  • IBM QRadar
  • GCIA
  • GCFA
  • GCIH
  • Forensics
  • Incident Management
  • Research
  • Security Clearance
  • Application Service Management
  • Oracle ASM
  • Management
  • Recruiting
  • Training
  • Office Administration
  • Inventory

Summary

The Incident Response Engineer Journeyman is a mid-level cybersecurity professional responsible for detecting, investigating, and remediating security incidents affecting mission-critical systems in a highly regulated government environment. This role analyzes security alerts, leads triage activities, and coordinates containment and recovery actions with operations, IT, and mission stakeholders. The engineer also contributes to threat hunting, maintains incident response playbooks and tooling, and produces clear reports and metrics to drive continuous improvement of security operations.

Key Responsibilities
  • Perform initial detection, triage, and validation of security events from SIEM, endpoint, network, and cloud security tools to distinguish true incidents from false positives and prioritize response.
  • Lead or support containment, eradication, and recovery efforts for cybersecurity incidents, coordinating with system owners and operations teams to minimize impact on mission-critical systems.
  • Conduct host and network forensics, log analysis, and malware analysis to determine root cause, attack path, and data exposure, preserving evidence as needed.
  • Maintain and enhance incident response runbooks, playbooks, and standard operating procedures that align with organizational policies, regulatory frameworks, and evolving threat landscapes.
  • Participate in proactive threat hunting using security telemetry, threat intelligence, and behavioral analytics to identify stealthy or emerging threats in enterprise networks.
  • Configure, tune, and maintain incident response tooling and SIEM rules to improve detection fidelity, reduce noise, and enhance visibility across regulated environments.
  • Produce clear incident reports, metrics, and post-incident reviews documenting timeline, impact, corrective actions, and recommendations for control improvements.
  • Collaborate with security training and awareness functions to support tabletop exercises, incident simulations, and communications that reinforce response readiness.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent relevant experience.
  • Typically 5-7 years of experience in security operations and incident response with hands-on exposure to forensics and SIEM in government or similarly regulated environments.
  • Demonstrated experience triaging security alerts, conducting incident investigations, and supporting containment and recovery activities.
  • Hands-on experience with SIEM platforms and endpoint or network security tools used for incident detection and response.
  • Proven ability to perform log analysis, basic malware analysis, and evidence preservation to support reporting and potential regulatory needs.
  • Active TS/SCI security clearance
  • U.S. citizenship, as required to support a federal IT environment.

Preferred Qualifications
  • Experience with leading SIEM and incident response tools such as Splunk, Elastic, QRadar, or similar platforms.
  • Industry certifications such as GCIA, GCFA, GCIH, or equivalent incident response/forensics credentials.
  • Experience handling data spills or incidents involving sensitive or classified information under formal response frameworks.
  • Background participating in threat hunting operations and developing or refining incident response playbooks.

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10184228
  • Position Id: a79acdeb0bfd265ff5c6c4a51eaf26da
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Arlington, Virginia

Today

Full-time

USD 78,600.00 - 160,200.00 per year

Arlington, Virginia

Today

Full-time

USD 53,900.00 - 120,100.00 per year

Hybrid in Bethesda, Maryland

7d ago

Easy Apply

Full-time

$120000

Washington, District of Columbia

Today

Full-time

USD 140,000.00 - 150,000.00 per year

Search all similar jobs