JobTarget Logo

Incident Management Lead in at Crest Security Assurance

NewSalary: $145000 - $155000
Crest Security Assurance
United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Incident Management and Response Lead Position (US Citizenship Required)

Leads enterprise cybersecurity incident management and response operations, overseeing incident detection, investigation, analysis, containment, eradication, and recovery. Directs incident coordination, digital forensics, threat intelligence integration, and response activities to minimize operational impact and strengthen enterprise cyber resilience.

Key Responsibilities

  • Lead enterprise incident response operations, including incident triage, classification, investigation, containment, eradication, recovery, and post-incident analysis.
  • Develop, maintain, and execute Incident Response Plans, CONOPS, SOPs, escalation procedures, and technical playbooks aligned with NIST SP 800-61 and applicable federal requirements.
  • Direct incident investigations using SIEM, SOAR, EDR/XDR, network traffic analysis, endpoint telemetry, and digital forensic tools, including Splunk, Microsoft Defender, Wireshark, Volatility, and approved forensic platforms.
  • Coordinate digital forensics and incident analysis involving malware, compromised endpoints, credential theft, lateral movement, unauthorized access, data exfiltration, and advanced persistent threats.
  • Apply MITRE ATT&CK tactics, techniques, and procedures (TTPs) to investigate adversary activity, reconstruct attack timelines, identify root causes, and determine incident scope and impact.
  • Lead major incident response and crisis management, coordinating SOC analysts, threat hunters, system owners, cybersecurity engineers, Government leadership, and external response organizations.
  • Develop and execute containment and remediation strategies, including endpoint isolation, credential revocation, malicious artifact removal, vulnerability mitigation, and secure restoration of affected systems.
  • Integrate cyber threat intelligence, indicators of compromise (IOCs), threat hunting, and detection engineering to accelerate investigations and prevent recurring incidents.
  • Conduct incident response tabletop exercises, technical simulations, and purple team activities to validate playbooks, escalation procedures, response readiness, and operational effectiveness.
  • Manage incident documentation, evidence preservation, chain of custody, incident tracking, and required federal cybersecurity reporting and notification timelines.
  • Produce incident reports, root cause analyses, after-action reports, executive briefings, and risk-based corrective action recommendations.
  • Establish incident response performance metrics, including MTTD, MTTR, containment effectiveness, and incident trends, to drive continuous operational improvements.

Required Qualifications

  • Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 10+ years of cybersecurity experience, including 5+ years leading enterprise incident response or SOC operations.
  • Demonstrated expertise in digital forensics, malware analysis, threat hunting, incident investigation, and enterprise containment and recovery.
  • Hands-on experience with SIEM, SOAR, EDR/XDR, forensic analysis tools, and MITRE ATT&CK.
  • Proven ability to lead high-severity cyber incidents, coordinate cross-functional response teams, and brief executive leadership.

Preferred Qualifications

  • Experience supporting federal cybersecurity operations in complex enterprise environments.
  • Familiarity with NIST SP 800-61, NIST SP 800-53, FISMA, RMF, and federal incident reporting requirements.
  • Experience with cloud incident response, adversary emulation, incident response automation, and threat intelligence integration.
  • GCIH, GCFA, GCFE, CISSP, or equivalent incident response certification.

Clearance Requirements

Must be a U.S. Citizen; Public Trust or higher clearance required.

Work Environment

Hybrid role based in Alexandria, VA. Initial 30 days onsite, followed by 2–3 days onsite per week.

Job Location

United States

Frequently asked questions about this position

Apply For This Position

Apply Now