Incident Response (IR) Tech Lead

🏢 Edgewater Federal Solutions · all Edgewater Federal Solutions jobs
📍 United States
💰 USD 160,000 - 190,000 / annual
📅 Posted 2026-08-07 · via Himalayas
🏷 Incident-Response,Cybersecurity,Infosec,Security-Operations,Forensics,Incident-Response-Lead,Lead-Security-Incident-Responder,Senior-Incident-Response-Analyst,Incident-Response-Manager,Security-Incident-Response-Team-Manager
Apply on original site ↗

Overview

Edgewater Federal Solutions is currently seeking an Incident Response (IR) Tech Lead to provide technical expertise, oversight, growth, and maturation of an Incident Response team comprised of IR Tier-1, IR Tier-2, and Forensics specialists on a Federal government contract. This role will provide expert Tier-2/3 support for threat mitigation, incident handling, and response in a 24x7x365 environment, ensuring the security of national-level infrastructure. As a senior incident responder, you will manage significant incidents, guide cross-functional teams, and implement advanced investigative techniques to defend against complex cyber threats. This role requires hands-on technical expertise, strategic oversight, and the ability to develop and improve detection and response processes. This role will also partner with the “Right-of-Boom” Deputy to the Cybersecurity Operations Task Lead.

**Due to the nature of the contract and customer US Citizenship is required.
Responsibilities

- Lead the response for significant and escalated incidents, coordinating tasks across the IR team and ensuring timely completion.

- Oversee incident triage, determining scope, urgency, and potential impact on operations.

- Develop containment, eradication, and recovery strategies for high-severity incidents.

- Perform real-time monitoring and alerting for potential threats using enterprise security tools, including SIEMs and cloud service provider tools.

- Proactively identify and accurately categorize security incidents, leveraging advanced analytics and correlation techniques.

- Lead threat-hunting operations focused on detecting advanced persistent threats (APTs) and other cyber threats.

- Coordinate efforts between various incident response teams across the enterprise to provide full-scale detection and incident response.

- Act as a point of escalation for complex incidents and support junior analysts by providing guidance and mentorship.

- Collaborate with cybersecurity, counterintelligence, and law enforcement teams for insider threat investigations and other sensitive matters.

- Conduct malware analysis and reverse engineering of suspicious payloads and network traffic.

- Perform digital forensics across various platforms, including host-based, network, cloud, and mobile device forensics.

- Acquire and analyze full disk images and other volatile data as part of investigations, ensuring adherence to NIST SP 800-86 guidelines.

- Develop new or enhance existing detection and response processes, leveraging innovative technologies like Security Orchestration, Automation, and Response (SOAR) platforms.

- Create custom detection signatures and automate response workflows.

- Lead research into new technologies and tools to improve the organization’s security posture.

- Develop detailed After-Action Reports (AARs) following significant incidents, summarizing actions taken and lessons learned.

- Create executive summaries and provide regular incident updates for senior leadership.

- Lead and document monthly Lessons Learned meetings for significant incidents, tracking action items to completion.

- Participate in and lead incident response tabletop exercises, collaborating with national and agency-level stakeholders.

- Ensure continual improvement of incident response processes by documenting lessons learned from exercises and real-world events.

- Support counterintelligence and insider threat activities by performing advanced analytics, forensics, and investigation support.

- Analyze suspicious emails, websites, and downloads for nefarious behaviors, escalating findings as necessary.

- Perform content development for SIEM systems, including correlation algorithms and threat detection signatures.

- Assist in evaluating and integrating new security tools to improve threat detection and response capabilities.

Qualifications
-
- Bachelor’s Degree or higher in relevant cybersecurity-related major and 12 years experience.

← All remote jobs