Demo

Incident Responder

cFocus Software Incorporated
Washington, DC Full Time
POSTED ON 4/8/2026
AVAILABLE BEFORE 6/17/2026
cFocus Software seeks a n Incident Responder to support the Administrative Offices of the United States Courts (AOUSC) in Washington, DC.  This position will require 4 days a week onsite at the Thurgood Marshall Building and 1 day remote with hours of 8am- 4:30pm.  

Position Overview

The Incident Responder supports the Administrative Office of the U.S. Courts (AOUSC) by delivering advanced cybersecurity incident response and threat hunting services across both cloud and on-premises environments. This role focuses on identifying, analyzing, and mitigating sophisticated cyber threats while strengthening detection capabilities and improving overall security posture.


Key Responsibilities

  • Provide incident response support for declared security incidents and proactively hunt for threats not detected through automated systems

  • Conduct counterintelligence activities, develop Threat Actor (TA) dossiers, and identify adversary tactics, techniques, and procedures (TTPs)

  • Analyze SIEM alerts and security events to determine risk, impact, and appropriate response actions

  • Collect and analyze forensic data from compromised systems using EDR tools and custom scripts

  • Track and document incidents from initial detection through final resolution

  • Respond to government technical requests via ITSM platforms (e.g., HEAT, ServiceNow)

  • Perform malware triage and root cause analysis

  • Review open-source intelligence for emerging threats and adversary activity

  • Collaborate with court IT personnel to troubleshoot and resolve endpoint detection issues

  • Participate in after-action reviews and provide recommendations for improving security posture

  • Attend Agile Scrum standups and report on assigned Jira tasks

  • Review SOC incident reports and recommend enhancements, escalations, or re-evaluations


Required Qualifications

  • Minimum of 5 years of experience in incident response across cloud and non-cloud environments, including:

    • Microsoft Azure

    • Microsoft O365

    • Microsoft Active Directory

    • Zscaler

  • Minimum of 5 years of experience using Splunk Enterprise Security for incident response

  • Minimum of 5 years of experience collecting and analyzing data using:

    • EDR tools (CrowdStrike, Qualys)

    • Custom scripts (e.g., Sysmon, Auditd)

  • Experience with the following tools and technologies:

    • Microsoft Sentinel (threat hunting in Azure)

    • Tenable Nessus and SYN/ACK (vulnerability management)

    • NetScout (network traffic analysis)

    • SPUR.us (IP/address enrichment)

    • Mandiant threat intelligence feeds

  • Splunk Core Power User certification (required)

  • Must possess one of the following certifications:

    • GIAC Certified Intrusion Analyst (GCIA)

    • GIAC Certified Incident Handler (GCIH)

    • GIAC Continuous Monitoring (GMON)

    • GIAC Defending Advanced Threats (GDAT)

  • Ability to obtain a Low Risk Public Trust Suitability Determination


Key Deliverables

  • QA/Security Analysis review of SOC incident reports

  • Threat Actor (TA) IOC assessments

  • Web Application Firewall (WAF) rule implementations

  • Development of operational templates

  • Advanced SME Incident Response support for Priority 1 events (engagement within 4 hours, 24/7/365)

  • Comprehensive incident reports including:

    • Executive summary

    • Detailed findings

    • Security impact assessment

    • Timeline of events

    • Actions taken

  • Documentation of all work in Jira aligned with Agile processes 

  • Creation and maintenance of Standard Operating Procedures (SOPs) and security playbooks


Work Environment

This role requires a strong on-site presence (80%) at the AOUSC facility in Washington, DC, and active participation in a collaborative, Agile-based cybersecurity operations environment.

Salary.com Estimation for Incident Responder in Washington, DC
$107,837 to $136,222
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Incident Responder?

Sign up to receive alerts about other jobs on the Incident Responder career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$115,647 - $153,495
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at cFocus Software Incorporated

  • cFocus Software Incorporated Fairfax, VA
  • Job Summary: The Proposal Technical Writer will play a critical role in crafting winning proposals for DoD and federal contracts. This position requires a ... more
  • Just Posted

  • cFocus Software Incorporated Springfield, VA
  • We are seeking a highly experienced Senior Kubernetes Engineer to support mission-critical systems for the Transportation Security Administration (TSA). Th... more
  • 2 Days Ago

  • cFocus Software Incorporated Washington, DC
  • cFocus Software seeks a System Reliability Engineer to join our program supporting the Executive Office of the President. This position is remote. This pos... more
  • 4 Days Ago

  • cFocus Software Incorporated Washington, DC
  • cFocus Software seeks a Tier 2 SOC Analyst to join our program supporting the Congressional Budget Office (CBO). This position is remote. This position req... more
  • 13 Days Ago


Not the job you're looking for? Here are some other Incident Responder jobs in the Washington, DC area that may be a better fit.

  • Evolver Federal Washington, DC
  • Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential government client. The Lead Incident Responder serves as the ... more
  • 4 Days Ago

  • Planet Technologies Washington, DC
  • Planet Technologies, the Nation’s leading Microsoft services provider to the public sector, is looking for a highly motivated individual to join our growin... more
  • 5 Days Ago

AI Assistant is available now!

Feel free to start your new journey!