Demo

Incident Responder – Shift

ICS Nett
Quantico, VA Full Time
POSTED ON 8/2/2026
AVAILABLE BEFORE 11/29/2026
Embark on an exciting journey with us. Revolutionize technology, drive innovation, and unlock your potential.
Incident Responder – Shift

JOB DESCRIPTION:

ICS Nett, Inc is hiring a Cyber Incident Responder to join our dynamic team for swing shift from 2.00 PM to Midnight to provide support, including weekends and holidays, on rotations. This is an on-site position at Quantico, VA.

The candidate will serve as a front-line defender, detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.

The Cyber Incident Responder will play an important role in executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).

The Incident Responder will collaborate with cross-functional IT and security teams to:

  • Execute incident response procedures in accordance with NIST SP 800-61 and DoD guidelines
  • Coordinate with JFHQ-DODIN on cyber incident reporting and remediation
  • Support insider threat response and investigations
  • Contain and remediate compromised systems, accounts, and endpoints
  • Preserve and document forensic evidence for incident case management
  • Maintain incident response playbooks and ensure high operational readiness during all covered hours

CLEARANCE LEVEL:

Active Top Secret Clearance with eligible to be upgraded to TS/SCI.

LOCATION:

Must be available including weekend and holiday rotations, fully on-site at Quantico, VA.

REQUIREMENTS:

  • At least two (2) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cybersecurity and Computer Network Defense policies.
  • Active Top Secret Clearance with eligibility to be upgraded to TS/SCI.
  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire — IAT Level II (e.g., CCNA Security, CySA , GICSP, GSEC, Security , SSCP); CSIH, GCIH, or GCFA preferred for incident handling.
  • Must be available, including weekend and holiday rotations, fully on-site at Quantico, VA.

Required Skills

  • Incident Detection & Triage: Monitor security alerts and events from SIEM, EDR, IDS/IPS, firewall, DNS, and ESS sources to rapidly detect, triage, and prioritize potential security incidents.
  • Incident Response Lifecycle: Execute the full incident response lifecycle — preparation, detection and analysis, containment, eradication, recovery, and post-incident activity — in accordance with NIST SP 800-61.
  • Containment & Eradication: Take decisive containment and eradication actions on compromised endpoints, accounts, and systems to limit incident impact.
  • Cyber Task Management: Process and handle JFHQ-DODIN cyber-related tasks, orders, and incident reporting requirements to completion within required timelines.
  • Investigation & Forensics: Identify evidence of illegal activity involving cybercrime offenses; examine computers potentially involved in crime or malware infection and preserve forensic evidence following chain-of-custody procedures.
  • Malware Analysis: Use forensic tools and investigative methods to identify, isolate, and analyze specific electronic data associated with complex malware infections.
  • Incident Documentation: Develop and maintain incident response playbooks, standard operating procedures (SOPs), and detailed incident case documentation.
  • Reporting & Escalation: Provide timely incident reports and escalations to senior leadership and deliver daily/weekly/monthly summaries on incident trends and key indicators of network security.

EDUCATION:

  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.

CERTIFICATION(s):

  • Must meet DoD 8570 certification requirements at time of hire — IAT Level II (e.g., CCNA Security, CySA , GICSP, GSEC, Security , SSCP); CSIH, GCIH, or GCFA preferred for incident handling.

Salary : $50,462 - $82,950

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Incident Responder – Shift?

Sign up to receive alerts about other jobs on the Incident Responder – Shift career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Incident Responder – Shift jobs in the Quantico, VA area that may be a better fit.

  • Alaka`ina Foundation Family of Companies Arlington, VA
  • The Alaka`ina Foundation Family of Companies (FOCs) has a potential need for an Incident Responder/Incident Response Coordinator to provide support for our... more
  • 9 Days Ago

  • Alakaina Family of Companies Arlington, VA
  • The Alaka`ina Foundation Family of Companies (FOCs) has a potential need for an Incident Responder/Incident Response Coordinator to provide support for our... more
  • 25 Days Ago

AI Assistant is available now!

Feel free to start your new journey!