Demo

Tier 3 Incident Response Lead

Tyto Athene, LLC
Washington, DC Full Time
POSTED ON 7/30/2026
AVAILABLE BEFORE 8/28/2026

Tyto Athene is searching for a Tier 3 Incident Response Lead. You will play a critical role in conducting in-depth analyses and responding to incidents from cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for other analysts, helping guide them through more complex and high-priority incidents.



Responsibilities:

  • Lead cross-functional teams to perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize security tools to analyze, investigate, and triage security alerts
  • Coordinate the monitoring of our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Utilize advanced tools, such as digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Serve as the primary incident point of contact with law enforcement, third-party vendors, and other external parties
  • Conduct post-incident analysis and lessons learned to identify improvement opportunities
  • Develop or tune detection rules or signatures to improve the effectiveness of security monitoring and collaborate with engineering teams to implement them
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research on emerging threats and vulnerabilities to aid their prevention and mitigation
  • Assist in developing and implementing initiatives that will enhance the SOC’s performance (e.g., SOPs, playbooks, capability deployments)
  • Escalate SOC performance issues or risks to management
  • Provide guidance and mentorship to Tier 1 and Tier 2 SOC Analysts to enhance their skills and capabilities



Required:

  • Bachelor’s Degree or an equivalent combination of formal education and experience in relevant field.
  • 8 or more years of cyber security experience.
  • 8 or more years of experience in investigating network and endpoint architecture
  • CISSP and CEH certifications or equivalent.
  • 3 or more years of incident response experience.
  • 3 or more years of SIEM experience.
  • 2 or more years of Endpoint Detection Response (EDR) experience.
  • Demonstrated competency in opensource industry standard forensic tools and suites
  • Experience with operational security, including security operations center (SOC), incident response, malware analysis, or IDS and IPS analyses
  • Understanding of scripting languages such as Python and regular expressions



Desired:

  • CISSP - Certified Information Systems Security Professional
  • GCFA - GIAC Certified Forensic Analyst
  • GCFE - GIAC Certified Forensic Examiner
  • GREM - GIAC Reverse Engineering Malware




Location:

  • This is hybrid position with requirements to report to the client site in Washington, DC for incident support as needed

Salary : $170,000 - $180,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Tier 3 Incident Response Lead?

Sign up to receive alerts about other jobs on the Tier 3 Incident Response Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$186,685 - $265,377
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Tyto Athene, LLC

  • Tyto Athene, LLC Denver, CO
  • Tyto Athene is searching for a Desktop Support Level II in Aurora, CO. This is a complex, multi-year contract to support the Air Force Reserve Command (AFR... more
  • 2 Days Ago

  • Tyto Athene, LLC Linthicum Heights, MD
  • Tyto Athene is seeking a Senior Cyber Lead to support the Department of Defense Cyber Crime Center (DC3) Cyber Forensics Laboratory (CFL) mission supportin... more
  • 2 Days Ago

  • Tyto Athene, LLC Reserve, CA
  • Description Tyto Athene is searching for a Network Administrator II for a complex, multi-year contract to support the Air Force Reserve Command (AFRC) Info... more
  • 2 Days Ago

  • Tyto Athene, LLC Wahiawa, HI
  • Tyto Athene is searching for a Senior Engineering Technician to design, develop, configure, install, and maintain Physical Security Engineering and Electro... more
  • 3 Days Ago


Not the job you're looking for? Here are some other Tier 3 Incident Response Lead jobs in the Washington, DC area that may be a better fit.

  • Accenture Federal Services Germantown, MD
  • At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. O... more
  • 2 Days Ago

  • Agile Defense Reston, VA
  • About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the fut... more
  • 2 Months Ago

AI Assistant is available now!

Feel free to start your new journey!