See all roles

Cybersecurity Incident Response Engineer- Secret

Work from home Full-time role Hiring

We are hiring for Jr, Mid, and SR levels for this role! This role requires an active Secret Clearance or within 24 months. Falsely claiming a DoD clearance can lead to serious legal consequences, including criminal charges under 18 U.S. Code § 1001, which may result in fines and imprisonment of up to five years. Clearance: Active Secret Clearance required Travel: Up to 10% We are seeking Cybersecurity Incident Response Engineer to support a mission-critical federal environment. This role is responsible for monitoring enterprise security tools, identifying potential threats, and supporting incident response efforts. The ideal candidate will have foundational cybersecurity knowledge, strong analytical skills, and the ability to operate in a fast-paced Security Operations Center (SOC).

Key Responsibilities

  • Monitor SIEM and security tools to detect, analyze, and correlate potential cybersecurity threats
  • Perform alert triage, including validating alerts, assessing severity, and escalating as needed
  • Differentiate false positives from legitimate security incidents
  • Support incident response activities, including evidence collection and containment efforts
  • Document investigations thoroughly for audit and reporting purposes
  • Follow SOC playbooks, procedures, and escalation protocols
  • Assist in tuning detection rules and improving alert accuracy
  • Collaborate with IT, operations, and risk teams to align with security policies and mission needs
  • Maintain awareness of security technologies such as firewalls, IDS/IPS, endpoint protection, and vulnerability scanners

Required Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Computer Science, or related field (or equivalent experience)
  • 1–10 years of experience in cybersecurity, IT operations, or related field
  • Basic understanding of cybersecurity principles and threat detection
  • Experience or familiarity with SIEM and other security tools
  • Active Secret Clearance (required)
  • Strong problem-solving, communication, and analytical skills

Preferred Qualifications

  • Experience in a SOC or 24/7 monitoring environment
  • Relevant Certification (Security+, CySA+, etc.)
  • Familiarity with incident response playbooks and procedures
  • Exposure to federal cybersecurity frameworks or compliance standards

Apply To This Job

You might like

(Remote)Technical Writer

Work from home Full-time role

Medical Writer, Medical Communications

Work from home Full-time role

Future Opportunity, Customer Account Executive (Enterprise)

Work from home Full-time role

Higher Education Human Resources/Payroll Consultants

Work from home Full-time role

UX/UI Designer, eComm (Contract)

Work from home Full-time role

Pre-Sales Engineer (Land Mobile Radio - Northeast)

Work from home Full-time role

Accountant - Pacific Northwest - Full-Time or Part-Time

Work from home Full-time role

Associate Technical Support Engineer - Red Hat Advanced Cluster Management for Kubernetes

Work from home Full-time role

Windows System Admin

Work from home Full-time role

Need submission details for Network Administrator, Remote

Work from home Full-time role

Senior Benefits Analyst

Work from home Full-time role

Risk Adjustment Manager

Work from home Full-time role

Sales & Operations Manager

Work from home Full-time role

Experienced Part-Time Customer and Team Member Outreach Specialist – Real Estate Management

Work from home Full-time role

Adjunct Lecturer of Nursing (e-Learning Campus)-1

Work from home Full-time role

Experienced Part-Time Remote Data Entry Clerk – arenaflex

Work from home Full-time role

Cyber Incident Coordinator (m/w/d)

Work from home Full-time role

Clinical Trial Specialist, US

Work from home Full-time role

Experienced Part-Time Remote Data Entry Clerk – Typing – Entry-Level Opportunity at arenaflex

Work from home Full-time role

Sales Appointment Setter (Cold Caller) – Remote

Work from home Full-time role