ForgeApply · Job listing
Cyber Incident Response Team (CIRT) Lead
GDIT
Tailor your resume for this GDIT job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for GDIT's site. Free trial, no card required.
About this role
Type of Requisition: Regular
Clearance Level Must Currently Possess: Secret
Clearance Level Must Be Able to Obtain: Secret
Public Trust/Other Required: None
Job Family: Cyber and IT Risk Management
Job Qualifications: Skills: Cyber Incident Response, Cyber Operations, Cyber Risks, Data Security, Leadership Certifications: None Experience: 5 + years of related experience US Citizenship Required: Yes
Job Description: Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls Church, VA Clearance: Active SECRET (must be maintained)
At GDIT, we are passionate about securing and supporting some of the most challenging government, defense, and intelligence missions. As part of our team, your work will have meaning and impact, helping to make today safer and tomorrow smarter. Join a culture that values autonomy, collaboration, and delivering your best every day. GDIT has an opening for a Cyber Incident Response Team (CIRT) Lead supporting the Army National Guard (ARNG). This position is part of an IT Service Management contract that includes the operation, modernization, expansion, and evolution of the ARNG’s global IT services. These services span networking, compute, storage, infrastructure, cybersecurity, applications, hosting, and program management. The program operates within the ITIL framework to deliver high-quality IT services to the ARNG, and this leadership role is critical to ensuring the security and success of that mission.
HOW A CIRT LEAD WILL MAKE AN IMPACT As the CIRT Lead, you will combine hands-on incident response expertise with team leadership responsibilities to guide analysts and coordinate complex cyber operations in support of ARNG. Lead and Manage the CIRT Team • Provide day-to-day leadership of CIRT analysts, including tasking, prioritization, and oversight of incident response activities.
• Mentor, coach, and develop team members, including feedback, informal performance guidance, and support for career development.
• Ensure consistent adherence to incident response procedures, quality standards, and timelines.
• Coordinate shift coverage, on-call rotations, and escalation paths to meet mission requirements.
• Serve as the primary point of contact for CIRT-related activities with ARNG stakeholders and other GDIT teams.
Incident Response Operations • Lead triage of cyber incidents, determining scope, urgency, impact, and recommended courses of action.
• Guide and, when necessary, perform collection and analysis of network/host artifacts (logs, images, packet captures) to identify root cause and operational impact.
• Oversee real-time cyber defense incident handling, ensuring rapid, coordinated response and remediation.
• Direct proactive identification of vulnerabilities and recommend mitigations to reduce risk.
• Demonstrate and validate effectiveness of defenses through coordination with Red Team activities and investigations.
• Ensure cyber defense incidents are managed, documented, and tracked from detection through resolution, with clear, concise reporting.
Process, Documentation, and Training • Maintain and improve Incident Response tactics, techniques, procedures (TTPs), and training documentation.
• Plan and oversee the delivery of incident response training courses (at least four per calendar year), delegating instruction and ensuring quality content.
• Support efforts to maintain the customer’s CSSP accreditation, including documentation, technical writing, and audit support.
• Drive continuous improvement in incident response workflows, tools usage, and reporting.
Stakeholder Communication and Collaboration • Provide timely briefings and written reports to ARNG leadership and other stakeholders on incident status, trends, and lessons learned.
• Participate in and often lead cross-functional meetings to improve cybersecurity posture across the environment.
• Coordinate closely with engineering, operations, and other cyber defense teams to ensure alignment and effective mitigation of threats.
• Support on-call and after-hours activities as needed, and ensure the team is prepared to respond to time-sensitive events under tight deadlines.
WHAT YOU’LL NEED TO SUCCEED Education / Equivalent Training • Bachelor’s degree in information technology, computer science, or a related technical discipline; or an equivalent combination of education, technical certifications/training, and relevant work experience.
Required Experience • 5+ years of practical experience in a cybersecurity, engineering, T&E, or A&A-related field.
• Demonstrated prior experience with cyber incident response on DoW networks and digital forensics.
• Experience in a lead or senior role guiding incident response activities or mentoring junior analysts is strongly preferred.
Technical and Leadership Skills • Proficiency in collecting and analyzing logs, system images, and other artifacts to investigate and resolve cybersecurity incidents.
• Strong understanding of cybersecurity concepts, mitigation strategies, root cause analysis, and Red Team operations.
• Familiarity with current cyber defense tools and technologies (e.g., SIEM, IDS/IPS, endpoint protection, packet capture tools).
• Excellent oral and written communication skills for both technical and non-technical audiences, including incident reports and briefings.
• Strong organizational skills for multitasking, meeting deadlines, and managing team workload.
• Ability to work independently and lead a team in fast-paced environments, solving complex problems under pressure.
• Collaborative mindset, strong customer service orientation, and ability to build trust and credibility with customers and team members.
• Dependability, punctuality, responsiveness to management, and attention to detail.
Certification Requirements • Must possess the appropriate baseline certification(s) to achieve at least DoWD 8570.01-M IAT Level II (e.g., CompTIA Security+ CE ) prior to start.
• Must obtain an
Tailor your resume for this GDIT role before you apply.
Tailor my resume for this jobSimilar jobs
- Director, Cyber Security Incident Response Team (CSIRT) — AstraZeneca · MD, Gaithersburg
- Senior Manager, Cyber Incident Response Team — Adobe · Lehi | Seattle | San Jose
- Cyber Threat Hunt (CTH) Lead — Accenturefederalservices · Arlington, VA
- Cyber Operations Lead — Accenturefederalservices · Arlington, VA
- Cybersecurity Incident Response Specialist — Geotab · Atlanta, Georgia - USA
- Cyber Analyst, Digital Forensics Incident Response — Atbayjobs · Remote
- Senior Cyber Defense Incident Responder — AIG · NC-Charlotte
- Sr. Cyber Analyst, Digital Forensics Incident Response — Atbayjobs · Remote
More like this: More jobs at GDIT · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)