ForgeApply · Job listing
Incident Responder (IR Specialist)
GDIT
See all 236 open roles at GDIT →
Tailor your resume for this GDIT job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for GDIT's site. Free trial, no card required.
About this role
Type of Requisition: Regular
Clearance Level Must Currently Possess: Interim Secret
Clearance Level Must Be Able to Obtain: Top Secret/SCI
Public Trust/Other Required: None
Job Family: Cyber and IT Risk Management
Job Qualifications: Skills: Cyber Incident Response, Monitoring Tools, Network Forensics Certifications: None Experience: 5 + years of related experience US Citizenship Required: Yes
Job Description: Position Summary The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on‑site operations, collaborating with hunt and intelligence teams, and surging during high‑tempo events.
Key Responsibilities
Incident Response Execution • Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent. • Drive containment, eradication, and recovery with affected entities and the command center. • Build and maintain evidence‑based incident timelines. • Determine and document root cause when evidence supports it.
Deployed & Remote Engagement Support • Support on‑site incident response, including travel as needed. • Conduct remote engagements when deployment is not required or feasible. • Operate within available monitoring and tooling, clearly noting visibility limitations. • Work directly with affected technical staff, translating findings into actionable steps.
Technical Analysis • Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement. • Use outputs from commercial detection and monitoring tools in environments outside organizational control. • Triage suspicious files and artifacts; escalate items requiring deeper analysis. • Document indicators of compromise and share with intelligence and hunt teams.
Coordination Across Mission Functions & Agencies • Maintain accurate incident status and ensure required notifications. • Collaborate with hunt teams to align response findings with hunt operations. • Work with intelligence teams to enrich findings and support broader threat understanding. • Coordinate with external responders such as federal law enforcement, National Guard, and state teams.
Documentation, Reporting & After‑Action • Produce technical documentation, findings, and actionable reports meeting customer standards. • Support case file completion aligned with NCISS requirements. • Ensure rationale for response actions is preserved. • Contribute to after‑action reviews and procedural improvements.
Surge Readiness • Maintain readiness to deploy or surge on short notice for major cyber events. • Support crisis action team operations during elevated tempo. • Stay current on tools, tradecraft, and mission‑relevant environments.
Required Qualifications • Hands‑on enterprise incident response experience, including scoping, containment, eradication, and recovery. • Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity. • Experience using commercial detection and monitoring tools in external environments. • Experience producing technical incident documentation for external stakeholders. • Ability to work directly with affected organizations during active incidents. • Willingness and ability to travel and support surge operations. • Relevant technical training, certification, or degree, plus 5 years of experience. • Active Top Secret clearance.
Preferred Qualifications • National‑level incident response experience. • Experience with ICS/OT or critical infrastructure environments. • Experience coordinating multi‑agency or multi‑jurisdictional response. • Malware triage and basic reverse engineering skills. • Experience with flyaway kits or deployable response tooling. • Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.
GDIT Is Your Place At GDIT, the mission is our purpose, and our people are at the center of everything we do. ● Growth: AI-powered career tool that identifies career steps and learning opportunities ● Support: An internal mobility team focused on helping you achieve your career goals ● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off ● Community: Award-winning culture of innovation and a military-friendly workplace
Own Your Opportunity Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
The likely salary range for this position is $131,750 - $178,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours: 40
Travel Required: 25-50%
T elecommuting Options: Hybrid
Work Location: USA VA Arlington
Additional Work Locations:
Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We r
Tailor your resume for this GDIT role before you apply.
Tailor my resume for this jobSimilar jobs
- Incident Response Specialist, Analyst — MUFG · Tempe, AZ
- Incident Response Manager — Crowe · Sarasota FL USA | Tallahassee FL USA | Chicago IL USA
- Incident Response Manager — Fluidstack · San Francisco, CA
- Incident Response Technician — Ferrovial · Manassas, VA
- Incident Response Engineer — Accenturefederalservices · Arlington, VA
- Incident Response Engineer — Reteam · Remote
- Incident Response Engineer — Reteam · New york
- Incident Response Analyst I — Astreya · Austin, TX
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)