Cyber Incident Responder (24x7 Days)

ASRC FederalQuantico, VA
$125,000 - $153,656Onsite

About The Position

ASRC Federal is seeking a highly skilled and experienced Cyber Incident Responder to join our dynamic team on the day shift (0600 – 1600), providing extended-hours coverage that includes weekend and holiday rotations. This is a fully on-site position at Quantico Marine Corps Base, VA — no telework is available for this role. The successful candidate will serve as a front-line defender, rapidly detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.

Requirements

  • At least Five (5) years of hands-on technical cybersecurity experience and knowledge of incident response concepts, Computer Network Defense, DISA Security Technical Implementation Guides (STIGs), DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01B, United States Cyber Command guidelines, and other applicable DoD Cyber Security and Computer Network Defense policies.
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI.
  • Bachelor’s degree in Information Technology, Information Systems Management, Cyber Security, or equivalent experience.
  • Must meet DoD 8570 certification requirements at time of hire — IAT Level II (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+, SSCP).
  • Willingness and availability to work the day shift (0600 – 1600), including weekend and holiday rotations, fully on-site at Quantico, VA.
  • Knowledge of computer network defense concepts, DISA Security Technical Information Guides, DoD A&A Process, NIST SP 800-53, NIST SP 800-61, CJCSM 6510.01 B, United States Cyber Command guidelines, and other applicable DoD Cybersecurity and Computer Network Defense Policies Cybersecurity and Computer Network Defense policies.

Nice To Haves

  • CSIH, GCIH, or GCFA preferred for incident handling.

Responsibilities

  • Executing the full incident response lifecycle during day shift, weekend, and holiday coverage windows.
  • Detecting and responding to security incidents in real time.
  • Performing containment and eradication actions.
  • Coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
  • Executing incident response procedures in accordance with NIST SP 800-61 and DoD guidelines.
  • Coordinating with JFHQ-DODIN on cyber incident reporting and remediation.
  • Supporting insider threat response and investigations.
  • Containing and remediating compromised systems, accounts, and endpoints.
  • Preserving and documenting forensic evidence for incident case management.
  • Maintaining incident response playbooks and ensuring high operational readiness during all covered hours.
  • Developing, maintaining, and providing a weekly brief that captures all the cyber events including metrics and trends.
  • Providing continuous monitoring, data to include but not limited to network and host vulnerability scanning IDS, firewall, network sensor tuning, net flow/packet capture (PCAP).
  • Collecting and keeping audit data in order to conduct a technical analysis relating to misuse, penetration, or other incidents.
  • Documenting incidents, response actions, and remediation recommendations in accordance with government reporting requirements.
  • Monitoring multiple environments for malicious or anomalous activity using SIEM, SOAR, and on-prem security tooling.
  • Analyzing logs, telemetry, alerts, and audit data to identify indicators of compromise (IOCs) and attack patterns.

Benefits

  • health care
  • dental
  • vision
  • life insurance
  • 401(k)
  • education assistance
  • paid time off
  • holidays
  • any other paid leave required by law
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service