Incident Responder (IR Specialist)

General Dynamics Information TechnologyArlington, VA
$131,750 - $178,250Hybrid

About The Position

The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on‑site operations, collaborating with hunt and intelligence teams, and surging during high‑tempo events.

Requirements

  • Hands‑on enterprise incident response experience, including scoping, containment, eradication, and recovery.
  • Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity.
  • Experience using commercial detection and monitoring tools in external environments.
  • Experience producing technical incident documentation for external stakeholders.
  • Ability to work directly with affected organizations during active incidents.
  • Willingness and ability to travel and support surge operations.
  • Relevant technical training, certification, or degree, plus 5 years of experience.
  • Active Top Secret clearance.

Nice To Haves

  • National‑level incident response experience.
  • Experience with ICS/OT or critical infrastructure environments.
  • Experience coordinating multi‑agency or multi‑jurisdictional response.
  • Malware triage and basic reverse engineering skills.
  • Experience with flyaway kits or deployable response tooling.
  • Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.

Responsibilities

  • Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent.
  • Drive containment, eradication, and recovery with affected entities and the command center.
  • Build and maintain evidence‑based incident timelines.
  • Determine and document root cause when evidence supports it.
  • Support on‑site incident response, including travel as needed.
  • Conduct remote engagements when deployment is not required or feasible.
  • Operate within available monitoring and tooling, clearly noting visibility limitations.
  • Work directly with affected technical staff, translating findings into actionable steps.
  • Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement.
  • Use outputs from commercial detection and monitoring tools in environments outside organizational control.
  • Triage suspicious files and artifacts; escalate items requiring deeper analysis.
  • Document indicators of compromise and share with intelligence and hunt teams.
  • Maintain accurate incident status and ensure required notifications.
  • Collaborate with hunt teams to align response findings with hunt operations.
  • Work with intelligence teams to enrich findings and support broader threat understanding.
  • Coordinate with external responders such as federal law enforcement, National Guard, and state teams.
  • Produce technical documentation, findings, and actionable reports meeting customer standards.
  • Support case file completion aligned with NCISS requirements.
  • Ensure rationale for response actions is preserved.
  • Contribute to after‑action reviews and procedural improvements.
  • Maintain readiness to deploy or surge on short notice for major cyber events.
  • Support crisis action team operations during elevated tempo.
  • Stay current on tools, tradecraft, and mission‑relevant environments.

Benefits

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace
  • Medical plan options
  • Health Savings Accounts
  • Dental plan options
  • Vision plan
  • 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • Full flex work weeks where possible
  • Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • Short and long-term disability benefits
  • Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service