- Salary
- $132k – $178k
- Location
- USA VA Arlington - 4200 Wilson Boulevard, Arlington VA (VAC493), United States of America
- Type
- Full-time
- Experience
- 5+ years
- Clearance
- Required
- Source
- Workday
Description
Type of Requisition:
RegularClearance Level Must Currently Possess:
Interim SecretClearance Level Must Be Able to Obtain:
Top Secret/SCIPublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Cyber Incident Response, Monitoring Tools, Network ForensicsCertifications:
NoneExperience:
5 + years of related experienceUS Citizenship Required:
YesJob Description:
Position Summary
The Incident Responder provides hands-on cyber incident response across Critical Infrastructure; State, Local, Tribal, and Territorial partners; and Federal Civilian agencies. The role handles high‑value intrusions, scoping attacks, driving containment and eradication, and supporting recovery. It is fully deployable, supporting both remote and on‑site operations, collaborating with hunt and intelligence teams, and surging during high‑tempo events.
Key Responsibilities
Incident Response Execution
• Conduct technical response to reported incidents, including scoping, evidence collection, and establishing intrusion extent.
• Drive containment, eradication, and recovery with affected entities and the command center.
• Build and maintain evidence‑based incident timelines.
• Determine and document root cause when evidence supports it.
Deployed & Remote Engagement Support
• Support on‑site incident response, including travel as needed.
• Conduct remote engagements when deployment is not required or feasible.
• Operate within available monitoring and tooling, clearly noting visibility limitations.
• Work directly with affected technical staff, translating findings into actionable steps.
Technical Analysis
• Perform host and network analysis to identify attacker activity, persistence mechanisms, and lateral movement.
• Use outputs from commercial detection and monitoring tools in environments outside organizational control.
• Triage suspicious files and artifacts; escalate items requiring deeper analysis.
• Document indicators of compromise and share with intelligence and hunt teams.
Coordination Across Mission Functions & Agencies
• Maintain accurate incident status and ensure required notifications.
• Collaborate with hunt teams to align response findings with hunt operations.
• Work with intelligence teams to enrich findings and support broader threat understanding.
• Coordinate with external responders such as federal law enforcement, National Guard, and state teams.
Documentation, Reporting & After‑Action
• Produce technical documentation, findings, and actionable reports meeting customer standards.
• Support case file completion aligned with NCISS requirements.
• Ensure rationale for response actions is preserved.
• Contribute to after‑action reviews and procedural improvements.
Surge Readiness
• Maintain readiness to deploy or surge on short notice for major cyber events.
• Support crisis action team operations during elevated tempo.
• Stay current on tools, tradecraft, and mission‑relevant environments.
Required Qualifications
• Hands‑on enterprise incident response experience, including scoping, containment, eradication, and recovery.
• Host and network forensic analysis skills sufficient to determine intrusion extent and attacker activity.
• Experience using commercial detection and monitoring tools in external environments.
• Experience producing technical incident documentation for external stakeholders.
• Ability to work directly with affected organizations during active incidents.
• Willingness and ability to travel and support surge operations.
• Relevant technical training, certification, or degree, plus 5 years of experience.
• Active Top Secret clearance.
Preferred Qualifications
• National‑level incident response experience.
• Experience with ICS/OT or critical infrastructure environments.
• Experience coordinating multi‑agency or multi‑jurisdictional response.
• Malware triage and basic reverse engineering skills.
• Experience with flyaway kits or deployable response tooling.
• Certifications such as GCIH, GCFA, GCFE, GREM, GNFA, or similar.
GDIT Is Your Place
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Community: Award-winning culture of innovation and a military-friendly workplace
Own Your Opportunity
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
Scheduled Weekly Hours:
40Travel Required:
25-50%Telecommuting Options:
HybridWork Location:
USA VA ArlingtonAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events atEqual Opportunity Employer / Individuals with Disabilities / Protected Veterans