Hiring.Camp

Cyber Incident Response Team (CIRT) Lead

GDIT

·

Today

Salary
$136k – $184k
Location
USA VA Falls Church - 3170 Fairview Park Drive (VAC466), United States of America
Workplace
Onsite
Type
Full-time
Seniority
Lead
Clearance
Required
Source
Workday

Description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Cyber Incident Response, Cyber Operations, Cyber Risks, Data Security, Leadership

Certifications:

None

Experience:

5 + years of related experience

US Citizenship Required:

Yes

Job Description:

Cyber Incident Response Team (CIRT) Lead
Location: Full-time onsite, Falls Church, VA
Clearance: Active SECRET (must be maintained)

At GDIT, we are passionate about securing and supporting some of the most challenging government, defense, and intelligence missions. As part of our team, your work will have meaning and impact, helping to make today safer and tomorrow smarter. Join a culture that values autonomy, collaboration, and delivering your best every day.

GDIT has an opening for a Cyber Incident Response Team (CIRT) Lead supporting the Army National Guard (ARNG). This position is part of an IT Service Management contract that includes the operation, modernization, expansion, and evolution of the ARNG’s global IT services. These services span networking, compute, storage, infrastructure, cybersecurity, applications, hosting, and program management. The program operates within the ITIL framework to deliver high-quality IT services to the ARNG, and this leadership role is critical to ensuring the security and success of that mission.

HOW A CIRT LEAD WILL MAKE AN IMPACT

As the CIRT Lead, you will combine hands-on incident response expertise with team leadership responsibilities to guide analysts and coordinate complex cyber operations in support of ARNG.

Lead and Manage the CIRT Team

  • Provide day-to-day leadership of CIRT analysts, including tasking, prioritization, and oversight of incident response activities.

  • Mentor, coach, and develop team members, including feedback, informal performance guidance, and support for career development.

  • Ensure consistent adherence to incident response procedures, quality standards, and timelines.

  • Coordinate shift coverage, on-call rotations, and escalation paths to meet mission requirements.

  • Serve as the primary point of contact for CIRT-related activities with ARNG stakeholders and other GDIT teams.

Incident Response Operations

  • Lead triage of cyber incidents, determining scope, urgency, impact, and recommended courses of action.

  • Guide and, when necessary, perform collection and analysis of network/host artifacts (logs, images, packet captures) to identify root cause and operational impact.

  • Oversee real-time cyber defense incident handling, ensuring rapid, coordinated response and remediation.

  • Direct proactive identification of vulnerabilities and recommend mitigations to reduce risk.

  • Demonstrate and validate effectiveness of defenses through coordination with Red Team activities and investigations.

  • Ensure cyber defense incidents are managed, documented, and tracked from detection through resolution, with clear, concise reporting.

Process, Documentation, and Training

  • Maintain and improve Incident Response tactics, techniques, procedures (TTPs), and training documentation.

  • Plan and oversee the delivery of incident response training courses (at least four per calendar year), delegating instruction and ensuring quality content.

  • Support efforts to maintain the customer’s CSSP accreditation, including documentation, technical writing, and audit support.

  • Drive continuous improvement in incident response workflows, tools usage, and reporting.

Stakeholder Communication and Collaboration

  • Provide timely briefings and written reports to ARNG leadership and other stakeholders on incident status, trends, and lessons learned.

  • Participate in and often lead cross-functional meetings to improve cybersecurity posture across the environment.

  • Coordinate closely with engineering, operations, and other cyber defense teams to ensure alignment and effective mitigation of threats.

  • Support on-call and after-hours activities as needed, and ensure the team is prepared to respond to time-sensitive events under tight deadlines.

WHAT YOU’LL NEED TO SUCCEED

Education / Equivalent Training

  • Bachelor’s degree in information technology, computer science, or a related technical discipline; or an equivalent combination of education, technical certifications/training, and relevant work experience.

Required Experience

  • 5+ years of practical experience in a cybersecurity, engineering, T&E, or A&A-related field.

  • Demonstrated prior experience with cyber incident response on DoW networks and digital forensics.

  • Experience in a lead or senior role guiding incident response activities or mentoring junior analysts is strongly preferred.

Technical and Leadership Skills

  • Proficiency in collecting and analyzing logs, system images, and other artifacts to investigate and resolve cybersecurity incidents.

  • Strong understanding of cybersecurity concepts, mitigation strategies, root cause analysis, and Red Team operations.

  • Familiarity with current cyber defense tools and technologies (e.g., SIEM, IDS/IPS, endpoint protection, packet capture tools).

  • Excellent oral and written communication skills for both technical and non-technical audiences, including incident reports and briefings.

  • Strong organizational skills for multitasking, meeting deadlines, and managing team workload.

  • Ability to work independently and lead a team in fast-paced environments, solving complex problems under pressure.

  • Collaborative mindset, strong customer service orientation, and ability to build trust and credibility with customers and team members.

  • Dependability, punctuality, responsiveness to management, and attention to detail.

Certification Requirements

  • Must possess the appropriate baseline certification(s) to achieve at least DoWD 8570.01-M IAT Level II (e.g., CompTIA Security+ CE) prior to start.

  • Must obtain an additional computing environment certification within six months of hire based on position designation (e.g., CEH, CCNA-Security, CND, etc.).

  • When DoW 8140 requirements are implemented on the program/contract, employees must conform to 8140 certification standards.

Security Clearance

  • Active SECRET security clearance required and must be maintained.

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tools that identify career steps and learning opportunities.

  • Support: An internal mobility team focused on helping you achieve your career goals.

  • Rewards: Comprehensive benefits and wellness packages, 401(k) with company match, competitive pay, and paid time off.

  • Community: Award-winning culture of innovation and a military-friendly workplace.

OWN YOUR OPPORTUNITY
Explore a leadership role in cyber incident response at GDIT and you’ll find opportunities to guide mission-critical work while growing alongside colleagues who share your passion for the mission and delivering results.

The likely salary range for this position is $136,000 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Onsite

Work Location:

USA VA Falls Church

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 

 


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

 

 

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Skills

CybersecuritySIEMRisk ManagementCustomer ServiceProgram ManagementTechnical WritingITILCompTIACCNA

Similar Jobs

30

Cyber Incident Response Analyst II

AmTrust Financial · Cleveland, OH, US

3 days ago

Cyber Incident Response Specialist (Associate)

Depository Trust Company · Tampa, FL, United States, US

1 week ago

Client Engagement Mgr Cyber Incident Response

Cognicion · Multiple Locations +1

1 week ago

Cyber Incident Response Analyst

Feverup · Argentina

2 weeks ago

Senior Consultant Cyber Incident Response (m/f/d)

Freseniusglobal · Bad Homburg (EK1), Germany

1 month ago

Senior Consultant Cyber Incident Response (m/f/d)

Freseniusglobal · Bad Homburg (EK1), Germany

1 month ago

Lead Analyst – Cyber Incident Response

Raymond James · FL - Saint Petersburg - 800 Carillon Pkwy, United States of America

1 month ago

Cyber Incident Response Associate Attorney

Wilsonelserattorneys · Washington, DC +1 · Hybrid

1 month ago

Cyber Incident Response Associate Attorney

Wilsonelserattorneys · Boston, Massachusetts +1 · Hybrid

1 month ago

FINEX Cyber Incident Response Leader

LON3 London - 51 Lime Street · London, London, United Kingdom, GB

1 month ago

Staff Cyber Incident Response Engineer

Adobe · San Jose, United States of America +2

2 months ago

Cyber Incident Response Business Development Senior Manager

Booz Allen Hamilton · USA, VA, McLean (8283 Greensboro Dr, Hamilton), United States of America +17

2 months ago

Senior Cyber Incident Response Analyst

Integrity360 · Dublin, Dublin, Ireland

2 months ago

Senior Manager, Cyber Incident Response Team

Adobe · Lehi, United States of America +2

2 months ago

Senior Cyber Incident Response Analyst

Integrity360

2 months ago

Senior Cyber Incident Response Analyst

Integrity360

2 months ago

Senior Cyber Incident Response Analyst

Integrity360

2 months ago

Senior Cyber Incident Response Analyst (Cape Town or Johannesburg)

Integrity360 · Cape Town, Western Cape, South Africa

3 months ago

Senior Associate, Cyber Incident Response

Richemont · Office RIC - NEW YORK 645 Fifth Avenue 5-9F (USNE0009), United States of America

4 months ago

Document Reviewer (Cyber Incident Response)

Integreon Smart Solutions to Process Driven Needs · , US · Onsite

5 months ago

Cyber Incident Response Associate Attorney

Wilsonelserattorneys · Miami, Florida +1 · Hybrid

6 months ago

Cyber Incident Response Associate Attorney

Wilsonelserattorneys · New York, New York +1 · Hybrid

6 months ago

Cyber Incident Response Associate Attorney

Wilsonelserattorneys · Los Angeles, California +1 · Hybrid

6 months ago

Cyber Incident Response Attorney position

Wilsonelserattorneys · Chicago, Illinois · Hybrid

6 months ago

Cyber Incident & Response Team Analyst

Euroclear · Poland, PL

6 months ago

Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS

Peraton · Arlington, VA, US

6 months ago

Engineer II - Cyber Incident Response

AmerisourceBergen is now Cencora! Explore our careers. · USA > PA > Conshohocken > West First, United States of America +1

6 months ago

Cyber Incident Response Manager

Bbh · Boston, United States of America +1

9 months ago

Senior Cyber Incident Response Attorney

Wilsonelserattorneys · New York, New York +1

1+ year ago

Senior Cyber Incident Response Attorney

Wilsonelserattorneys · Washington, DC +1

1+ year ago