Jobs and Careers
MA
Cyber Incident Response Team Lead
ManTechUnited Statesfull_timeVerifiedPosted 6 Dec 2025
About the role
General information
Requisition # R64626 Locations USA-VA-Ashburn Posting Date 12/05/2025 Security Clearance Required TS/SCI Remote Type Onsite Time Type Full timeDescription & Requirements
Transform the future of federal services with MANTECH! Join a vibrant, energetic team committed to enhancing national security and public services through innovative tech. Since 1968, we’ve partnered with Federal Civilian sectors to deliver impactful solutions. Engage in exciting projects in Digital Transformation, Cybersecurity, IT, Data Analytics and more. Ignite your career and drive change. Your journey starts now—innovate and excel with MANTECH!***This is for a future opportunity***
MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Team Lead to join our team in Ashburn, VA.
The ultimate purpose of this role is to provide the disciplined leadership and structural organization necessary to rapidly implement critical, high-impact security solutions that directly protect the Nation's digital borders while ensuring continuous, compliant contract delivery for 24x7x365 network, cyber, and cloud services.
Responsibilities include but are not limited to:
- Serve as the primary operational leader to the SOC for all major computer-related cybersecurity incidents, driving eradication efforts. Developing detailed post-incident reporting for senior leadership and the government client.
- Ensuring that the Incident Response Plan (IRP) lifecycle and the SOC’s incident response capabilities are compliant with DHS 4300A and NIST 800-61 standards.
- Managing the lifecycle of all SOC investigations from creation to closure, using the Case Management System to track all of the incident response metrics (Mean Time To Detect, Mean Time To Contain, etc). Driving continuous improvement against contractual Service Level Agreements (SLAs).
- Assist with advanced analysis of data file system artifacts, memory, network, and log analysis during incidents.
- Support and manage Information/Data Spillage Incident Response efforts.
Minimum Qualifications:
- Bachelor’s degree in computer science, engineering, information technology, or cybersecurity (or five years of relevant work experience in lieu of a degree).
- Certified Information System Security Professional (CISSP) and at least one of the following: SANS GIAC Certified Intrusion Analyst (GCIA), SANS GIAC Certified Incident Handler (GCIH), SANS GIAC Certified Forensic Analyst (GCFA), SANS GIAC Certified Enterprise Defender (GCED), or other IAT Level III certification.
- Seven (7+) years of progressively responsible experience in cyber security, incident response, security engineering, or network engineering.
- Proficient use of cyber tools including SIEM, endpoint detection, and IDS/IPS.
Clearance Requirements:
- Must have an active/ current TS/SCI clearance.
- Must be able to obtain and maintain a CBP BI (Background Investigation)
Phys
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s