147 incident response jobs at 97 companies in Maryland

2w
Save
Mark Applied
Hide
Incident Response Analyst
Bethesda, Maryland, United States
$110k-$130k/yr RemoteFull Time
SkyePoint Decisions
SkyePoint Decisions: Provider of cybersecurity, infrastructure, and IT development services.
5+ YOEBachelor's in a related field, 5+ years cybersecurity/incident response experience, federal program experience, U.S. citizenship, ability to obtain Public Trust, SIEM/Splunk and EDR experience, strong communication and on-call availability.
SIEM, Splunk, IDS/IPS, EDR, FireEye, Palo Alto, Tenable, Qualys, Rapid7
2w
Save
Mark Applied
Hide
Incident Response and Forensics Lead
Germantown or Washington
$100k-$203k/yr HybridFull Time
Accenture Federal Services
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
7+ YOEUS citizen with active TS clearance, 7+ years incident response/digital forensics experience, GCFE or GCIH, proficiency with Magnet, GrayKey, EnCase, Cellebrite, cloud and endpoint security expertise.
Magnet, GrayKey, EnCase, Cellebrite
1w
Save
Mark Applied
Hide
Incident Response (IR) and Forensics Lead (Q Clearance)
Germantown, Maryland, United States
OnsiteFull Time
ShorePoint
ShorePoint: Provides cybersecurity and risk management services for federal agencies.
7+ YOEBachelor’s degree or associate degree plus 2+ years’ experience, 7+ years relevant experience, active DOE Q or equivalent DoD Top Secret clearance, and expertise in incident response, digital forensics, and cybersecurity operations.
2mo
Save
Mark Applied
Hide
Senior Director, Digital Forensics and Incident Response
New York City or Maryland or Tel Aviv or San Francisco or London or Budapest or United States or South America
RemoteFull Time
BlueVoyant
BlueVoyant: Managed detection, response, and threat intelligence security services.
3+ YOEExperience leading DFIR incidents as incident commander, 3+ years hands-on DFIR, 6+ years client-facing cyber/incident response experience, executive communication, mentoring, familiarity with endpoint/cloud/identity forensics and related tools, US citizenship required.
EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Microsoft Sentinel, CrowdStrike, Microsoft 365, Microsoft Entra ID, Azure, AWS, Okta, Google Workspace, KQL, SPL, SQL, PowerShell, Python, Bash
1mo
Save
Mark Applied
Hide
Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)
Elkridge or United States
$100k-$160k/yr RemoteFull Time
Surefire Cyber
Surefire Cyber: Provides rapid incident response and digital forensics services.
Experienced DFIR professional with technical forensic analysis, incident response leadership, client-facing skills, team mentoring, and availability for after-hours on-call support.
ELK, Axiom, EnCase, FTK, Microsoft Teams
1mo
Save
Mark Applied
Hide
Incident Responder - Tier 2
Fort Meade, Maryland, United States
$115k-$147k/yr OnsiteFull Time
Evans & Chambers Technology
Evans & Chambers Technology: Develops technology solutions and software for national defense missions.
3+ YOETS/SCI with CI Poly required; 3+ years incident response/forensics/SOC experience; DoD 8570/8140 IAT Level III or CSSP Incident Responder cert (GCIH/GCFA/CySA+); EDR and scripting skills.
NIST SP 800-61, EDR, Python, PowerShell, Bash
1w
Save
Mark Applied
Hide
Night Shift Incident Manager
Bethesda, Maryland, United States
$87k-$100k/yr HybridFull Time
Computer World Services
Computer World Services: Provides IT modernization and cybersecurity solutions for federal government agencies.
4+ YOEBachelor's degree plus 4 years or associate degree plus 6 years related experience; incident response leadership, ITSM, NIH infrastructure, monitoring tools, communication, decision-making, and problem-solving skills required.
SL1, SiteScope, Sunburst, Microsoft Teams, ServiceNow, xMatters, ITIL Framework
3w
Save
Mark Applied
Hide
Cybersecurity Incident and Application Lead
Bethesda, Maryland, United States
HybridFull Time
Unissant
Unissant: Delivers data analytics and cybersecurity services to government agencies.
5+ YOE5–7 years in network/web application/cloud security, Bachelor\u0002s required, Public Trust clearance eligible, experience with incident response lifecycle, Splunk/Tenable/FireEye/IDS/IPS, and strong reporting and communication skills.
Splunk, Tenable, FireEye, IDS/IPS, SIEM, EDR, IAM, Antivirus, Windows, Linux
2d
Save
Mark Applied
Hide
Tier 2 Cyber Incident Responder (Shift Lead)
Beltsville, Maryland, United States
OnsiteFull Time
Internetwork Consulting Services
Internetwork Consulting Services: Provides cybersecurity and IT infrastructure solutions for government agencies.
9+ YOERequires U.S. citizenship, active Secret clearance, bachelor's degree with 9 years' experience or equivalent, and an approved cybersecurity certification. Experience with incident response, SIEM, SOAR, EDR, malware analysis, and threat intelligence required.
ServiceNow, Splunk SOAR, Microsoft Sentinel, Splunk, Elastic, QRadar, Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike, Microsoft Azure, Microsoft Defender for Endpoint and Identity, Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility, Python, PowerShell, BASH, MITRE ATT&CK, D3FEND, Azure SC-900, CCSP, CCSK, GSEC, GCLD, GCIA, SecurityX/CASP+, PRMP, GREM, GEIR, GNFA
5h
Save
Mark Applied
Hide
Cybersecurity Incident and Application Analyst
Bethesda, Maryland, United States
$130k-$145k/yr HybridFull Time
Gunnison Consulting Group
Gunnison Consulting Group: Provides technology solutions and IT consulting to federal agencies.
2+ YOERequires 2–5 years in cybersecurity incident response or related security disciplines, a relevant bachelor's degree, active E|CIH, OSCP, GCIH, and Splunk certification, plus ability to obtain Public Trust clearance.
FireEye, Palo Alto, Splunk, Tenable, Windows, Linux, NIST SP 800-61, Microsoft Defender, CrowdStrike, SentinelOne, AWS, Microsoft Azure, Google Cloud, Cisco
1w
Save
Mark Applied
Hide
Infrastructure Engineer, Incident Response – Bethesda, MD
Bethesda, Maryland, United States
$114k-$152k/yr HybridFull Time
Marriott International
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
5+ YOEBachelor's degree in engineering, computer science, or related field plus 5 years' technology experience; expertise in Windows, RHEL, VMware, AIX, CI/CD, security protocols, automation, and scripting.
Windows, AIX, Red Hat Enterprise Linux (RHEL), VMware, vCenter, ESXi Hypervisor, Hardware Management Console (HMC), Git, Docker Trusted Registry, Artifactory, HashiCorp Vault, Maven, SSL, SAML, LDAP, Ansible, PowerShell, VB, ShellScript
3w
Save
Mark Applied
Hide
Cybersecurity Analyst, Incident Responder
Bethesda, Maryland, United States
HybridFull Time
Digital Global Connectors
Digital Global Connectors: Provides cybersecurity, engineering, and compliance services to federal agencies.
4+ YOEBachelor's degree and 4+ years incident response experience; US citizenship and ability to obtain Tier 2 Public Trust; expertise with SIEM/EDR/XDR, digital forensics, malware analysis, and incident documentation.
Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, CrowdStrike Falcon, Palo Alto Cortex XDR, Trellix, Cisco Secure, Wireshark, Velociraptor, SIEM, EDR, XDR, Microsoft Office Suite, ServiceNow, Jira
2mo
Save
Mark Applied
Hide
Tier 2 Shift Lead / Secret
Beltsville, Maryland, United States
$104k-$166k/yr OnsiteFull Time
Peraton
Peraton: Provides advanced technology and mission support for government agencies.
4+ YOERequires US citizenship and active Secret clearance; degree plus multiple years experience (or equivalent experience); must hold or obtain specified cybersecurity certifications; experience with incident response, SOAR, SIEM, EDR, cloud security, malware analysis, and threat intelligence.
ServiceNow, Splunk SOAR, Microsoft Sentinel, Splunk, Elastic, QRadar, Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike, MITRE ATT&CK, D3FEND, Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility, Microsoft Azure, Python, PowerShell, BASH
2w
Save
Mark Applied
Hide
Engineering Manager, Rapid Response Assignment - US
Massachusetts or Austin or Maryland
RemoteFull Time
VulnCheck
VulnCheck: Provides real-time vulnerability and exploit intelligence data.
5+ YOE5+ years managing software engineering teams, cybersecurity or vulnerability management experience preferred, strong backend/API/cloud knowledge (AWS preferred), experience with distributed systems and incident response.
AWS, CVE, NVD, KEV, ETL, APIs, AI, LLM
3w
Save
Mark Applied
Hide
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Baltimore, Maryland, United States
OnsiteFull Time
OneMain Financial
OneMain FinancialNYSE: OMF: Provides personal loans and credit cards to nonprime consumers.
8+ YOE8+ years cybersecurity experience with 6+ years SOC experience; bachelor\u0002s degree or equivalent; 2+ DFIR/forensics years; requires multiple certifications (e.g., GCFA, GCIH, CISSP); deep expertise in enterprise incident response, detection engineering, and threat hunting.
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, Bash, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps, Elastic, EDR/XDR, NDR, SIEM, SOAR, IDS/IPS, WAF, firewalls, VPN, DNS, DHCP, proxy, CASB, DLP, IAM, PAM, Kubernetes, Azure, AWS, Microsoft 365, Microsoft Entra ID, VMware, Hyper-V
1mo
Save
Mark Applied
Hide
Director, Cyber Defense
Virginia or Research Triangle Park or Atlanta or New York City or Dallas or Pennsylvania or South Carolina or Maryland or Florida or Louisiana or Illinois
$201k-$376k/yr RemoteFull Time
Kyndryl
KyndrylNYSE: KD: Manages and modernizes mission-critical IT infrastructure systems.
12+ YOE5+ Mgmt12+ years in cybersecurity operations/incident response/threat intelligence with 5+ years senior leadership over distributed teams; experience operationalizing threat intelligence into detection and defense; detection engineering and incident response expertise.
MITRE ATT&CK, SIEM, SOAR, Microsoft, Google, Amazon, Skillsoft
2mo
Save
Mark Applied
Hide
Cybersecurity Operations Analyst (Muntinlupa City, National Capital Region (NCR), PH, 1781)
Muntinlupa or Manila or Columbia
OnsiteFull Time
W. R. Grace
W. R. Grace: Manufacturer of specialty chemicals and high-performance catalyst technologies.
2+ YOE2+ years in cybersecurity (incident response/SOC) required; 3+ years IT/network experience preferred. Experience with SIEM, EDR/XDR, Email Security, familiarity with MITRE ATT&CK, incident response skills, on-call availability, and strong communication.
SIEM, EDR, XDR, Email Security, MITRE ATT&CK, LinkedIn Learning
3mo
Save
Mark Applied
Hide
Senior Security Officer
Baltimore, Maryland, United States
OnsiteFull Time
University of Maryland Medical System
University of Maryland Medical System: Operates hospitals and clinics providing comprehensive medical healthcare services.
Seasoned security leader with risk management, policy development, audits, incident response, and team supervision experience.
Security monitoring systems, Risk assessment tools, Incident reporting software
1mo
Save
Mark Applied
Hide
SOC Analyst
Crownsville, Maryland, United States
OnsiteFull Time
DMI
DMI: Provides end-to-end digital transformation and managed IT services.
Monitor, detect, and analyze threats; perform threat hunting, triage incidents, develop SIEM rules, support incident response; bachelor's in CS/IS/engineering/business preferred and relevant security certifications.
Wireshark, VirusTotal, Splunk, Python, PowerShell, VBScript
1mo
Save
Mark Applied
Hide
Cybersecurity & Privacy Technology Manager
Baltimore, Maryland, United States
$152k-$173k/yr HybridFull Time
University System of Maryland
University System of Maryland: Managing and coordinating Maryland's public university system and institutions.
3+ YOEBachelor's in cybersecurity/IT or equivalent, 3+ years cybersecurity experience with responsibility in areas like vulnerability management, threat intelligence, SOC support, incident response, or security tool operations.
EDR, SIEM, vuln scanner, ISAC, SOC, Microsoft, Google, Apple, ticketing workflow