Evans & Chambers partners with the US national defense community to create fully integrated, resilient, and innovative digital solutions that enable them to make smart decisions in real-time. We work with our customers on everything from conquering their data to improving and safeguarding IT infrastructure. Our ultimate goal? To enhance our nation's ability to identify, address, and act – no matter what challenges arise.
Position Summary: The Tier 2 Incident Responder – Team Lead performs in-depth investigation, containment, and remediation of security incidents escalated from Tier 1, applying the NIST SP 800-61 incident response life cycle and manages Tier 1 Analysts and Tier 2 Incident Responders.
Clearance: TS/SCI with CI Poly
Location: Ft. Meade, MD (Onsite)
Work Schedule and Conditions: Primary shift assignment within the 24/7/365 coverage model with participation in an on-call rotation for incidents requiring escalation outside normal shift hours.
Duties and Responsibilities: Duties include the following.
- Investigate escalated alerts and incidents through log analysis, malware analysis, and digital forensics, determining scope, root cause, and impact.
- Support execution of containment and eradication actions. Support recovery of affected systems to a known-good, hardened baseline.
- Document incident timelines and findings, create and track POA&M entries to closure and contribute to after-action reviews that feed back into detection content and playbooks.
- Review and remediate findings.
- Provide technical mentorship to Tier 1 Analysts and serve as a secondary escalation point during major incidents or surge conditions.
- Manage personnel workload and daily performance management issues.
Required Education and Experience: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred, or equivalent experience; three to five years of hands-on incident response, digital forensics, or security operations experience.
Required Certifications: DoD 8570/8140 IAT Level III or CSSP Incident Responder certification (e.g., GCIH, GCFA, or CySA+) required; working knowledge of endpoint detection and response (EDR) tooling, packet analysis, and at least one scripting language (e.g., Python, PowerShell, or Bash) preferred.
Salary Range: $130k - $158k Depending on Experience and Shift
All employment opportunities are made without regard to age, race, creed, color, religion, sex national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status or any other basis protected by law.