Incident Response Lead
Parsons Corporation
Linthicum, MD
The Role
This lead position oversees a team conducting high-impact cyber investigations, including host-based and network-based forensic analysis, malware forensics, and memory analysis. Day-to-day responsibilities include guiding intrusion investigations, correlating multi-source data to identify APT activity, ensuring accurate reporting, and refining investigative workflows to meet critical mission objectives.
Skills & Experience
Candidates must hold an active TS/SCI clearance and a GCIH or equivalent certification. A minimum of eight years of hands-on DFIR experience is required, with at least five years focused on network intrusion analysis, malware forensics, and memory analysis, plus three or more years in a supervisory or leadership capacity briefing technical findings.
Who It Suits
This role suits a seasoned DFIR practitioner ready to step into a leadership position within a government-facing environment. Those who enjoy mentoring analysts, driving technical excellence, and working on sophisticated threat investigations in a collaborative, mission-driven team will find this opportunity particularly rewarding.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United States →
Certifications mentioned: GCIH — find training for these on the DFIR Training Finder.





