Office of the Chief Information Officer
Security Operations and Incident Response Lead
Lakewood, Colorado, United States · Washington, District of Columbia, United States · Kansas City, Missouri, United States · Raleigh, North Carolina, United States · Fort Worth, Texas, United States · Tacoma, Washington, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Lead / management
- Stated salary
- $127,829 – $187,093 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 30 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Summary
As a Security Operations and Incident Response Lead, you will act as the Cyber Incident Commander for any serious IT security incidents. Location of position: The Office of the Chief Information Security Officer is responsible for delivering secure and exceptional technology solutions and experiences to GSA. Position can be filled in any of the following locations: Kansas City, MO; Fort Worth, TX; Washington, DC; Tacoma, WA; Lakewood, CO or Raleigh, NC.
Duties
We are currently filling two vacancies, but additional vacancies may be filled as needed. As a Security Operations and Incident Response Lead you will perform the following duties: Leads GSA's combined Incident Response/Security Operations Center (SOC) program, provides incident handling and digital forensics services (including forensics in virtualized environments), which includes documenting, tracking, and reporting all security incidents in accordance with GSA policy and Cybersecurity and Infrastructure Security Agency (CISA). Leads the GSA SOC and GSA Threat Hunting team to direct and analyze internal threat hunts and ensure ongoing monitoring for security alerting across the GSA Enterprise; works to generate alerting and hunting processes to the benefit of the GSA Enterprise; automates repetitive processes as necessary; monitors and ensures alerting from GSA Data Loss Prevention tools (Zscaler, Cloudlock etc.). Provides security consulting and threat hunt support for GSAIT information systems and emerging IT and IT Security initiatives, including but not limited to: Cloud computing, bring-your-own-device (BYOD), Virtual Desktop Infrastructure, mobile devices, Remote Access Systems, Mobile Computing Platforms, Active Directory, System Virtualization, physical access control systems (building security), Zero Trust and identity and access management solutions; ensuring new technologies are implemented in support of GSA risk management strategy and shaping ongoing incident response and recovery policies. Provides technical expertise and advice on the restructuring and/or re-architecting of GSA networks to ensure the remediation of identified security risks to provide the maximum protection of various types of sensitive Government data. Supports automation and integrations as well as deploys and pilots new Security toolsets in support of GSA Enterprise security operations.
Qualifications
To evaluate your qualifications, your resume must clearly demonstrate how you meet the specialized experience described below. Your resume must not exceed two pages. To ensure your qualifications can be fully evaluated, we recommend including the following information: Name, address, telephone number, email address; Job Title (if Federal Service, provide series and grade; if not in GS plan, provide GS equivalent grade); Relevant work experience—should include employer name, job title, start and end dates (month/year), the number of hours worked per week and descriptions that explain how you meet the required qualifications in the job announcement. Education, certifications or licensures—If the job announcement requires any education, certifications or licensures, make sure to include the required information and any required documents like transcripts. Your resume should contain enough information to make a valid determination that you fully meet experience requirements for each grade level you are applying to. If you do not provide enough information for us to determine your qualifications, you may be rated ineligible If you have volunteered your service through a National Service program (e.g., Peace Corps, Americorps), we encourage you to apply and include this experience on your resume. The GS-14 salary range starts at $127,829 per year. If you are a new federal employee, your starting salary will likely be set at the Step 1 of the grade for which you are selected. Applicants applying for the GS-14 grade level must meet the following requirements: Have IT-related experience demonstrating EACH of the 9 competencies AND one year of specialized experience equivalent to the GS-13 level in the Federal service as described below: IT SPECIALIST COMPETENCY REQUIREMENTS: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. Decision Making - Makes sound, well-informed, and objective decisions; perceives the impact and implications of decisions; commits to action, even in uncertain situations, to accomplish organizational goals; causes change. Information Management - Identifies a need for and knows where or how to gather information; organizes and maintains information or information management systems. Interpersonal Skills - Shows understanding, friendliness, courtesy, tact, empathy, concern, and politeness to others; develops and maintains effective relationships with others; may include effectively dealing with individuals who are difficult, hostile, or distressed; relates well to people from varied backgrounds and different situations. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. Teamwork - Encourages and facilitates cooperation, pride, trust, and group identity; fosters commitment and team spirit; works with others to achieve goals. Technical Competence – Uses knowledge that is acquired through formal training or on-the-job experience to perform one's job; works with, understands, and evaluates technical information related to the job; advises others on technical issues. SPECIALIZED EXPERIENCE REQUIREMENTS: Specialized experience is experience performing advanced information technology security work (e.g. engineering secure networks, stopping active cyber-attacks, auditing complex system codes, and managing enterprise risk) to protect critical digital assets and data. This experience must also include: Planning, developing, or maintaining an organization-wide information security program; Implementing and/or evaluating security controls across enterprise systems and cloud-based environments; Conducting security reviews such as system assessments, vulnerability identification, and corrective action tracking; and Providing technical guidance to leadership, supporting incident response or continuity operations, and collaborating across teams to resolve complex security issues.
Education
There is no substitution of education for experience at the GS-14 level.
Requirements
- US Citizenship or National (Residents of American Samoa and Swains Island)
- Meet all eligibility requirements within 30 days of the closing date.
- Register with Selective Service if you are a male born after 12/31/1959
- Direct Deposit of salary check to financial organization required.
Similar jobs
- Principal, Incident Response Lead | Principal, Incident Response LeadVerisk Verisk · Jersey City, NJ, United StatesFirst seen today
- Incident Response LeadWhoop · Boston, MAFirst seen 3d ago
- Senior/Staff Security Engineer, Incident Response Grow Therapy · RemoteFirst seen 3d agoremote
- Incident Response LeadLeidos · 2 LocationsFirst seen 3d ago
- Incident Response ManagerCrowe · 5 LocationsFirst seen 3d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job