← all jobs

NIH - Incident Response Lead

Work from home Full-time role Hiring

cFocus Software seeks a Incident Response Lead to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance. Qualifications:Public Trust Clearance B.S. Computer Science, Information Technology, or a related field 7+ years leading enterprise incident response activities. Experience supporting federal cybersecurity programs and Security Operations Centers. Experience coordinating enterprise cyber investigations involving cloud and hybrid environments. Experience implementing NIST incident response methodologies. Active GCIH, GCFA, GNFA, CISSP, CEH, CySA+, Security+, CISM, or CCSP Duties:Lead enterprise cybersecurity incident response operations across NIH information systems. Direct technical response activities throughout the incident response lifecycle including preparation, identification, containment, eradication, recovery, and post-incident activities. Coordinate response efforts for high-impact cybersecurity incidents affecting enterprise infrastructure, cloud services, applications, and data. Serve as the primary technical advisor during cybersecurity incidents and major security events. Manage incident prioritization, escalation, resource coordination, and operational communications. Ensure incident response activities comply with NIH policies, HHS guidance, NIST standards, and federal cybersecurity requirements. Lead technical investigations involving malware infections, unauthorized access, insider threats, ransomware, phishing campaigns, data exfiltration, and advanced persistent threats (APTs). Coordinate root cause analysis and determine attack vectors, affected assets, and operational impact. Analyze indicators of compromise (IOCs), indicators of attack (IOAs), adversary tactics, techniques, and procedures (TTPs), and attack patterns. Coordinate evidence collection and preservation activities supporting investigations. Validate containment strategies and recovery actions. Ensure accurate documentation of incident timelines, findings, corrective actions, and lessons learned. Coordinate with Security Operations Center analysts during incident detection and response activities. Oversee incident triage, escalation procedures, and operational communications. Direct coordination between cybersecurity engineers, cloud engineers, infrastructure teams, system owners, ISSOs, and application administrators. Support continuous monitoring and operational readiness activities. Develop executive incident reports, after-action reports, technical findings, and corrective action recommendations. Prepare briefings for Government leadership regarding significant cybersecurity events. Maintain incident response metrics, trends, dashboards, and performance reporting. Ensure timely reporting in accordance with federal cybersecurity reporting requirements.

More open positions

NIH - Vulnerability Analyst

Work from home Full-time role

NIH - ISSO

Work from home Full-time role

NIH - Program Manager

Work from home Full-time role

Kyrgyz-Speaking Translator

Work from home Full-time role

QA Lead

Work from home Full-time role

Claims Examiner I

Work from home Full-time role

Senior Manager, Customer Supply Chain – Global Retail Partnerships & Forecasting (London/Remote)

Work from home Full-time role

Senior Data Engineer

Work from home Full-time role

Remote GRC (Governance, Risk, and Compliance) and Data Privacy Consultant

Work from home Full-time role

PPC Specialist Needed – Google resetup + Management (B2B SaaS, UK) - Contract to Hire

Work from home Full-time role

Data Entry Pharmacy Technician – Remote & On‑Site Long‑Term Care Support at careerzynith (Dallas, TX)

Work from home Full-time role

Experienced Full Stack Data Entry Specialist – Virtual Operations & Data Management

Work from home Full-time role

B2B National Sales Support Representative

Work from home Full-time role

National Consultant on Women’s Political Participation Community Support , Kyiv, Ukraine,SSA

Work from home Full-time role

Senior Engineer, Full Stack

Work from home Full-time role

Marketing Data Analyst – CRM & Personalization

Work from home Full-time role

Marketing Director (Remote)

Work from home Full-time role

[Remote] Supply Chain Analyst

Work from home Full-time role

[Remote] Senior Financial Planner

Work from home Full-time role

Remote Part‑Time Data Entry Clerk & Administrative Assistant – Full‑Remote, Flexible Schedule, Competitive Pay & Comprehensive Benefits

Work from home Full-time role

Junior Account Executive - SMB (Hybrid)

Work from home Full-time role