ICS Nett, Inc is hiring a Cyber Incident Responder to join our dynamic team day shift. This is a hybrid position with 2-3 days onsite every week in Hanover, MD
The candidate will provide as a front-line defender, detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.
The Cyber Incident Responder will play an important role responsible for executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Incident Responder will collaborate with cross-functional IT and security teams to:
ICS Nett, Inc is hiring a Cyber Incident Responder to join our dynamic team this is day shift with 4x 10 hours to provide support. This is an on-site position at Quantico, VA
The candidate will provide as a front-line defender, detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.
The Cyber Incident Responder will play an important role responsible for executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Incident Responder will collaborate with cross-functional IT and security teams to:
ICS Nett, Inc is hiring a highly skilled and experienced Senior ACAS (Assured Compliance Assessment Solution) Engineer to join our dynamic team. The successful candidate will be responsible for the implementation, maintenance, and optimization of our ACAS infrastructure. This role is critical for ensuring the security and compliance of our information systems with DoD and other federal regulations. The ideal candidate will have a strong background in cybersecurity, vulnerability management, and network security. This position will support our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.
The Assured Compliance Assessment Solution (ACAS) Engineer is a critical role responsible for the implementation, maintenance, and operational support of the ACAS suite of tools within the organization. This position focuses on ensuring continuous vulnerability scanning, configuration compliance assessments, and reporting capabilities to maintain a strong security posture and adherence to relevant security policies and regulations (e.g., NIST, DISA STIGs, CIS Benchmarks). The ACAS Engineer will collaborate with other cybersecurity professionals, system administrators, and IT staff to identify vulnerabilities, track remediation efforts, and improve overall security.
Responsibilities:
Work Environment and Physical Demands:
The selected candidate will perform robust network security monitoring and proactively identify potential threats across our enterprise infrastructure. This role is critical for defending mission systems, conducting in-depth traffic and vulnerability analysis, and maintaining a strong security posture in support of Department of War (DOW) missions.
The Cyber Defense Analyst (Threat Hunter) is a vital role responsible for performing comprehensive network security monitoring and proactive threat hunting during swing-shift, weekend, and holiday coverage windows. This position focuses on safeguarding the network through continuous traffic analysis, vulnerability and wireless scanning, and leveraging enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Analyst will collaborate with cross-functional IT and security teams to:
ICS Nett, Inc is seeking a highly skilled Zero Trust Architect with a specialized focus on Enterprise Architecture and Identity, Credential, and Access Management (ICAM). The successful candidate will be the primary technical authority for designing, integrating, and maturing the enterprise Zero Trust Architecture (ZTA) in support of critical Department of War (DoW) missions. This role requires a strategic thinker who can develop a holistic enterprise-level security architecture grounded in Zero Trust principles. The position will be responsible for ensuring that ICAM is the central pillar of our security posture, protecting critical infrastructure and CUI within Impact Level 5 (IL5) environments. The ideal candidate will possess deep expertise in the DoW Zero Trust Strategy, enterprise architecture frameworks, and the implementation of advanced ICAM solutions. This position will support our DCSA Contract based in Quantico VA.
Remote flexibility available! Telework offered with a requirement to be onsite up to 2 days a week at Quantico, VA.
As a Zero Trust Architect, you will be a critical leader in our transition from traditional perimeter-based security to a comprehensive, identity-driven security model. Your primary focus will be on the enterprise architecture of our Zero Trust ecosystem, ensuring all security solutions and pillars — User, Device, Network, Application/Workload, Data, Visibility, and Automation/Orchestration — are cohesive, scalable, and fully integrated. You will leverage your expertise in Enterprise Architecture to develop and maintain the overall structure of the ZTA, while using your deep knowledge of ICAM to enforce granular, dynamic access control across the enterprise. This role involves close collaboration with mission owners, cybersecurity professionals, and IT staff to build a resilient and unified security framework that adheres strictly to the DoW Zero Trust Strategy.
The Cyber Defense Auditor uses a documented test plan and methodology and a variety of approved tools to conduct penetration tests and red/blue team operations for customer systems supporting the Defense Counterintelligence and Security Agency (DCSA) Hanover, MD.
Responsibilities:
ICS Nett, Inc is hiring a Cyber Incident Responder to join our dynamic team for swing shift from 2.00 PM to Midnight to provide support, including weekends and holidays, on rotation. This is an on-site position at Hanover, MD.
The candidate will serve as a front-line defender, detecting, triaging, containing, and eradicating cyber threats across our enterprise infrastructure. This role is critical for minimizing the impact of security incidents, coordinating response actions, and preserving forensic evidence in support of Department of Defense (DoD) missions.
Position Description
The Cyber Incident Responder will play an important role in executing the full incident response lifecycle during swing-shift, weekend, and holiday coverage windows. This position focuses on detecting and responding to security incidents in real time, performing containment and eradication actions, and coordinating recovery efforts using enterprise tools such as SIEM, SOAR, CrowdStrike, CyberArk, and Endpoint Security Suite (ESS).
The Incident Responder will collaborate with cross-functional IT and security teams to:
Maintain incident response playbooks and ensure high operational readiness during all covered hours
Required Skills
ICS Nett, Inc is seeking a cleared Cybersecurity Cloud Engineer with strong AWS infrastructure skills to join our team. In this role, you will help implement, maintain, and monitor security controls across our secure cloud environments. Working closely with senior engineers and DevOps teams, you will configure secure AWS architectures, deploy Infrastructure-as-Code (IaC), and monitor cloud telemetry for potential threats. Experience with Elastic SIEM (Elastic Security) is highly valued and considered a strong bonus for this position.
Please note: This position requires compliance with Department of Defense (DoD) Directive 8570 and/or DoD Manual 8140 cyber workforce requirements.
Key Responsibilities:
Cloud Security Configuration: Configure and maintain AWS VPC designs, subnets, security groups, and Network Access Control Lists (NACLs) according to established security baselines and DoD STIGs.
Security Monitoring & Triage: Monitor security alerts using AWS native tools and SIEM platforms, triage potential threats, and assist in incident response and remediation within cleared environments.
SIEM Support & Log Analysis: Assist with monitoring security telemetry and managing cloud logs (CloudTrail, VPC Flow Logs, GuardDuty). Experience working within or connecting logs to Elastic SIEM is a plus.
Vulnerability Scanning: Run vulnerability assessments across cloud assets using tools like AWS Inspector, identify misconfigurations, and coordinate remediation timelines with engineering teams.
Access Management Maintenance: Implement and audit IAM policies, roles, and resource permissions following the principle of least privilege.
Documentation & Compliance: Help maintain technical security documentation and verify that cloud controls meet rigorous defense compliance requirements (such as NIST SP 800-53, FedRAMP, or DoD SRG).
Experience: 3+ years of professional experience in cloud engineering, system administration, or cybersecurity, with a minimum of 1–2 years focused directly on AWS security configurations.
AWS Security Tools: Hands-on experience using core AWS security and monitoring tools, including IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, and KMS.
Infrastructure as Code: Practical experience deploying infrastructure using Terraform or AWS CloudFormation.
Networking Basics: Solid understanding of TCP/IP networking, VPC architecture, routing tables, and firewalls.
Scripting Skills: Ability to write basic automation or remediation scripts using Python or Bash.