Cybersecurity Lead Investigator
Washington, DCJobSeen 2w agoStill listed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Washington, DC, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Cybersecurity Lead Investigator leads evidence-driven investigations and technical incident response across enterprise on-premises and cloud environments. The role sets investigative direction, coordinates specialist workstreams, assesses adversary activity and compromise scope, and directs response recommendations while balancing recovery, containment, evidence preservation and business constraints. It also serves as the primary technical contact for complex investigations and communicates findings and decision options to customer and internal stakeholders.
Skills & qualifications
Skills
Qualifications
Full job description
Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Set investigation objectives, hypotheses, priorities and evidence requirements; lead hands-on analysis and specialist workstreams across enterprise on-premises and cloud environments. Contextualise and prioritise findings, correlate disparate evidence and build cohesive incident timelines. Establish what is known, what remains uncertain and what additional collection or analysis is needed. Assess adversary activity, compromise scope and potential data collection or exfiltration; validate key findings and explain the confidence and limitations of conclusions. Direct technical response planning and recommendations to secure enterprise environments, balancing containment and recovery urgency with evidence preservation and customer business constraints. Coordinate execution with customer-authorised teams and relevant specialists. Serve as the primary technical point of contact for complex investigations; brief technical teams, executives, legal, compliance, engineering and other stakeholders with clear objectives, findings and decision options. Identify skill, access, telemetry and resource gaps early; work with incident coordinators and leadership to resolve dependencies, obtain specialist support and escalate delivery risks. Maintain investigative documentation and clear follow-the-sun handovers covering evidence, hypotheses, decisions, risks and next actions; support final reporting and lessons learned. A relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations, AND 5+ years of industry experience. Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions. Ability to correlate and assess evidence from multiple sources, reconstruct incident timelines, evaluate compromise scope and possible exfiltration, and clearly explain findings and uncertainty. Experience directing response activities while balancing rapid recovery, technical dependencies and business impact. Demonstrated ability to lead technical specialists and stakeholders, identify engagement gaps, request appropriate resources and manage investigations using a global follow-the-sun model. Demonstrable customer-facing written and verbal communication, including executive briefings. Flexibility to work non-standard business hours that may include evening, nighttime, weekends, and/or holidays. Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations. Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability. Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information. DART This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. *
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
IT Cybersecurity SpecialistOffice of Inspector General · Washington, DC · $122–158K/yrPosted 2 days agoPosted 2 days ago
SUPV IT CYBERSECURITY SPECIALIST (INFOSEC/NETWORK)Defense Information Systems Agency · Fort Meade, MD · $177–197K/yrPosted 2 days agoPosted 2 days ago
Senior Engineer, Cybersecurity (R5972)Shield AI · Washington, DC · $110–170K/yrPosted 2w agoPosted 2w ago
Cybersecurity - Information System Security Manager (ISSM)The Boeing Company · Herndon, VA · $140–190K/yrPosted 6 days agoPosted 6 days ago
InvestigatorExecutive Office for U.S. Attorneys and the Office of the U.S. Attorneys · Washington, DC · $102–133K/yrPosted 2w agoPosted 2w ago
You've read the whole posting — now see how you match it.