Enable job alerts via email!

Incident Responder

911Cyber

Old Toronto

On-site

CAD 70,000 - 110,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled cybersecurity incident responder to lead investigations and coordinate responses to security incidents. In this dynamic role, you will utilize your expertise in incident management and forensic analysis to protect critical systems and data. You will work closely with cross-functional teams to implement effective containment and remediation strategies while ensuring compliance with industry standards. This position offers a unique opportunity to make a significant impact in the ever-evolving field of cybersecurity, providing you with the chance to grow your skills and advance your career in a supportive environment.

Qualifications

  • Preferred certifications include GCIH, CISSP, and CEH.
  • Strong background in incident management and forensic analysis is essential.

Responsibilities

  • Lead investigation and response efforts for cybersecurity incidents.
  • Collaborate with teams to contain and remediate security breaches.
  • Maintain documentation of incident response activities.

Skills

Incident Management
Cybersecurity Incident Response
Forensic Analysis
Communication Skills
Documentation

Education

Relevant industry certifications

Tools

Splunk
IBM QRadar
CrowdStrike Falcon
Wireshark
Autopsy

Job description

Responsible for leading the investigation and response efforts for cybersecurity incidents. They coordinate with other SOC team members, IT staff, and external stakeholders to contain, mitigate, and remediate security breaches effectively.

Key Responsibilities:
  1. Incident Management: Lead the identification, assessment, and prioritization of cybersecurity incidents, adhering to established protocols and escalation procedures.
  2. Investigation: Conduct in-depth analysis of security breaches, employing forensic tools and methodologies to gather evidence, determine the root cause, and ascertain the extent of the compromise.
  3. Response Coordination: Collaborate closely with cross-functional teams, including SOC analysts, IT administrators, legal advisors, and law enforcement agencies, to orchestrate timely and effective response actions.
  4. Containment and Mitigation: Implement containment measures to prevent further proliferation of security threats, while deploying mitigation strategies to minimize the impact on critical systems and data.
  5. Remediation: Develop and execute remediation plans to restore affected systems and infrastructure to a secure state, ensuring compliance with regulatory requirements and industry standards.
  6. Communication: Serve as a primary point of contact for communication with internal stakeholders, external vendors, and regulatory bodies, providing regular updates on incident status, response efforts, and post-incident reviews.
  7. Documentation: Maintain comprehensive documentation of incident response activities, including incident reports, forensic findings, and lessons learned, to facilitate continuous improvement and knowledge sharing within the organization.
Minimum Qualifications:
  • Relevant industry certifications are preferred such as:
    • Certified Incident Handler (GCIH)
    • Certified Information Systems Security Professional (CISSP)
    • Certified Ethical Hacker (CEH)
    • GIAC Certified Forensic Analyst (GCFA)
    • Certified Cloud Security Professional (CCSP)
    • CompTIA Cybersecurity Analyst (CySA+)
    • EC-Council Certified Incident Handler (ECIH)
    • CompTIA Security+
Tools:
  • Security Information and Event Management (SIEM) Systems:
    • Splunk
    • IBM QRadar
    • LogRhythm
    • ElasticSIEM
  • Endpoint Detection and Response (EDR) Platforms:
    • CrowdStrike Falcon
    • SentinelOne
    • Carbon Black
  • Network Traffic Analysis:
    • Wireshark
    • Zeek (formerly Bro)
    • tcpdump
  • Forensic Analysis Tools:
    • Autopsy
    • The Sleuth Kit (TSK)
    • Volatility
  • Threat Intelligence Platforms (TIP):
    • Anomali ThreatStream
    • ThreatConnect
    • Recorded Future
  • Malware Analysis Tools:
    • VirusTotal
    • Cuckoo Sandbox
    • IDA Pro
  • Vulnerability Scanning Tools:
    • Nessus
    • Qualys
    • Rapid7 InsightVM
  • Email Security Gateways:
    • Proofpoint
    • Mimecast
    • Cisco Email Security
Working Conditions: This role may require occasional on-call duty and availability during non-business hours to respond to emergent cybersecurity incidents.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Incident Response Analyst

Coalition Inc

Remote

CAD 60,000 - 100,000

30+ days ago

Senior Incident Response Analyst

Coalition, Inc.

Remote

CAD 60,000 - 100,000

30+ days ago

Cybersecurity Incident Response Analyst

Hitachi ABB Power Grids

Quebec

Remote

CAD 60,000 - 90,000

30+ days ago