We are looking for an Incident Responder to join our Security Operations Center (SOC) and lead the response when a security breach occurs. In this role, you will investigate major, complex incidents escalated from Tier-2 analysts, contain active threats, and ensure attackers are fully eradicated from enterprise environments.
Job Description
- Lead security incidents from initial confirmation through successful remediation, executing rapid-containment playbooks under time pressure
- Plan and execute targeted eradication, including removing web shells, persistence mechanisms, rogue admin accounts, and malware payloads
- Partner with IT Infrastructure and Disaster Recovery teams to guide safe, verified restoration of business systems after a breach
- Perform forensic collection on Windows, Linux, and macOS endpoints (memory captures, MFT extraction, and other system artifacts)
- Reconstruct multi-stage attack timelines by correlating telemetry across cloud (AWS/Azure/GCP), identity, network firewall, and application layers
- Conduct behavioral malware analysis to identify IoCs, C2 infrastructure, and attacker capabilities
- Author Root Cause Analysis (RCA) and Post-Incident Reports (PIR) for executive leadership and compliance auditors
- Turn findings from real incidents into automated response playbooks in the SOAR platform
- Maintain strict chain-of-custody and evidentiary standards to support regulatory disclosures, insurance claims, or legal actions
- Participate in the critical incident on-call rotation
Qualifications
- Minimum 4–6+ years of technical cybersecurity experience, including at least 2–3 years dedicated to Digital Forensics and Incident Response (DFIR)
- Proven experience as a primary responder on major incidents (e.g., ransomware, data exfiltration, business email compromise, cloud tenant hijacking)
- Hands‑on experience with forensic tools such as KAPE, Velociraptor, Volatility, FTK Imager, EnCase, or X‑Ways Forensics
- Advanced experience with EDR/XDR platforms (CrowdStrike Falcon, Microsoft Defender for Endpoint, Cortex XDR) for threat hunting, triage collection, and remote isolation
- Strong log analysis skills using Splunk (SPL), Microsoft Sentinel (KQL), or Elastic Security
- Scripting skills in Python, PowerShell, or Bash
- Solid understanding of the MITRE ATT&CK framework and NIST SP 800-61
- Ability to stay calm under pressure, make decisions independently, and communicate clearly with non-technical stakeholders
- Disciplined in following playbooks and documenting every step in ticketing systems
- Preferred certifications: GCIH, GCFA, GCFE, GCDA, or CSIH