NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended detection and response (MXDR), attack surface management (ASM), breach and attack simulation (BAS), and advisory services fortify your cybersecurity across both offense and defense. AI-driven intelligence in our Nopal360° platform, our NopalGo mobile app, and our proprietary Cyber Intelligence Quotient (CIQ) lets anyone quantify, track, and visualize their cybersecurity posture in real-time. Our service packages, which are each tailored to a client’s needs and budget, and external threat analysis, which provides critical intelligence at no-cost, help to democratize cybersecurity by making enterprise-grade defenses and security operations available to organizations of all sizes. NopalCyber lowers the barrier to entry while raising the bar for security and service.
Job Description
RoleOverview
Weare seeking a highly skilled and proactive Senior Incident Response Analyst to join our security operations function. In this role, you will lead andsupport the detection, investigation, containment, and remediation of securityincidents across enterprise and cloud environments. You will work closely withSOC analysts, threat intelligence, engineering, IT, legal, privacy, andbusiness stakeholders to ensure timely and effective response to threats whilestrengthening the organization’s overall security posture.
Thisrole requires strong technical depth, sound incident handling judgment, and theability to operate calmly under pressure in high-impact security situations.
KeyResponsibilities
- Leadend-to-end incident response activities, including triage, investigation,containment, eradication, and recovery.
- Analyzesecurity alerts, logs, telemetry, endpoint artifacts, network traffic,cloud audit trails, and identity events to determine impact and scope.
- Performroot cause analysis and produce clear incident reports with actionableremediation recommendations.
- Coordinateincident handling across teams such as SOC, infrastructure, cloud,application, identity, and legal/compliance.
- Supportforensics and evidence preservation activities while maintainingchain-of-custody practices.
- Developand improve incident response playbooks, SOPs, escalation workflows, andresponse standards.
- Identifyattack patterns, adversary behaviors, and control gaps using threatintelligence and detection engineering techniques.
- Collaboratewith engineering teams to improve detection coverage, alert fidelity, andresponse automation.
- Leadpost-incident reviews and drive corrective actions to reduce repeatincidents and business risk.
- Participatein on-call rotation and support major security incidents when required.
- Mentorjunior analysts and contribute to knowledge sharing and operationalmaturity.
RequiredQualifications
- Bachelor’sdegree in Cybersecurity, Computer Science, Information Technology, or arelated field, or equivalent practical experience.
- 5to 8 years of experience in cybersecurity, with significant exposure toincident response, SOC operations, digital forensics, or securityengineering.
- Stronghands-on experience in investigating endpoint, email, identity, cloud, andnetwork security incidents.
- Solidunderstanding of attacker techniques, MITRE ATT&CK, malware behavior,privilege escalation, lateral movement, and persistence methods.
- Proficiencyin analyzing logs and telemetry from tools such as SIEM, EDR/XDR, IDS/IPS,firewalls, proxy, IAM, cloud security platforms, and DLP systems.
- Experiencewith Windows and Linux environments, including command-line analysis andbasic scripting.
- Familiaritywith cloud platforms such as Azure, AWS, or GCP.
- Strongreport writing, communication, and stakeholder management skills.
- Abilityto work independently, prioritize under pressure, and make sound decisionsduring active incidents.
- Certificationssuch as GCIH, GCFA, GCFE, CEH, Security+, Azure Security Engineer,or equivalent.
- Experiencewith incident response automation, SOAR, or scripting using Python,PowerShell, Bash, or similar.
- Exposureto malware analysis, memory analysis, forensic tooling, or reverseengineering concepts.
- Experiencesupporting regulated environments such as financial services, healthcare,enterprise SaaS, or large-scale cloud deployments.
- Familiaritywith Zero Trust, identity security, container security, and moderndetection engineering practices.
- Experienceworking in high-scale or globally distributed environments.
- Stronganalytical and investigative mindset
- Highsense of ownership and accountability
- Clearwritten and verbal communication
- Abilityto remain effective during high-severity incidents
- Collaborationacross technical and non-technical teams
- Attentionto detail and evidence-based decision making
- Continuousimprovement and process discipline
- Participationin on-call rotation, flexible working hours & travel to client location, off-hours support forcritical incidents.
- Comfortableoperating in a fast-paced, collaborative, and security-sensitiveenvironment.