Associate Principal Incident Responder

Clutch Canada

United States

On-site

USD 139,500 - 170,500

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first culture
Comprehensive benefits
Equity package

Job summary

Dragos is seeking an Associate Principal Incident Responder to lead OT incident response investigations and advance customer IR maturity. This role combines hands-on investigations with high-impact consulting across remote environments.

You will guide incident response engagements as Incident Commander, conduct post-incident reviews, develop advisory services, and mentor team members while traveling up to 40% domestically and internationally.

Qualifications

  • 8+ years hands-on incident response and digital forensics experience.
  • Proven experience in IC SS/OT cybersecurity with knowledge of industrial architecture, threat landscapes, vulnerabilities, and frameworks.
  • Leads end-to-end investigations and correlates events across data types.
  • Strong incident management and customer-facing communication skills.
  • Consulting experience translating technical depth into strategic guidance.
  • Ability to work independently and remotely with distributed teams.
  • Willingness to travel up to 40% (domestic and some international).

Responsibilities

  • Lead and execute incident response engagements for OT customers as Incident Commander across onsite and remote environments.
  • Conduct post-incident reviews and root-cause analysis, updating playbooks and procedures.
  • Develop advisory services including planning workshops, maturity assessments, and tabletop exercises.
  • Manage customer relationships across onboarding and strategic advisory engagements.
  • Contribute to research, threat analysis, and thought leadership that influence Dragos methodology.
  • Mentor teammates and act as a technical escalation point for operational excellence.
  • Drive delivery accountability for quality, timeliness, and utilization; coordinate with internal teams.

Skills

Incident response
Digital forensics
OT/ICS cybersecurity
Incident management
Remote work
Travel readiness

Job description

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.

About the Role

Our Professional Services team is hiring an Associate Principal Incident Responder to lead Operational Technology (OT) incident response investigations and advance customer OT IR maturity. This is primarily an incident response role with a strong consulting component: you will lead active response engagements and deliver advisory work, including maturity assessments, incident response planning workshops, tabletop exercises, retainer onboarding, and purple team engagement. You will be responsible for supporting improvements to the Dragos IR methodology. You will represent Dragos as a thought leader through community engagement. This role suits practitioners who are equally strong at executing investigations and advising customers on strategy, and who treat incident response planning and maturity work as core expertise rather than a secondary responsibility.

Responsibilities
  • Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, compromise assessments, and on-call response across onsite and remote environments.
  • Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks, standard operating procedures, and response methodologies
  • Develop and deliver advisory services including incident response planning workshops, maturity assessments, playbook design, and tabletop exercises that advance customer readiness.
  • Manage customer relationships across onboarding, strategic advisory engagements, and stakeholder communication to align response capabilities with evolving business risk.
  • Contribute to research, threat analysis, and thought leadership (whitepapers, webinars, presentations) that influence Dragos methodology and training.
  • Mentor and develop teammates through hands-on training and incident guidance; serve as technical escalation point and role model for operational excellence.
  • Drive delivery accountability for quality, timeliness, and utilization; partner with internal teams on service expansion, scalability improvements, and represent Dragos mission to customers and industry.
Qualifications
  • 8+ years of hands-on incident response and digital forensics experience with proficiency in at least two forensics domains (network, hardware, memory, disk) -- methodology is more important than tool specialization.
  • Proven experience in IC SS/OT cybersecurity including knowlege of industrial architecture, threat landscapes, vulnerabilities, and applicable frameworks and standards.
  • Proven ability to lead end-to-end investigations, correlate events across multiple data types, and uncover threats through methodical analysis and pivoting.
  • Proven incident management and communication ability: able to manage coordination during incidents, guide customers calmly and confidently through high-pressure situations, and author customer-facing documentation, playbooks, and executive briefings.
  • Consulting and advisory experience translating technical depth into strategic customer guidance, incident response planning, and recommendations for advancing incident readiness and response maturity.
  • Ability to work independently and remotely while coordinating effectively across distributed teams.
  • Willingness to travel up to 40% (domestic and some international),
Compensation
  • Salary: $155,000
  • Competitive Equity Package
  • Comprehensive Benefits Plan

#LI-JF1 #LI-REMOTE

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Principal Incident Responder
Associate Principal Incident Responder

Dragos, Inc. • United States

On-site
USD 131,000 - 179,000
Principal Resident Engineer, IC/OT Cybersecurity (Secret)
Principal Resident Engineer, IC/OT Cybersecurity (Secret)

Dragos, Inc. • Washington

On-site
USD 155,000
Competitive Equity Package
Comprehensive Benefits Plan
Senior OT Incident Response Lead & Advisory
Senior OT Incident Response Lead & Advisory

Clutch Canada • United States

On-site
USD 155,000
Remote-first culture
Comprehensive benefits
Equity package
Associate Principal Consultant - ICS/OT Cybersecurity
Associate Principal Consultant - ICS/OT Cybersecurity

careers.allegiscyber.com - Jobboard • United States

On-site
USD 150,000
Competitive Equity Package
Comprehensive Benefits Plan
Associate Principal Resident Engineer (Federal)
Associate Principal Resident Engineer (Federal)

Socket.dev • Houston (TX)

On-site
USD 134,000 - 182,000
Competitive Equity Package
Comprehensive Benefits Plan
Associate Principal Resident Engineer (Federal)
Associate Principal Resident Engineer (Federal)

Dragos, Inc. • Houston (TX)

On-site
USD 134,000 - 155,000
Competitive Equity Package
Comprehensive Benefits Plan
Lead OT Incident Responder & Advisory Strategist
Lead OT Incident Responder & Advisory Strategist

Dragos, Inc. • United States

On-site
USD 140,000 - 210,000
Equity package
Principal Field Operations Engineer - Federal
Principal Field Operations Engineer - Federal

Dragos, Inc. • Lennox Park (MD)

Hybrid
USD 149,000 - 182,000
Competitive Equity Package
Comprehensive Benefits Plan
Director, Engineering
Director, Engineering

Dragos, Inc. • Northern (KY)

Hybrid
USD 180,000 - 280,000
Equity package
Remote OT Incident Responder & IR Advisory Lead
Remote OT Incident Responder & IR Advisory Lead

Dragos, Inc. • United States

On-site
USD 131,000 - 179,000