Enable job alerts via email!

Cyber Incident Handler – Principal (BHJOB22048_763)

ITmPowered Consulting

Denver (CO)

Remote

USD 80,000 - 130,000

Full time

25 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Cyber Incident Handler to lead incident response efforts and enhance security posture. In this remote role, you will leverage your expertise in forensic analysis and incident management to tackle security breaches effectively. Collaborating with various teams, you'll analyze incidents, develop mitigation strategies, and document findings to improve organizational security. This position offers the opportunity to make a significant impact in a dynamic environment, where your skills will be crucial in protecting sensitive information and ensuring operational continuity. Join a forward-thinking company dedicated to cybersecurity excellence.

Qualifications

  • 10+ years in cybersecurity focusing on incident response or forensics.
  • 7+ years hands-on with forensic software and investigations.
  • Strong communication, leadership, and incident management skills.

Responsibilities

  • Evaluate processes and artifacts for anomalies and unauthorized access.
  • Conduct root cause analysis and develop remediation plans.
  • Document findings and prepare reports for management.

Skills

Digital Processing Platforms Knowledge
Windows OS Expertise
Linux/UNIX Knowledge
Malware Behavioral Analysis
Static Analysis Skills
Reverse Engineering Skills
EDR and Forensics Tools Experience
Excellent Communication Skills
Teamwork in High-Pressure Environments

Education

Master’s Degree
Bachelor’s Degree or 10+ Years Experience

Tools

EnCase
FTK
Nuix
X-Ways
SIEM (e.g., Splunk)

Job description

Join to apply for the Cyber Incident Handler – Principal (BHJOB22048_763) role at ITmPowered Consulting.

**Cyber Security Incident Handler (Principal) – Remote – KAISJP00211866**

The Incident Handler uses incident response, investigative, and forensics skills to determine the extent of a breach, the containment measures required, and the overall response needed. This includes appropriate data collection, preservation, mitigation, remediation requirements, and security improvement plans. The Incident Handler will utilize forensic best practices and provide chain of custody services for criminal investigations (e.g., employee situations, fraud). The role may involve working on different teams depending on the incident type or pre-incident activities.

Essential Functions
  1. Evaluate processes, services, drivers, libraries, binaries, scripts, memory, network traffic, files, emails, and other artifacts for anomalies, security exploitation, and unauthorized access.
  2. Identify attack vectors, social engineering attempts, exploits, malicious code, C2 activity, and persistence mechanisms.
  3. Determine containment controls to halt ongoing attacks on affected resources.
  4. Identify mitigation controls to prevent future attacks.
  5. Analyze to determine breach scope, risk, and impact.
  6. Conduct root cause analysis, develop remediation plans, and coordinate with SMEs for proper execution.
  7. Collaborate with SMEs to determine mitigation strategies and coordinate with affected units.
  8. Collect and preserve digital evidence according to best practices.
  9. Document incident findings, evidence, analysis steps, and prepare reports and recommendations.
  10. Engage management to improve organizational security posture.
  11. Contribute to security infrastructure design based on incident response insights.
  12. Update security policies and procedures routinely.
  13. Focus on preserving uptime and minimizing impact on medical services.
Desired Skills
  • Broad knowledge of digital processing platforms, hardware, OS, applications, and troubleshooting skills.
  • Expertise in Windows OS and working knowledge of Linux/UNIX, Android, iOS.
  • Skills in malware behavioral analysis, static analysis, reverse engineering, and disassembly.
  • Experience with security controls including EDR, forensics tools, SIEM (e.g., Splunk), and others.
  • Excellent communication, documentation, and reporting skills.
  • Ability to lead, respond quickly to security incidents, and manage elevated access responsibly.
  • Teamwork in high-pressure environments.
Preferred Qualifications and Certifications
  • Master’s degree and 10+ years of related experience.
  • 7+ years hands-on with forensic software and investigations.
  • 10+ years in cybersecurity focusing on incident response or forensics.
  • Certifications such as EnCE, GCFE, GCFA, GCIH, GREM, CISA, CISM, or similar.
Qualifications (Minimum 13 of the following)
  • Degree in related field or 10+ years of experience.
  • 15+ years in IT.
  • Multiple OS expertise and forensic artifacts knowledge.
  • Shell scripting skills in multiple languages.
  • Understanding of malware methodologies and network analysis skills.
  • Experience with forensic platforms like EnCase, FTK, Nuix, X-Ways.
  • Strong communication, leadership, and incident management skills.
Logistics
  • Remote work in the US, preferred locations Colorado or Georgia.
  • COVID-19 vaccination and booster required or medical exemption.
  • Pass a background check, drug screen, and employment verification.
  • US citizen or Green Card holder only; no visa sponsorship.
  • W2 employment only; no vendors or sponsorship.
  • Include contact info on resume.

To apply, email your details to Careers@itmpowered.com.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cyber Incident Handler – Principal (BHJOB22048_763)

ITmPowered

Denver

Remote

USD 90,000 - 150,000

30+ days ago

Cyber Incident Handler – Principal (BHJOB22048_763)

ITmPowered Consulting

Atlanta

Remote

USD 80,000 - 120,000

18 days ago

Cyber Incident Handler – Principal (BHJOB22048_763)

ITmPowered

Atlanta

Remote

USD 90,000 - 150,000

30+ days ago

Cyber Incident Handler – Principal (BHJOB22048_763)

ITmPowered

Seattle

Remote

USD 90,000 - 150,000

30+ days ago