Incident Responder

SOClogix

Catonsville (MD)

Hybrid

USD 100,000 - 145,000

Full time

17 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
Annual certification and training

Job summary

SOClogix, Inc. is seeking an experienced Incident Responder to lead cyber incident investigations for managed security clients.

You will triage, contain, eradicate, and recover from breaches while coordinating with client IT teams, legal, insurers, and law enforcement as needed. Your work includes digital forensics across endpoints, servers, cloud environments, and network infrastructure, with malware and memory analysis to define scope and impact.

Qualifications

  • 3+ years in incident response, forensics, or security operations.
  • Hands-on with forensic tools: Velociraptor, KAPE, FTK, Autopsy, X-Ways or similar.
  • Strong knowledge of Windows/Linux forensic artifacts and event logs.
  • Experience with SIEM (OpenSearch, Splunk, Sentinel) and EDR (LimaCharlie, CrowdStrike, SentinelOne).
  • Understanding of MITRE ATT&CK and applying it to investigations.
  • Excellent written and verbal communication, capable of briefing executives.

Responsibilities

  • Lead incident response engagements from triage to remediation and post-incident review.
  • Perform digital forensics across endpoints, servers, cloud, and network.
  • Analyze malware, memory, and logs to determine scope and impact.
  • Contain active threats including ransomware, BEC, data exfiltration, insider threats.
  • Prepare incident reports with timelines, findings, and remediation recommendations.
  • Coordinate with client IT, legal, insurers, and law enforcement as needed.
  • Develop incident response playbooks, runbooks, and escalation procedures.
  • Contribute to post-incident lessons learned and security posture improvements.
  • Support on-call rotation for 24/7 incident response.

Skills

Incident response
Digital forensics
Security operations
Forensic tooling
OpenSearch
Splunk
EDR tooling
MITRE ATT&CK
Executive briefing

Education

GCIH/GCFA/GCFE/GREM/EnCE

Tools

Velociraptor
KAPE
FTK
Autopsy
X-Ways
OpenSearch
Splunk
LimaCharlie
CrowdStrike
SentinelOne
Azure AD
M365
AWS CloudTrail

Job description

Security Operations Remote (US) / Catonsville, MD Full-Time $100K–$145K DOE

About the Role

SOClogix is seeking an experienced Incident Responder to lead and execute cybersecurity incident investigations for our managed security clients. You'll be the frontline defender when a breach occurs - conducting triage, containment, eradication, and recovery operations while coordinating with client IT teams and, when necessary, law enforcement. This is a high-impact role that requires composure under pressure, deep technical skills, and the ability to communicate clearly with both technical staff and executive stakeholders.

What You'll Do
  • Lead incident response engagements from initial triage through full remediation and post-incident review
  • Perform digital forensic analysis across endpoints, servers, cloud environments, and network infrastructure
  • Conduct malware analysis, memory forensics, and log analysis to determine scope, root cause, and impact
  • Contain active threats including ransomware, business email compromise, data exfiltration, and insider threats
  • Develop and deliver incident reports with timelines, technical findings, executive summaries, and remediation recommendations
  • Coordinate with client IT teams, legal counsel, insurance carriers, and law enforcement as needed
  • Build and maintain incident response playbooks, runbooks, and escalation procedures
  • Conduct post-incident lessons learned and help clients strengthen their security posture
  • Participate in on-call rotation for emergency incident response (24/7 coverage)
Requirements
  • 3+ years of experience in incident response, digital forensics, or security operations
  • Hands-on experience with forensic tools: Velociraptor, KAPE, FTK, Autopsy, X-Ways, or similar
  • Strong knowledge of Windows and Linux forensic artifacts (event logs, registry, prefetch, $MFT, syslog)
  • Experience investigating ransomware incidents, BEC, lateral movement, and data exfiltration
  • Proficiency with SIEM platforms (OpenSearch, Splunk, Sentinel, or similar) and EDR tools (LimaCharlie, CrowdStrike, SentinelOne)
  • Understanding of MITRE ATT&CK framework and how to apply it to real-world investigations
  • Strong written and verbal communication skills - ability to brief executives and write professional reports
  • At least one relevant certification: GCIH, GCFA, GCFE, GREM, EnCE, or equivalent
Nice to Have
  • GCFA, GNFA, or GREM certification
  • Experience with cloud incident response (Azure AD, M365, AWS CloudTrail)
  • Experience working with cyber insurance carriers and breach coaches
  • Scripting skills (Python, PowerShell) for automation and custom tooling
  • Previous MSSP or consulting IR experience
  • Competitive salary based on experience
  • Health, dental, and vision insurance
  • 401(k) with company match
  • Unlimited PTO
  • Annual certification and training budget
  • Remote-first culture with flexible scheduling
  • Paid on-call compensation
  • Access to forensic lab and investigation tools
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Staff CSIRT Analyst
Staff CSIRT Analyst

Hidden Jobs • United States

Remote
USD 180,000 - 240,000
Remote US-wide
Generous paid time off
Medical, dental & vision benefits
+4
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Security Engineer, Incident Response
Security Engineer, Incident Response

Eliassen Group • Burbank (CA)

Hybrid
Confidential
Medical insurance
Dental insurance
Vision insurance
+2
Incident Response & DFIR Lead
Incident Response & DFIR Lead

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 160,000
Vacation days
Sick leave
Public holidays
+5
Senior Incident Responder – Remote Forensics Lead
Senior Incident Responder – Remote Forensics Lead

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Senior Incident Response Consultant
Senior Incident Response Consultant

Pondurance • McLean (VA)

Hybrid
USD 110,000 - 136,000
Medical, dental, vision
401(k) plan
Time off: PTO, sick, holiday, parental
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2