Incident Response Consultant – Microsoft Security (NA)

Quorum Cyber

United States

Hybrid

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Quorum Cyber is seeking an experienced Incident Response professional in the United States to lead investigations, perform forensics, and coordinate with SOC, MDR and client teams. You will analyse Windows, Linux, macOS and cloud environments, identify attacker TTPs, and help shape response actions.

The role requires deep technical skills in security telemetry, Microsoft-aligned security stacks, and experience with AI-enabled incident workflows.

Qualifications

  • Experience performing host, network, and memory forensics.
  • Proficient in analysing logs, traffic, disks, and volatile artefacts.
  • Familiar with Windows, Linux, macOS and multi-cloud environments.
  • Strong understanding of enterprise security controls and attacker TTPs.
  • Experience with AI-enabled IR workflows is a plus.

Responsibilities

  • Support investigations into cyber security incidents across diverse technologies and environments.
  • Perform forensics and evidence handling with proper chain-of-custody.
  • Identify threat actor tools, tactics, and procedures (TTPs).
  • Analyse logs, network traffic, and artefacts to determine attacker actions and impact.
  • Interact with customers and stakeholders during incidents and provide guidance.
  • Collaborate with SOC, MDR, Threat Intelligence and other teams.
  • Contribute to improving detection, escalation, containment and recovery processes.

Skills

Forensic analysis
Memory forensics
Log & network analysis
EDR & SIEM usage
Microsoft security stack
Threat hunting
Scripting / automation
I/O and evidence handling
Communication

Tools

EDR
SIEM
Microsoft Defender
Azure/M365 security tools

Job description

Quorum Cyber is seeking an experienced Incident Response professional in the United States to lead investigations, perform forensics, and coordinate with SOC, MDR and client teams. You will analyse Windows, Linux, macOS and cloud environments, identify attacker TTPs, and help shape response actions.

The role requires deep technical skills in security telemetry, Microsoft-aligned security stacks, and experience with AI-enabled incident workflows.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead | Microsoft Security Expert
Senior Incident Response Lead | Microsoft Security Expert

Quorum Cyber • United States

On-site
USD 140,000 - 190,000
World class benefits
Senior Incident Response Consultant (North America)
Senior Incident Response Consultant (North America)

Quorum Cyber • United States

On-site
USD 140,000 - 190,000
World class benefits
Remote Senior Incident Response Consultant - Forensics Lead
Remote Senior Incident Response Consultant - Forensics Lead

Forensic Focus • Town of Texas (WI), Northern (KY)

Hybrid
USD 123,000 - 179,000
Senior Incident Response Lead — Cloud & Forensics
Senior Incident Response Lead — Cloud & Forensics

Forensic Focus • Georgia

Hybrid
USD 123,000 - 179,000
Senior Incident Responder – Remote Forensics Lead
Senior Incident Responder – Remote Forensics Lead

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Incident Response Consultant (North America)
Incident Response Consultant (North America)

Quorum Cyber • United States

Hybrid
USD 120,000 - 180,000
Incident Response Lead - Remote IR Commander
Incident Response Lead - Remote IR Commander

Rippling, Inc. • United States

Remote
USD 105,000 - 135,000
Medical, dental, vision coverage
401(k) with company match
Paid time off
+1
Incident Response Specialist
Incident Response Specialist

myBridge Corporation • Arlington (VA)

On-site
USD 90,000 - 120,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000