Incident Response & DFIR Lead

Greenhouse Software, Inc.

United States

Remote

USD 120,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Vacation days
Sick leave
Public holidays
Medical budget
Remote work
Education budget
Language budget
Wellness budget

Job summary

Greenhouse Software, Inc. is seeking an Incident Response & DFIR Lead to spearhead incident response, containment and forensic activities across endpoints, cloud and identity systems.

You will act as Incident Commander for major incidents, coordinate cross-team investigations, and drive evidence collection and post-incident reviews to strengthen security posture. Ideal candidates bring hands-on IR lifecycle experience, SIEM/XDR proficiency, and strong communication to leadership and technical

Qualifications

  • Experience leading complex security incidents with multi-team coordination.
  • Practical experience in endpoint/server/cloud investigations using SIEM/audit logs.
  • Familiarity with incident lifecycle and evidence handling.
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration.
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles.
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation.
  • Experience with Microsoft Entra ID / Active Directory incident investigation.

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents.
  • Act as Incident Commander for major security incidents within the defined authority model.
  • Assign incident roles and maintain ownership of investigation, containment and recovery actions.
  • Maintain incident timelines, evidence logs, decision logs and action tracking.
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry.
  • Direct forensic collection and analysis to determine attack path, scope, persistence and impact.
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners.
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required.
  • Coordinate eradication and recovery actions and ensure systems return to a sufficiently trusted state.
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements.
  • Maintain practical forensic and evidence-handling standards.
  • Develop and maintain incident playbooks, forensic checklists and containment procedures.
  • Lead post-incident reviews and root-cause analysis.
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up.
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations.
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners.
  • Support incident exercises and readiness testing.
  • Develop and mentor Incident Response / DFIR Specialists.
  • Coordinate with external forensic, incident-response or specialist providers where required.
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders.

Skills

Incident response
Incident Commander
Forensics
EDR/XDR
Cloud forensics
Windows/Linux
Documentation
Scripting

Tools

Velociraptor
KAPE
Volatility
EnCase
FTK
Cortex XDR

Job description

We are inviting you, a highly motivated and results-orientedIncident Response & DFIR Leadto join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities
  • Lead incident response, containment and forensic coordination for confirmed security incidents
  • Act as Incident Commander for major security incidents within the defined authority model
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
  • Maintain incident timelines, evidence logs, decision logs and action tracking
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
  • Maintain practical forensic and evidence-handling standards
  • Develop and maintain incident playbooks, forensic checklists and containment procedures
  • Lead post-incident reviews and root-cause analysis
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
  • Support incident exercises and readiness testing
  • Develop and mentor Incident Response / DFIR Specialists
  • Coordinate with external forensic, incident-response or specialist providers where required
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders
Requirements
  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
  • Experience leading complex security incidents and coordinating multiple technical teams during active response
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
  • Experience with Microsoft Entra ID / Active Directory incident investigation
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly
Will be a plus
  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
  • Experience investigating AWS or other cloud environments
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
  • Experience developing or improving incident response playbooks and containment procedures
  • Experience running tabletop or cyber incident exercises
  • Experience working with Legal, Privacy, HR or regulators during security incidents
  • Experience managing external DFIR or incident-response retainers
  • Python, PowerShell or other scripting experience useful for investigation and evidence processing
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent
We offer
  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Staff CSIRT Analyst
Staff CSIRT Analyst

Hidden Jobs • United States

Remote
USD 180,000 - 240,000
Remote US-wide
Generous paid time off
Medical, dental & vision benefits
+4
Project Manager, Digital Forensics & Incident Response (DFIR)
Project Manager, Digital Forensics & Incident Response (DFIR)

surefirecyber • United States

Remote
USD 90,000 - 130,000
Remote role
Equity
Generous PTO
+1
Security Operations Analyst (L1)
Security Operations Analyst (L1)

Greenhouse Software, Inc. • United States

Remote
USD 65,000 - 90,000
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per company policy
+5
Senior Digital Forensics and Incident Response Analyst
Senior Digital Forensics and Incident Response Analyst

SentinelOne, Inc. • United States

On-site
USD 140,000 - 210,000
Medical, dental, and vision coverage
Employee assistance program
Gym reimbursement
+4
Director, DFIR (Remote)
Director, DFIR (Remote)

Surefire Cyber Inc. • Northern (KY)

Remote
USD 150,000 - 190,000
Competitive pay
PTO
Medical & dental coverage
+2
Unix/Linux Infrastructure Forensics & Incident Engineer
Unix/Linux Infrastructure Forensics & Incident Engineer

Hallmark Global Technologies Limited • San Jose (CA)

On-site
USD 180,000 - 240,000
Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Zoho • United States

On-site
USD 140,000 - 210,000
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Incident Response & Digital Forensics Analyst (f/m/d)
Incident Response & Digital Forensics Analyst (f/m/d)

Concepture GmbH • United States

On-site
USD 120,000 - 190,000
Ownership & autonomy
Flexible hours
International team
+3