Incident Response Lead - AI-Driven Detection & Containment

Career Techniques

Dallas (TX)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Career Techniques is seeking an experienced Incident Response Lead to execute end-to-end IR lifecycle with AI-assisted tooling and threat intel. You will act as both hands-on responder and incident leader, coordinating cross-functional teams to rapidly mitigate incidents and improve detection fidelity and response speed.

The role requires 6+ years in security operations, strong Microsoft ecosystem experience, and proficiency with KQL.

Qualifications

  • 6+ years in Cybersecurity Operations / Incident Response.
  • Strong experience within Microsoft Security Ecosystem.
  • Proven experience investigating incidents across cloud, identity, endpoint, and email.
  • Demonstrated experience integrating or leveraging AI/automation in security operations.
  • Strong proficiency in KQL for threat hunting and investigation.
  • Excellent written and verbal communication, including executive-level reporting.
  • Bachelor’s degree in Cybersecurity/IT or related field (or equivalent).
  • Certifications: CISSP, CISM, CISA, or SANS GIAC.

Responsibilities

  • Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts.
  • Lead the full Incident Response lifecycle with focus on rapid detection and containment.
  • Leverage MITRE ATT&CK and Cyber Kill Chain to guide investigations and response.
  • Lead real-time decision-making during active incidents and communicate risk clearly.
  • Utilize AI-assisted platforms to pre-triage alerts and prioritize high-risk activity.
  • Drive AI-based correlation and context aggregation across SIEM/XDR and threat intel sources.
  • Conduct deep-dive investigations across endpoints, identities, email, network, and cloud.
  • Perform host forensics, log analysis, and malware triage to determine scope and persistence.
  • Provide technical leadership and mentorship to junior analysts.
  • Collaborate with IT, Legal, HR, and business stakeholders during investigations.
  • Deliver executive-ready incident reports with impact assessments and actions.
  • Conduct post-incident reviews and root cause analysis to improve controls.

Education

Bachelor’s degree in Cybersecurity/Information Technology or related field
CISSP/CISM/CISA or SANS GIAC certifications

Tools

Microsoft Security Ecosystem
Azure
AWS

Job description

About the RoleThis role is responsible for the end-to-end execution of the Incident Response lifecycle, leveraging AI-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment.You will operate as both a hands-on technical responder and incident leader, driving rapid mitigation actions while improving detection fidelity, response speed, and operational efficiency.Responsibilities Include, but Are Not Limited to:
  • Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts and driving containment, eradication, and recovery actions
  • Execute the full Incident Response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain
  • Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain to guide investigations and response strategies
  • Lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated
  • Utilize AI-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue
  • Drive the adoption of AI-based correlation and context aggregation across SIEM/XDR, case management, and threat intelligence sources
  • Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments
  • Perform host forensics, log analysis, and malware triage to determine scope, impact, and persistence mechanisms
  • Drive operational efficiency by reducing manual touchpoints and enabling automated containment and remediation actions
  • Provide technical leadership and mentorship to junior and mid-level analysts, elevating team capability and consistency
  • Collaborate with IT, Engineering, Legal, HR, and business stakeholders during investigations and incident response activities
  • Serve as a key contributor across multiple concurrent initiatives, including tool enablement, process improvement, and security strategy
  • Deliver clear, concise, and executive-ready incident reports, including impact assessments and recommended actions
  • Conduct post-incident reviews and root cause analysis, driving improvements to detection, response, and prevention controls
Requirements and Qualifications
  • 6+ years of hands-on experience in Cybersecurity Operations / Incident Response
  • Strong experience within Microsoft Security Ecosystem
  • Proven experience investigating incidents across cloud (Azure/AWS), identity, endpoint, and email platforms
  • Demonstrated experience integrating or leveraging AI/automation in security operations (e.g., security copilots, ML-based detections, automated triage)
  • Strong proficiency in KQL (Kusto Query Language) for threat hunting and investigation
  • Strong analytical and critical thinking skills with the ability to operate under pressure
  • Excellent written and verbal communication skills, including executive-level reporting
  • Ability to lead incidents, influence stakeholders, and drive rapid decision-making
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • Certified in one or more of the following: CISSP, CISM, CISA,SANS GIAC Security Certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Senior Manager - Cyber Operations & Assurance- Incident Response
Senior Manager - Cyber Operations & Assurance- Incident Response

American Express • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior Incident Response Consultant
Senior Incident Response Consultant

Jobtailor • Colorado

On-site
USD 60,000 - 90,000
AI Incident Response Lead
AI Incident Response Lead

Arcitix Technologies • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
Senior Manager - Cyber Operations & Assurance- Incident Response
Senior Manager - Cyber Operations & Assurance- Incident Response

American Express • New York (NY)

On-site
USD 150,000 - 190,000
Senior Manager - Cyber Operations & Assurance- Incident Response
Senior Manager - Cyber Operations & Assurance- Incident Response

American Express • Salt Lake City (UT)

On-site
USD 120,000 - 210,000
Engineer, Cyber Security II
Engineer, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 120,000 - 160,000