Incident Response Lead, DFIR

Asymmetricsecurity

New York (NY)

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Asymmetric, the world’s first AI-native DFIR lab, is assembling a world-class Incident Response Lead to shape how DFIR is done in the AI era. You will lead technically challenging forensic work and grow into a key technical leader on the founding team, supported by an AI engineering group.

You will spearhead investigations including business email compromise, ransomware, and cloud-based intrusions, build defensible timelines, codify best practices, and collaborate to develop AI DFIR tools.

Qualifications

  • Significant experience in major incident investigations and forensic analysis efforts.
  • Investigated cloud-based attacks in Microsoft and/or Google Workspace.
  • Skilled in developing playbooks and analysis plans for complex forensic investigations.
  • Able to clearly communicate technical findings to stakeholders and team members.

Responsibilities

  • Lead investigations including business email compromise, ransomware, network intrusions, and insider threats; initial focus on cloud-based email attacks across Google and Microsoft environments.
  • Build defensible timelines and substantiate findings across log sources.
  • Uncover novel attack paths and codify best practices in case handbooks.
  • Partner with the engineering team to develop AI DFIR tools.
  • Grow into a key technical leader on the founding team with AI engineering support.

Skills

Incident response
Forensic analysis
Cloud security
Playbooks
Leadership
Technical communication

Job description

The last great shift in computing, the cloud, created a new generation of giants in DFIR, like Crowdstrike. The next great shift—AI—will be even bigger. It will create new giants. We are building one of them.

Asymmetric is the world’s first AI-native DFIR lab. We build human-AI analyst teams designed from the ground up to redefine the next generation of DFIR. Our AI agents take on the repetitive, laborious work, freeing analysts to focus on the most challenging and critical parts of investigations.

Our first AI agent is already live, running Business Email Compromise (BEC) investigations for a DFIR partner as part of a six-figure contract. We are backed by a $4.2M investment by some of the world’s best investors, including Susa Ventures, Matt Clifford, Charlie Songhurst (Meta board member), and Geoff Ralston.

About the role

We are assembling a world-class team and are looking for a talented and ambitious Incident Response Lead to shape how DFIR is done in the AI era. You will lead technically challenging forensic work and grow into a key technical leader at Asymmetric. You will be supported by an AI engineering team dedicated to automating the least interesting parts of your job, freeing you to focus on what matters most: solving the most complex analytical challenges within each case.

This is a role on the founding team that comes with significant responsibility. We will pay exceptionally well for top performers.

Responsibilities
  • Lead investigations including business email compromise, ransomware, network intrusions, and insider threats. Your initial focus will be on cloud-based email attacks across Google and Microsoft environments.
  • Build defensible timelines and substantiate findings across log sources.
  • Take challenging forensic problems, including uncovering novel attack paths.
  • Codify best practices, contributing to case handbooks.
  • Partner with the engineering team to develop AI DFIR tools.
You may be a fit if you:
  • Have significant experience in major incident investigations and forensic analysis efforts.
  • Have investigated cloud-based attacks in Microsoft and/or Google Workspace.
  • Are skilled in developing playbooks and analysis plans for complex forensic investigations.
  • Can communicate technical findings clearly with key stakeholders and team members.
  • Excited about uncovering novel threat actor TTPs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, AI-Driven DFIR Investigations
Lead, AI-Driven DFIR Investigations

Asymmetricsecurity • New York (NY)

On-site
USD 150,000 - 210,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Consultant, DFIR
Senior Consultant, DFIR

MOXFIVE • United States

On-site
USD 100,000 - 150,000
Partner 20, Staff Engineer, Incident Response
Partner 20, Staff Engineer, Incident Response

P2P • San Francisco (CA)

On-site
USD 243,000 - 284,000
Health insurance
Dental insurance
Vision insurance
+3
Senior Threat Intelligence Researcher
Senior Threat Intelligence Researcher

Aegis AI • New York (NY)

On-site
USD 120,000 - 160,000
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Security Operations Lead
Security Operations Lead

Fireworks AI • San Mateo (CA)

On-site
USD 180,000 - 230,000
Incident Manager - Detection & Response
Incident Manager - Detection & Response

United States Digital Space LLC • San Francisco (CA), Washington

Hybrid
USD 290,000 - 365,000
Visa sponsorship
Detection & Response Engineer Austin, TX
Detection & Response Engineer Austin, TX

Future Secure AI Pty • Austin (TX)

Hybrid
USD 110,000 - 150,000
State-of-the-art technology
Flexible work environment
Competitive salary
+1