Principal Consultant: DFIR

Lever, Inc.

United States

Hybrid

USD 175,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Medical Insurance
Retirement Match Program
Paid Time Off

Job summary

Cyderes is hiring a Principal Incident Response Consultant to lead responses to major client incidents. You will assemble and guide cross‑functional teams, triage threats, and drive remediation while communicating with customers at all levels.

The role requires 5+ years in security with 3+ in incident response, strong forensics skills, and the ability to operate across Windows, Linux, MacOS and cloud environments. Hybrid work available in the US.

Qualifications

  • Minimum 5 years in professional services or information security, with at least 3 in incident response.
  • Industry certs validating digital forensics or incident response: GCIH, GCFA, GCFE, CFCE, GREM, EnCE, CCE or similar.
  • Ability to communicate complex technical topics to technical and non-technical audiences.
  • Experience coordinating incidents and leading a team during incidents.
  • Experience investigating Windows, Linux, MacOS and cloud environments.

Responsibilities

  • Act as lead responder on high profile and sensitive engagements.
  • Perform incident triage to determine scope, urgency, and impact and recommend remediation.
  • Participate in full incident response lifecycle from prep to lessons learned.
  • Collect, triage, and analyze forensic artifacts from client networks or devices.
  • Use EDRs or log collection platforms for large-scale investigations.
  • Communicate clearly with customers across all incident phases.
  • Assist with developing and improving Cyderes Incident Response services.
  • Train and supervise junior responders.

Skills

Incident response
Leadership
Client communication
Forensic analysis
Threat hunting
Project management

Education

Bachelor's degree in relevant discipline

Tools

Axiom
FTK
X-Ways

Job description

We Help the World Be Everyday Ready™

Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by experienced operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.

Great Place to Work® Certified™

About the Role: The Principal Incident Response Consultant will respond to our customer’s major information security incidents, as the lead responder or incident handler. Drawing additional resources from our technical consulting teams, the Principal will build and lead teams for the purpose of responding to and remediating active client threats. As a primary interface to customers in crisis, the Principal will have excellent communication and organizational skills, ensuring the efficient and smooth handling of incidents. The Principal will be highly skilled in collaboration.

Responsibilities
  • Act as a lead responder on high profile and sensitive customer engagements.
  • Performing incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation
  • Be involved in the full incident response lifecycle, from preparation for information security incidents, through detecting, managing, and resolving ongoing incidents, and finally reporting on those incidents and identifying improvements and lessons learned.
  • Collect, triage, and analyze forensic artifacts from client networks or devices in support of incident response investigations
  • Utilize various EDRs or log collection platforms to conduct large-scale investigations and examine endpoint and network-based sources of evidence.
  • Communicate with customer in a clear and precise manner throughout all phases of an incident, including verbal and written reports.
  • Assist with developing, operating, and continuously improving the Cyderes Incident Response services.
  • Train, develop, coach, and supervise junior and ad-hoc responders.
Requirements
  • Minimum of 5 years of experience in professional services or information security field with at least 3 of those years in Incident Response
  • Holds an industry accepted certification validating digital forensics or incident response capabilities: GCIH, GCFA, GCFE, CFCE, GREM, EnCE, CCE, or similar
  • Experience communicating complex technical topics to both technical and non-technical audiences
  • Experience coordinating an incident and/or leading a team during an incident
  • Experience investigating Windows, Linux, MacOS, and cloud environments
  • Demonstrated experience and competence in endpoint forensics, memory forensics, network forensics, and malware analysis, with specialized knowledge in at least one of those fields using tools such as Axiom, FTK, X-Ways, etc.
  • Experience identifying indicators of compromise and threat actor activity using a hypothesis-driven approach to uncover connections and correlations in data
  • Applied knowledge of the Incident Response Lifecycle, the Cyber Kill Chain, and the MITRE ATT&CK Framework.
  • Strong client facing communication (report issues to customer in a timely manner, demonstrate expertise of the overall business unit and command of the incident, develop presentations to highlight results and solutions, etc.)
  • Bachelor’s degree in relevant discipline
  • Experience working with network and security technologies to include Elasticsearch, data analytic platforms, endpoint tools, network technologies, and SIEMs
  • Proficiency with common programming or scripting languages such as Python and PowerShell
  • Ability to preserve host-based and network evidence in an industry accepted and forensically sound manner
  • Experience with project management to bring about the successful completion of specific project goals and objectives
  • Ability to learn new technology and concepts quickly
  • Effective in collaboration with teams in remote locations

The following will be considered an asset:

  • Certifications such as CISSP, OSCP, ITIL, COBiT, or SABSA
  • Working knowledge of NIST SP800-61r2 and ISO 27035
  • Knowledge of ISO information security standard families, particularly ISO 27001 and 27002

$175,000 - $190,000 a year

WHY CYDERES?

Benefits that go beyond the basics, we support our people so they can do their best work.

  • Medical Insurance - Employee + dependents covered
  • Life Insurance -Protection for what matters most
  • Retirement Match Program - We invest in your future
  • Hybrid Work Model -2–3 days in office
  • Maternity & Paternity Leave-Time for the moments that matter
  • Paid Time Off -PTO+ sick & casual leave
  • Bereavement & Volunteer Time - Giveback to your community
  • Professional Development -Reimbursement program
  • LinkedIn L&D Platform -Thousands of coursesat your fingertips
  • Mobile Phone Reimbursement -Stay connected, on us

Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status.

Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Consultant: DFIR (Fully Remote)
Principal Consultant: DFIR (Fully Remote)

Cyderes • United States

Remote
USD 140,000 - 190,000
Principal Product Manager
Principal Product Manager

Cacheflow • United States

Hybrid
USD 140,000 - 210,000
Medical Insurance
Hybrid Work Model
Manager, Software Engineering
Manager, Software Engineering

Lever, Inc. • Northern (KY)

Hybrid
USD 150,000 - 190,000
Medical Insurance
Life Insurance
Retirement Match Program
+7
DevOps Engineer
DevOps Engineer

Lever, Inc. • Northern (KY)

Hybrid
USD 120,000 - 140,000
Medical Insurance
Retirement Match
Hybrid Work Model
+3
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

INSPYR Solutions • California (MO)

On-site
USD 100,000 - 130,000
Manager, Software Engineering
Manager, Software Engineering

Cyderes • United States

Hybrid
USD 150,000 - 210,000
Medical Insurance - Employee + depend.
Life Insurance
Retirement Match Program
+7
Principal Consultant, Restoration and Remediation
Principal Consultant, Restoration and Remediation

Surefire Cyber Inc. • Northern (KY)

On-site
USD 140,000 - 210,000
Competitive compensation
Paid time off
Health benefits (medical, dental, and
Incident Response Engineer 2
Incident Response Engineer 2

Sophos • United States

Remote
USD 85,000 - 120,000
Remote-first
Flexible schedule