Principal Consultant: DFIR (Fully Remote)

Cyderes

United States

Remote

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cyderes is seeking a senior security incident response lead to manage the full lifecycle of sensitive customer incidents. You will act as the primary interface during crises, coordinating communications and rapid containment.

The role requires extensive IR experience, knowledge of MITRE ATT&CK, and hands-on expertise with Python, PowerShell, Elasticsearch, and SIEMs. You will train junior responders and help enhance Cyderes IR services.

Qualifications

  • Minimum 5 years in information security with 3+ years in incident response and relevant certifications.
  • Strong knowledge of the Incident Response Lifecycle, Cyber Kill Chain, and MITRE ATT&CK.
  • Experience with Python, PowerShell, Elasticsearch, SIEMs, and endpoint forensic tools is a plus.

Responsibilities

  • Act as the lead responder for sensitive customer security incidents, managing the full response lifecycle.
  • Serve as a primary interface during crises, ensuring clear communication and efficient incident handling.
  • Perform incident triage, scoping, and forensic analysis using industry standard tools.
  • Investigate endpoint, memory, network, and cloud evidence to identify threats and indicators of compromise.
  • Train, develop, and supervise junior and ad-hoc responders while improving Cyderes IR services.

Skills

Incident response
Cybersecurity
Leadership

Tools

Python
PowerShell
Elasticsearch
SIEMs
Endpoint forensics

Job description

  • Act as the lead responder for sensitive customer security incidents, managing the full response lifecycle.
  • Serve as a primary interface during crises, ensuring clear communication and efficient incident handling.

Key Responsibilities:

  • Perform incident triage, scoping, and forensic analysis using industry standard tools.
  • Investigate endpoint, memory, network, and cloud evidence to identify threats and indicators of compromise.
  • Train, develop, and supervise junior and ad-hoc responders while improving Cyderes IR services.

Requirements & Assets:

  • Minimum 5 years in information security with 3+ years in incident response and relevant certifications.
  • Strong knowledge of the Incident Response Lifecycle, Cyber Kill Chain, and MITRE ATT&CK.
  • Experience with Python, PowerShell, Elasticsearch, SIEMs, and endpoint forensic tools is a plus.

Cyderes builds practical identity and access management, exposure management, and risk programs, helping organizations stop active threats fast with managed detection and response. A Great Place to Work-Certified global team, they are driven by experienced operators and augmented by AI to deliver trusted security solutions.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead
Senior Incident Response Lead

Cyderes • United States

Remote
USD 140,000 - 190,000
DFIR
DFIR

Cye • United States

On-site
USD 65,000 - 110,000
DFIR
DFIR

Lever, Inc. • United States

Remote
USD 70,000 - 100,000
Security Analyst II: Gaurdian
Security Analyst II: Gaurdian

Lever, Inc. • United States

Remote
USD 68,000 - 75,000
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
Incident Response & DFIR Lead
Incident Response & DFIR Lead

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 210,000
Vacation days
Sick leave
Public holidays
+5
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Remote Senior Incident Responder: Executive Cyber Defense
Remote Senior Incident Responder: Executive Cyber Defense

BlackCloak • United States

Remote
USD 105,000 - 115,000
Remote work USA
Medical benefits
401k with match
+4