Remote Incident Response & DFIR Lead - FinTech Security

Greenhouse Software, Inc.

United States

Remote

USD 120,000 - 160,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Vacation days
Sick leave
Public holidays
Medical budget
Remote work
Education budget
Language budget
Wellness budget

Job summary

Greenhouse Software, Inc. is seeking an Incident Response & DFIR Lead to spearhead incident response, containment and forensic activities across endpoints, cloud and identity systems.

You will act as Incident Commander for major incidents, coordinate cross-team investigations, and drive evidence collection and post-incident reviews to strengthen security posture. Ideal candidates bring hands-on IR lifecycle experience, SIEM/XDR proficiency, and strong communication to leadership and technical

Qualifications

  • Experience leading complex security incidents with multi-team coordination.
  • Practical experience in endpoint/server/cloud investigations using SIEM/audit logs.
  • Familiarity with incident lifecycle and evidence handling.

Responsibilities

  • Lead incident response, containment and forensic coordination for confirmed security incidents.
  • Act as Incident Commander for major security incidents within the defined authority model.
  • Assign incident roles and maintain ownership of investigation, containment and recovery actions.
  • Maintain incident timelines, evidence logs, decision logs and action tracking.
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry.
  • Direct forensic collection and analysis to determine attack path, scope, persistence and impact.
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners.
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required.
  • Coordinate eradication and recovery actions and ensure systems return to a sufficiently trusted state.
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements.
  • Maintain practical forensic and evidence-handling standards.
  • Develop and maintain incident playbooks, forensic checklists and containment procedures.
  • Lead post-incident reviews and root-cause analysis.
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up.
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations.
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners.
  • Support incident exercises and readiness testing.
  • Develop and mentor Incident Response / DFIR Specialists.
  • Coordinate with external forensic, incident-response or specialist providers where required.
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders.

Skills

Incident response
Incident Commander
Forensics
EDR/XDR
Cloud forensics
Windows/Linux
Documentation
Scripting

Tools

Velociraptor
KAPE
Volatility
EnCase
FTK
Cortex XDR

Job description

Greenhouse Software, Inc. is seeking an Incident Response & DFIR Lead to spearhead incident response, containment and forensic activities across endpoints, cloud and identity systems.

You will act as Incident Commander for major incidents, coordinate cross-team investigations, and drive evidence collection and post-incident reviews to strengthen security posture. Ideal candidates bring hands-on IR lifecycle experience, SIEM/XDR proficiency, and strong communication to leadership and technical

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior Incident Response Consultant - Forensics Lead
Remote Senior Incident Response Consultant - Forensics Lead

Forensic Focus • Town of Texas (WI), Northern (KY)

Hybrid
USD 123,000 - 179,000
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Remote IR Lead: Cloud Security & Incident Response
Remote IR Lead: Cloud Security & Incident Response

FICO • United States

Remote
USD 137,000 - 215,000
Remote-work option
Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Senior DFIR Incident Response Lead - Client-Facing
Senior DFIR Incident Response Lead - Client-Facing

Forensic Focus • Northern (KY)

Hybrid
USD 123,000 - 179,000
Senior DFIR Lead: Incident Response & Forensics
Senior DFIR Lead: Incident Response & Forensics

Forensic Focus • Northern (KY)

Hybrid
USD 92,000 - 154,000
DFIR Analyst: Lead Incident Response & Forensics
DFIR Analyst: Lead Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Senior DFIR Engineer - Incident Response & Forensics
Senior DFIR Engineer - Incident Response & Forensics

Intuit Inc. • Frisco (TX)

On-site
USD 140,000 - 180,000
Bonus potential
Equity rewards
Benefits package
Remote DFIR Lead: Incident Response & Forensics
Remote DFIR Lead: Incident Response & Forensics

Zoho • United States

Remote
USD 140,000 - 210,000
Senior DFIR Consultant – Incident Response & Forensics
Senior DFIR Consultant – Incident Response & Forensics

Forensic Focus • Northern (KY)

On-site
USD 92,000 - 154,000