Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Jobtailor is seeking a senior cybersecurity professional to lead complex incident investigations and drive end-to-end incident response across enterprise, cloud, and on‑prem environments.
You will conduct forensics, develop detections and runbooks, and mentor SOC staff while coordinating with multiple teams and stakeholders.
• Lead complex cyber incident investigations across enterprise, cloud, hybrid, and on-premises environments
• Conduct end-to-end incident response, including triage, scoping, containment, eradication, recovery, and post-incident reporting
• Investigate network intrusions, account compromise, ransomware, insider risk, fraud-related incidents, unauthorized access, and advanced threat activity
• Preserve evidence and maintain chain of custody for forensic, legal, compliance, and regulatory investigations
• Produce investigative findings, root cause analyses, executive summaries, and remediation recommendations
• Perform digital forensics and incident response across Windows, cloud, identity, endpoint, network, and application environments
• Conduct dead-box forensic examinations, artifact analysis, timeline analysis, and evidence collection
• Analyze suspicious files, malware behavior, persistence mechanisms, attacker tooling, and indicators of compromise
• Conduct proactive threat hunting and improve SIEM detections, correlation rules, KQL queries, alerts, dashboards, and response workflows
• Apply MITRE ATT&CK, threat intelligence, incident lessons learned, and attacker TTPs to improve detection coverage
• Partner with SOC, Threat Intelligence, Engineering, Platform, Infrastructure, Cloud, Identity, Application, and Security Operations teams
• Support engineering, administration, optimization, log onboarding, data normalization, telemetry validation, and use-case development for security platforms
• Build scripts, queries, automation, dashboards, and technical workflows to improve investigation speed and quality
• Use AI-assisted tools, copilots, automation, and scripting to improve investigation efficiency, reporting, and analysis
• Support threat emulation and purple team activities and assist with attack path, lateral movement, persistence, and detection validation analysis
• Serve as senior technical lead during significant cybersecurity investigations and incident response efforts
• Mentor SOC Leads, Security Analysts, Incident Responders, and Security Engineers
• Contribute to playbooks, runbooks, investigation standards, threat hunting procedures, and operational documentation
• Communicate with technical teams, leadership, Legal, HR, Compliance, and business stakeholders
Requirements
Core Competencies
Demonstrates expertise in leading complex cyber incident investigations and incident response across diverse environments, including cloud and on-premises. Proficient in digital forensics, threat hunting, and developing security automations to enhance incident detection and response.
Highest-signal resume keywords
ATS Optimization Keywords
Hard Skills
Soft Skills
Certifications & Qualifications
Industry Keywords
Tools & Technologies