Senior Incident Responder, Global CSIRT

Jobtailor

United States

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced Incident Response Lead to investigate and respond to security incidents end to end, triage, containment, eradication, recovery, and post-incident review across on‑premises and multi‑cloud environments.

You will mentor junior responders, support on-call rotations, and drive improvements to playbooks, SOAR tooling, and detection‑as‑code while communicating clearly with technical and non‑technical stakeholders.

Qualifications

  • 5+ years in information security with hands-on incident response experience.
  • Host and network forensics across Windows, macOS, and Linux.
  • Experience responding to incidents in cloud environments (AWS, Azure, GCP).
  • Familiarity with cloud architectures, CI/CD pipelines, and cloud telemetry.
  • Understanding of attacker TTPs, tooling, and hardening best practices.

Responsibilities

  • Investigate and respond to security incidents end to end: triage, containment, eradication, recovery, post-incident review.
  • Lead incidents and support Lead Incident Responders on high-severity events.
  • Investigate adversary activity, insider threats, and web app attacks across multi-cloud environments.
  • Contribute to playbooks, SOAR tooling, detection-as-code, and strategic projects.
  • Produce incident documentation and status updates for technical and non-technical stakeholders.
  • Mentor newer incident responders and support on-call rotations.

Skills

Incident Response
Operational Security Monitoring
Host Forensics
Network Forensics
Cloud Incident Response
Detection Engineering
Malware Analysis
Web Application Attacks
MITRE ATT&CK
Cloud Logging

Tools

AWS
Azure
GCP
SOAR Tooling
CI/CD Pipelines
Salesforce

Job description

  • Investigate and respond to security incidents end to end, including triage, containment, eradication, recovery, and post-incident review
  • Take point on many incidents and support Lead Incident Responders on the highest-severity, highest-visibility events
  • Investigate adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments
  • Contribute to process improvements, playbooks, SOAR tooling, detection-as-code, and strategic detection and response projects
  • Produce incident documentation and status updates for technical and non-technical stakeholders
  • Mentor newer incident responders
  • Support the team's on-call rotation, including core hours of 10:30 AM–6:30 PM ET Monday–Friday and occasional overnight/weekend on-call
Requirements
  • 5+ years in information security, including hands-on operational security monitoring and incident response
  • Host and network forensics across Windows, macOS, and Linux
  • Experience responding to incidents in cloud environments (AWS, Azure, and/or GCP)
  • Familiarity with cloud architectures, CI/CD pipelines, and cloud logging/telemetry
  • Experience handling high-priority incidents, including insider investigations, adversary activity, and web application attacks
  • Current understanding of attacker tactics, techniques, and procedures (TTPs), tooling, and hardening best practices
  • Working knowledge of a framework such as MITRE ATT&CK
  • Clear written and verbal communication
  • U.S. citizenship (U.S. born or naturalized), without dual citizenship
  • Agreement to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position
  • Preferred: depth in malware analysis, detection engineering, forensics, cloud security, offensive security, or applied AI/ML for security
  • Preferred: prior experience in a 24x7x365 security operations environment
  • Preferred: relevant certifications such as SANS GCIH, GCFA, GCFE, GNFA, GPEN, GREM, or Offensive Security OSCP
  • Preferred: experience applying AI and LLMs to SOC operations and understanding of the Salesforce platform and SaaS offerings
Core Competencies

Demonstrates expertise in incident response, including triage, containment, and recovery, while effectively communicating with both technical and non-technical stakeholders. Proficient in cloud security and forensics across multiple operating systems, with a strong understanding of attacker tactics and detection methodologies.

Highest-signal resume keywords
  • Incident Response
  • Cloud Security
  • Host And Network Forensics
  • MITRE ATT&CK Framework
  • Communication Skills
ATS Optimization Keywords
Hard Skills
  • Incident Response
  • Operational Security Monitoring
  • Host Forensics
  • Network Forensics
  • Cloud Incident Response
  • Detection Engineering
  • Malware Analysis
  • Web Application Attacks
  • Tactics, Techniques, And Procedures (TTPs)
  • Cloud Logging
Soft Skills
  • Mentoring
  • Clear Communication
Certifications & Qualifications
  • SANS GCIH
  • GCFA
  • GCFE
  • GNFA
  • GPEN
  • GREM
  • Offensive Security OSCP
Industry Keywords
  • Information Security
  • Security Operations
  • Incident Documentation
  • Adversary Activity
  • Insider Threats
  • Cloud Architectures
  • Detection-As-Code
  • Strategic Detection And Response
  • 24x7x365 Security Operations
  • Minimum Background Investigation (MBI)
Tools & Technologies
  • AWS
  • Azure
  • GCP
  • SOAR Tooling
  • CI/CD Pipelines
  • Salesforce
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance
Security Operations & Engineering Lead
Security Operations & Engineering Lead

Jobtailor • Brea (CA)

On-site
USD 170,000 - 250,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior SOC Engineer
Senior SOC Engineer

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

Jobtailor • Dearborn (MO)

On-site
USD 140,000 - 190,000
Security Engineer, Level 5 – Detection & Response
Security Engineer, Level 5 – Detection & Response

Jobtailor • California (MO)

On-site
USD 125,000 - 180,000
Incident Response Analyst
Incident Response Analyst

Jobtailor • California (MO)

On-site
USD 110,000 - 150,000
Senior Information Security Engineer – SIEM, Detection
Senior Information Security Engineer – SIEM, Detection

Jobtailor • Washington

On-site
USD 170,000 - 250,000