Senior Incident Response Analyst

OpenLoop

United States

On-site

USD 140,000 - 190,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match
Life Insurance
Pet insurance

Job summary

OpenLoop is seeking a Senior Incident Response Analyst to join our Security Operations team. You will own incidents end-to-end, conduct forensic investigations across host, memory, network, cloud, and identity, and produce both technical timelines and executive summaries for complex cases.

You will refine queries, build correlation logic from EDR/SIEM data, and help automate triage with AI-assisted techniques to improve speed and quality, while supporting on-call rotations.

Qualifications

  • 6–8 years of hands-on security experience, focused on incident response and/or digital forensics.

Responsibilities

  • Own tier-1 and tier-2 incidents end to end: detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
  • Run host, memory, network, cloud, and identity forensic investigations independently, with evidence handling that stands up to legal, regulatory, and client scrutiny.
  • Investigate from EDR and SIEM telemetry — write and refine queries, build correlation logic, and reconstruct incident timelines from log data.
  • Share the IR on-call rotation with the Lead Incident Responder and Senior Staff Security Analyst, and exercise named containment authority within a defined threshold.
  • Author and rewrite IR playbooks based on incidents you personally work, and run post-incident reviews with findings tracked to closure.
  • Automate or AI-assist repetitive triage and evidence-collection steps so the team’s time goes to investigation rather than toil.
  • Write for two audiences — a defensible technical timeline and an executive summary of the same incident.

Skills

Incident response
Digital forensics
EDR/EPP
SIEM
Threat hunting
Forensic toolchain
MITRE ATT&CK
Scripting (Python/PowerShell)
AI tools in security
Incident writing

Tools

Velociraptor
KAPE
Volatility
Autopsy/EnCase/FTK/X-Ways
Wireshark
Zeek
CrowdStrike Falcon
Splunk
CloudTrail
GuardDuty

Job description

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About The Role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Security Operations team protects the clinical and operational systems that OpenLoop and our partners run patient care on. As a Senior Incident Response Analyst, you’ll be a dedicated responder on our DFIR function — owning incidents end to end, deepening our forensic capability, and making sure containment happens fast when PHI and clinical operations are on the line.

What You’ll Do
  • Own tier-1 and tier-2 incidents end to end: detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
  • Run host, memory, network, cloud, and identity forensic investigations independently, with evidence handling that holds up to legal, regulatory, and client scrutiny.
  • Investigate from EDR and SIEM telemetry — write and refine queries, build correlation logic, and reconstruct incident timelines from log data.
  • Share the IR on-call rotation with the Lead Incident Responder and Senior Staff Security Analyst, and exercise named containment authority (host isolation, session revocation) within a defined threshold.
  • Author and rewrite IR playbooks based on incidents you personally work, and run post-incident reviews with findings tracked to closure.
  • Automate or AI-assist repetitive triage and evidence-collection steps so the team’s time goes to investigation rather than toil.
  • Write for two audiences — a defensible technical timeline and an executive summary of the same incident.
Who You Are

You’re a hands‑on responder who has led real incidents under real ambiguity, and you’re straight about what you got wrong. We hire for the discipline, not the tool SKU or the credential: no specific degree is required, and strong responders from Defender, SentinelOne, Splunk, or Sentinel environments are fully in scope. This is an individual contributor role.

Required Qualifications
  • 6–8 years of hands‑on security experience, with the majority in incident response and/or digital forensics.
  • Demonstrated ownership of the full incident lifecycle, from detection validation through post-incident review.
  • Digital forensics breadth across host/disk, memory, network, cloud, and identity — from real casework, not coursework.
  • Working depth in EDR/EPP: investigating from endpoint telemetry, running response actions, and tuning what the tool surfaces.
  • Working depth in SIEM: query authoring, correlation logic, and timeline reconstruction from log data.
  • Hands‑on fluency with a forensic toolchain (e.g., Velociraptor, KAPE, Volatility, Autopsy/EnCase/FTK/X‑Ways, plaso, Zeek, Wireshark).
  • Evidence handling discipline — chain of custody, sound acquisition, and documentation that survives legal, regulatory, and client scrutiny.
  • MITRE ATT&CK fluency applied to real investigations.
  • Scripting for investigation and automation (Python, PowerShell, or similar).
  • Demonstrated, hands‑on use of AI tools (Claude, ChatGPT, Copilot, or equivalent) in security work, with specific examples of their impact on speed or quality — and sound judgment about AI and sensitive data (PHI, credentials, telemetry).
  • Clear incident writing: able to produce both a technical timeline and an executive summary of the same incident.
  • Willingness to participate in a shared IR on‑call rotation.
Preferred Qualifications
  • CrowdStrike Falcon EDR — hands‑on investigation and response in the console.
  • CrowdStrike Falcon Next‑Gen SIEM — CQL query authoring, correlation rules, and dashboards.
  • CrowdStrike Falcon Shield — SaaS app, identity, and third‑party integration risk.
  • Cloud incident response in AWS (CloudTrail, GuardDuty, IAM abuse patterns).
  • Identity‑centric investigation, particularly Okta (session hijacking, MFA fatigue, token theft, SSO abuse).
  • Healthcare, fintech, or other regulated‑industry experience with sensitive data.
  • HIPAA, HITRUST, or SOC 2 from the operator side, including breach determination workflow.
  • GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise.
  • Malware triage and reverse engineering fundamentals.
  • SOAR / automation platform experience, or AI‑assisted IR workflows built on LLM APIs.
  • Multi‑entity or M&A environment experience — we operate across several subsidiaries.
  • Open‑source contributions to DFIR or security tooling; CTF history, conference talks, or other community engagement.
  • Experience maturing an IR program from a lower baseline.
  • Threat intelligence consumption applied to active investigations.
What Success Looks Like
  • In your first 6 months: fully onboarded and taking primary responder duty on a defined rotation, independently owning tier‑1 and tier‑2 incidents without escalation for routine cases.
  • Forensic capability is genuinely two‑deep — you can run a host, memory, cloud, or identity investigation without the Lead Incident Responder in the room.
  • At least three IR playbooks rewritten or newly authored from incidents you worked, with post‑incident reviews running on a consistent cadence and findings tracked to closure.
  • In your first 12 months: measurable reduction in MTTD and MTTR against baseline, with repetitive triage and evidence collection automated or AI‑assisted rather than manual.
Our Benefits

In addition, for salaried positions you would also be eligible for:

  • Medical, Dental, and Vision plans
  • Flexible Spending/Health Savings Accounts
  • Flexible PTO
  • 401(k) + Company Match
  • Life Insurance, Pet insurance, and more
Our Company

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst
Senior Incident Response Analyst

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Medical, Dental, Vision plans
Flexible Spending Accounts
Flexible PTO
+2
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Senior Incident Response Consultant
Senior Incident Response Consultant

Pondurance • McLean (VA)

Hybrid
USD 110,000 - 136,000
Medical, dental, vision
401(k) plan
Time off: PTO, sick, holiday, parental
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
DFIR Analyst
DFIR Analyst

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Senior Incident Response Analyst - DFIR Specialist
Senior Incident Response Analyst - DFIR Specialist

OpenLoop • United States

On-site
USD 140,000 - 190,000
Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match
+2
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Incident Response Security Engineer - Escalations
Senior Incident Response Security Engineer - Escalations

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Sr. Staff Security Engineer
Sr. Staff Security Engineer

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 170,000 - 260,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings
Flexible PTO
+2
Director, IT Operations
Director, IT Operations

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 120,000 - 170,000
Medical, Dental, Vision coverage
401(k) + company match
Flexible PTO
+1