Senior Incident Response Lead - Forensics & Cloud IR

BetterCloud

Indianapolis (IN)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BetterCloud is looking for a Staff Incident Response Analyst to serve as a technical escalation point for L2 SOC analysts. This role involves handling complex incidents requiring deep forensics, cloud incident response, and advanced technical skills.

As a key member of the security team, you will lead incident investigations, analyze artifacts, and contribute to threat hunts. Candidates must have extensive experience in incident response, particularly in AWS environments, along with proficiency in EDR tools.

Qualifications

  • 6+ years of hands-on incident response experience, with at least 3 years at a senior or staff level.
  • Expert-level EDR proficiency with tools like CrowdStrike Falcon and SentinelOne.
  • Deep AWS incident response capability, including CloudTrail forensics.
  • Strong Windows and Linux forensics skills, with ability to analyze various artifacts.
  • Hands-on experience with SIEM, writing detection logic, and event correlation.

Responsibilities

  • Receive and escalate L2 incidents across all severity levels.
  • Perform deep-dive endpoint triage via EDR and analyze forensic artifacts.
  • Lead AWS-based incident response and correlate logs for cloud-side timelines.
  • Investigate identity provider incidents and respond to OAuth abuse.
  • Conduct structured threat hunts in the SIEM and provide escalation support.

Skills

Incident Response
EDR proficiency
AWS IR capability
Windows forensics
Linux forensics
SIEM investigation
Technical writing
MITRE ATT&CK fluency

Tools

CrowdStrike Falcon
SentinelOne
Google SecOps/Chronicle
Splunk
Microsoft Sentinel
Volatility

Job description

BetterCloud is looking for a Staff Incident Response Analyst to serve as a technical escalation point for L2 SOC analysts. This role involves handling complex incidents requiring deep forensics, cloud incident response, and advanced technical skills.

As a key member of the security team, you will lead incident investigations, analyze artifacts, and contribute to threat hunts. Candidates must have extensive experience in incident response, particularly in AWS environments, along with proficiency in EDR tools.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Senior Cloud DFIR Lead - Remote Incident Response
Senior Cloud DFIR Lead - Remote Incident Response

Palo Alto Networks, Inc. • Arizona

Remote
USD 151,000 - 208,000
Senior Cloud Forensics Analyst – TS/SCI, Onsite Incident Response
Senior Cloud Forensics Analyst – TS/SCI, Onsite Incident Response

Nightwing • Arlington (VA)

On-site
USD 100,000 - 120,000
Senior Incident Response Lead: Cloud & Forensics
Senior Incident Response Lead: Cloud & Forensics

WHOOP • Boston (MA)

On-site
USD 130,000 - 170,000
Senior SOC Analyst: Cloud & Forensics Incident Response
Senior SOC Analyst: Cloud & Forensics Incident Response

Alteryx • United States

On-site
USD 139,000 - 151,000
Senior Forensic Lead — Incident Response & Investigations
Senior Forensic Lead — Incident Response & Investigations

Arete Advisors, LLC • Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Senior IR Lead: Cloud & Forensics
Senior IR Lead: Cloud & Forensics

Google • United States

On-site
USD 138,000 - 200,000
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Incident Response Team Lead - Cybersecurity Forensics
Incident Response Team Lead - Cybersecurity Forensics

Artech Information System LLC • Plano (TX)

On-site
USD 90,000 - 120,000