Staff CSIRT Analyst

Hidden Jobs

United States

Remote

USD 180,000 - 240,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote US-wide
Generous paid time off
Medical, dental & vision benefits
401(k) with employer match
Home office stipend
Education and professional development
Stock options

Job summary

Huntress is seeking a senior, high-impact staff member for its internal Computer Security Incident Response Team. You will own the full incident response lifecycle, from triage to remediation, while coordinating with engineering, product security, and detection functions.

The role blends hands-on technical response with program leadership, readiness exercises, and cross-functional collaboration to strengthen defenses across the organization.

Qualifications

  • 8+ years in incident response, SOC ops, or digital forensics.
  • Ability to translate complex problems into practical security solutions.
  • Experience leading small project teams and cross-functional alignment.

Responsibilities

  • Lead identification, triage, and validation of security incidents for the internal IR program.
  • Design and run tabletop exercises and purple-team engagements to keep responders prepared.
  • Collaborate with engineering, product security, and detection teams to tune telemetry and reduce noise.
  • Partner with offensive security to surface visibility gaps and drive remediation.
  • Facilitate post-incident reviews and push improvements to tooling and processes.
  • Maintain incident response playbooks and scalable configurations.

Skills

Incident response leadership
SOC operations
EDR/MDR platforms
Cloud security
Executive communication

Tools

SIEM
ELK
Confluence
Jira
Lucidchart

Job description

Role overview

This is a senior-level staff position on an internal Computer Security Incident Response Team, focused on safeguarding the organization itself with the same rigor applied to customer-facing environments. The role serves as the highest internal escalation point from the Security Operations Center, owning the full incident response lifecycle and partnering across engineering, product security, and detection functions. The work blends hands-on technical response with strategic program leadership, readiness exercises, and cross-functional coordination.



Responsibilities


  • Lead identification, triage, and validation of security incidents across multiple telemetry sources, acting as the primary internal escalation for the SOC.

  • Design and run practical response exercises such as tabletop scenarios and purple-team engagements to keep first responders prepared at every level.

  • Collaborate with engineering, product security, and detection teams to tune telemetry sources for high true-positive rates and reduced noise.

  • Partner with offensive security counterparts to surface visibility gaps against modern threat actor tactics, techniques, and procedures, and drive remediation to close them.

  • Facilitate cross-functional Post-Incident Reviews, track resulting remediation work, and push tooling or process improvements that harden future response.

  • Maintain playbooks, system configurations, and incident response standards that keep the program scalable and supportable.



Requirements


  • 8+ years of experience in incident response, SOC operations, or digital forensics.

  • Advanced working knowledge of EDR/MDR platforms, log aggregation tools such as SIEM or ELK, and cloud environments including AWS, Azure, or M365.

  • Demonstrated ability to articulate root causes of complex problems from first principles and translate them into technical solutions.

  • Experience leading small project teams and aligning technology stacks across functions.

  • Strong written and verbal communication skills for conveying technical incident detail to both engineers and executives.

  • Familiarity with automation or SOAR platforms, plus documentation and diagramming tools such as Confluence, Jira, and Lucidchart.



Benefits and work setup


  • Fully remote work environment within the United States.

  • Generous paid time off covering vacation, sick time, and holidays, plus 12 weeks of paid parental leave.

  • Comprehensive medical, dental, and vision benefits, along with life and disability insurance.

  • 401(k) plan with a 5% employer contribution independent of employee deferrals, and stock options for full-time staff.

  • A one-time $500 reimbursement for home office setup, a $75 monthly digital reimbursement, and an annual allowance for education and professional development.

  • Access to a coaching and personal growth platform, with an organizational emphasis on inclusive culture.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Security Operations
Senior Manager, Security Operations

gomotive • United States

Remote
USD 140,000 - 200,000
Medical, dental, vision coverage
401(k) contributions
Disability & life insurance
+1
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Senior Cybersecurity Consultant, Blue Team Lead
Senior Cybersecurity Consultant, Blue Team Lead

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000