787,996open jobs
49,912companies
122,545added this week
Browse all
Salary
$105k – $135k per year
Location
Remote (United States)
Seniority
Staff · 6+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 25, 2026.

Overview
Company
Impact
Profile match
Cyber-first managed IT, cybersecurity, and cloud services for complex, compliance-driven environments in healthcare, infrastructure, and PE.

Harbor IT is a national provider of managed IT, cybersecurity, AI, and cloud services, built for organizations running complex, regulated, and mission-critical environments. Harbor was formed by bringing together specialized technology firms rather than by acquiring generalists, which is why our engineering bench runs deeper across more domains than a typical managed service provider. Cybersecurity is not a product line we added. We started as a security company, and security is built into every service we deliver.

Our practices concentrate on industries where failure is not an option: critical infrastructure across oil and gas, agriculture, manufacturing, and transportation; multi-site healthcare and life sciences; and private equity portfolio companies and serial acquirers. We run a 24/7/365 Security Operations Center staffed entirely in the United States.

Our Managed Detection and Response practice, formerly Quadrant Information Security, combines security technology with in-house cybersecurity talent to deliver 24/7 monitoring, detection, and response across customer environments. The platform is built on Sagan, our proprietary detection and correlation engine.

This is a new role, and it exists because Harbor manages the systems attackers land in: email, identity, endpoints, servers, firewalls, backups, and the help desk that touches all of them. When a client is compromised we are the first call and the only party with hands already on the environment, but Harbor does not perform deep digital forensics and does not intend to. You will own the first hours instead: triage, scoping, containment decisions, straight answers for executives, and the judgment call about what Harbor handles end to end versus what gets handed to an outside DFIR firm, breach counsel, or an insurance panel. You are the incident commander, directing Harbor’s SOC analysts, security engineers, infrastructure teams, and help desk during a live event, and you will build the practice that supports it: the severity model, the playbooks, the escalation matrix, the client-facing report format, and the tabletops that test all of it before a real incident does. You report to the Senior Director of Cyber Services and work alongside the SOC Manager, the Director of Deployments and Engineering, Client Success, and the account teams who own the client relationship.

Key Responsibilities

Incident Command

  • Serve as incident commander for client security incidents: establish scope, set response priorities, assign actions to named owners, track decisions, and keep the incident moving when the environment is unfamiliar and the data is incomplete.
  • Run triage and initial investigation across the environments Harbor manages, including Microsoft 365 and Entra ID, Active Directory, endpoints under EDR, servers, firewalls, and the Sagan-based detection pipeline and its alert history. Often times delegating information gathering to internal resources while you focus on the things only you are capable of.
  • Own containment decisions and their consequences: what gets isolated, what credentials get reset, what gets left running to preserve evidence, and who at the client has authority to approve each one.
  • Make and defend the escalation call. Own the incidents that sit inside Harbor’s scope from detection through post-incident reporting, including business email compromise, single-host malware, and bounded credential compromise. When an incident exceeds that scope, brief the receiving DFIR firm and hand off with a written timeline and evidence inventory rather than a phone call and a shrug.
  • Carry on-call responsibility. Incidents do not respect business hours, and this role requires availability outside them.

Stakeholder Communication

  • Be the voice clients hear during the worst week of their year. Translate technical findings into decisions an owner, executive, or general counsel can act on, without overstating certainty and without hiding behind jargon.
  • Coordinate with breach counsel, cyber insurance carriers and their panel firms, third-party DFIR teams, client internal IT, and law enforcement where applicable, and keep Client Success and leadership current on active incidents.
  • Produce the post-incident report: what happened, what was confirmed versus assumed, what was contained, what remains open, and what the client should change.

Building the Practice

  • Write and maintain Harbor’s incident response playbooks, severity model, and escalation matrix, and define in writing where Harbor’s responsibility begins and ends so the boundary holds up in a contract and under pressure.
  • Build named working relationships with outside DFIR firms and breach counsel practices so handoffs start warm instead of starting with introductions.
  • Maintain an escalation-readiness record for every managed client: who holds an IR retainer, who holds cyber insurance and with which carrier, who has named counsel, and who has nothing.
  • (When applicable/feasible) Run tabletop exercises with Harbor teams and with clients, and turn what breaks in those exercises into playbook changes.
  • Mentor SOC analysts and security engineers on investigative method and incident discipline, and feed lessons from real incidents back to detection engineering so the same intrusion gets caught earlier next time.

Required Qualifications & Skills

Experience & Education

  • 6+ years in cybersecurity, with substantial time spent responding to real intrusions rather than monitoring for them.
  • Direct experience acting as the lead on security incidents, meaning you set the direction and other people executed against it. Participation on an IR team is not the same thing.
  • Experience responding across multiple distinct organizations, whether from a consulting, MSSP, MDR, or panel DFIR background. This role sees a different environment every time.

Technical Depth

  • Hands-on investigative depth in Microsoft 365, Google Workspace, and Entra ID compromise: unified audit log analysis, message trace, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access gaps.
  • Working command of endpoint detection and response tooling for investigation and containment, and enough host and Windows internals knowledge to interpret process lineage, persistence mechanisms, and lateral movement evidence.
  • Ability to build a defensible incident timeline from mixed and incomplete sources: SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets.
  • Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft, sufficient to scope an incident correctly and to recognize immediately when it exceeds what Harbor should be handling.

Judgment & Communication

  • Demonstrated experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including handing off an investigation.
  • Ability to brief non-technical executives under pressure and to write clearly enough that a client can act on the document without a follow-up call.
  • Willingness and ability to be reachable outside business hours for incident escalation.

Preferred Qualifications & Skills

  • GCIH, GCFA, GCIA, or comparable GIAC certification. CISSP or CISM.
  • Prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team.
  • Host and memory forensics depth, malware triage, or reverse engineering. Not required for this role, but useful for knowing what to ask an outside firm for.
  • Linux investigation experience, and cloud incident response beyond Microsoft such as AWS or Google Workspace.
  • Familiarity with regulatory and contractual notification obligations under HIPAA, PCI DSS, GLBA, state breach notification statutes, or SEC disclosure rules.
  • Background in managed services or another multi-tenant environment where you owned the relationship as well as the investigation.

Location & Work Model

Location: Remote (US)

Travel: None expected

Schedule: Standard business hours with on-call rotation and availability for incident escalation outside those hours.

Compensation & Benefits

  • Base salary: $105,000 to $135,000, depending on experience
  • Employer-paid medical, dental, and vision coverage for the employee, with additional premium plan options available
  • 401(k) with company match
  • Paid time off
  • Reimbursement for approved tuition, certifications, and conference attendance

Equal Employment Opportunity

Harbor IT is an equal opportunity employer. We evaluate all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law. If you need a reasonable accommodation during the application or interview process, let us know and we will work with you.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
787,996 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
$199k – $279k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Austin • San Jose • Washington
AI/ML
AI Agents
Anomaly Detection
Context Engineering
LLM Guardrails
Machine Learning
DevOps
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
Threat Modeling
Apply
≈ $39k – $93k per year (Estimated) • Remote (India) • 8+ years exp • India
DevOps
CI/CD
Cybersecurity
OWASP Top 10
OWASP ASVS
Threat Modeling
OWASP
Apply
$118k – $145k per year • Hybrid • Full-Time • 6+ years exp • Omaha
Apply
≈ $125k – $275k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Charlotte
DevOps
IAM
Windows
Cybersecurity
Okta
Microsoft Entra ID
Auth0
Active Directory
Management
Agile
ITIL
Apply
$150k – $250k per year • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • United States
Python
PowerShell
AI/ML
LLM
Human-in-the-Loop
Red Teaming
Cybersecurity
Metasploit
Nmap
Cobalt Strike
BloodHound
MITRE ATT&CK
SIEM
Apply
System Administrator 3 hours ago
≈ $54k – $113k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • United States
DevOps
Windows
Cybersecurity
Active Directory
Apply
$100k – $150k per year • Equity 0.5–0.8% • In office • Full-Time • 1+ year exp • San Francisco
Python
Go
Rust
TypeScript
Databases
PostgreSQL
AI/ML
Copilot
AI Agents
LLM
DevOps
GCP
Azure
AWS
Docker
KVM
GitHub
Linux
Windows
Cybersecurity
GDPR
Apply
$150k – $200k per year • Equity 0.5–1.5% • Remote (United States) • Full-Time • 3+ years exp • San Francisco
AI/ML
Reinforcement Learning
AI Agents
Synthetic Data
Computer Use
DevOps
Linux
Windows
Apply
Hybrid • 3+ years exp
DevOps
Splunk
Windows Server
AWS
Docker
Kubernetes
AWS Fargate
Amazon EC2
IAM
Amazon ECS
Linux
Cybersecurity
Nessus
FedRAMP
Active Directory
Apply
$99k – $130k per year • In office • 2+ years exp
DevOps
Windows Server
Linux
Windows
DNS
VPN
Cybersecurity
Zero Trust
Apply
≈ $97k – $179k per year (Estimated) • Remote (United States) • Full-Time • 6+ years exp • Bachelor's Degree
DevOps
SLI/SLO/SLA
Management
ServiceNow
Agile
ITIL
ITSM
Waterfall
Apply
≈ $62k – $113k per year (Estimated) • Remote (United States) • Full-Time
Python
PowerShell
DevOps
Azure
Platform Engineering
Linux
Windows
Cybersecurity
Microsoft Entra ID
Management
OneDrive
SharePoint
ITIL
Service Desk
Apply
Help Desk II 9 days ago
≈ $62k – $112k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree
DevOps
Windows
DNS
Cybersecurity
SentinelOne
Active Directory
Apply
≈ $38k – $62k per year (Estimated) • In office • Full-Time • Framingham
DevOps
Windows
Apply
≈ $38k – $62k per year (Estimated) • In office • Full-Time • Framingham
DevOps
Windows
Apply
See all jobs
This is one of many
787,996 more open roles from verified company boards, updated every day.