This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Incident Response Analyst based in United States.
Lead end-to-end security incident response activities within a fast-paced, technology-driven environment.
You will take ownership of complex incidents from initial detection through containment, recovery, and post-incident review.
The role combines digital forensics, threat investigation, security operations, automation, and clear incident communication.
You will investigate host, memory, network, cloud, and identity environments while protecting sensitive systems and information.
Working as a hands-on individual contributor, you will exercise defined containment authority and collaborate closely with senior security professionals.
You will also strengthen incident response capabilities by improving playbooks, automating repetitive work, and applying AI responsibly to security workflows.
Success will be measured through faster response, stronger forensic capabilities, effective documentation, and continuous improvement of the incident response program.
Accountabilities:
- Own Tier 1 and Tier 2 security incidents from detection validation, triage, and scoping through containment, eradication, recovery, and post-incident review.
- Conduct independent digital forensic investigations across host and disk, memory, network, cloud, and identity environments while maintaining rigorous evidence-handling practices.
- Investigate security events using EDR and SIEM telemetry, developing queries, correlation logic, and incident timelines from available log data.
- Participate in the incident response on-call rotation and exercise defined containment authority, including host isolation and session revocation when appropriate.
- Develop, update, and improve incident response playbooks based on lessons learned from real incidents.
- Lead post-incident reviews and ensure identified findings and corrective actions are tracked through completion.
- Automate repetitive triage and evidence-collection activities and use AI-assisted workflows to improve investigation efficiency while applying sound judgment around sensitive information.
- Produce clear and defensible incident documentation for both technical and executive audiences, translating detailed findings into concise business-level summaries.
- Apply threat intelligence and MITRE ATT&CK techniques to active investigations and use investigative findings to strengthen detection and response capabilities.
- Contribute to the ongoing maturity of the incident response program, including improvements to processes, tooling, automation, and operational readiness.
- 6-8 years of hands-on cybersecurity experience, with the majority focused on incident response and/or digital forensics.
- Demonstrated ownership of the complete incident response lifecycle, from detection validation through post-incident review.
- Hands-on digital forensics experience spanning host and disk, memory, network, cloud, and identity investigations.
- Strong experience with EDR/EPP platforms, including endpoint telemetry investigation, response actions, and tuning detection or response capabilities.
- Strong SIEM experience, including query development, correlation logic, and reconstruction of incident timelines from log data.
- Practical experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
- Strong evidence-handling discipline, including chain of custody, sound acquisition practices, and documentation suitable for legal, regulatory, and client review.
- Working knowledge of the MITRE ATT&CK framework applied to real-world investigations.
- Scripting and automation experience using Python, PowerShell, or similar technologies.
- Demonstrated hands-on experience using AI tools such as Claude, ChatGPT, Copilot, or equivalent solutions in security operations, with an understanding of how to use AI effectively while protecting sensitive data.
- Excellent technical and executive communication skills, with the ability to produce both detailed incident timelines and concise executive summaries.
- Willingness to participate in a shared incident response on-call rotation.
- Experience with CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, or similar platforms is preferred.
- Experience with AWS incident response, including CloudTrail, GuardDuty, IAM abuse patterns, and related cloud security investigations is preferred.
- Experience investigating identity-related threats, particularly within Okta environments, including session hijacking, MFA fatigue, token theft, and SSO abuse.
- Healthcare, fintech, or other regulated-industry experience involving sensitive data is advantageous.
- Familiarity with HIPAA, HITRUST, or SOC 2 from an operational perspective, including breach determination processes, is preferred.
- Relevant certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise are valued.
- Experience with malware triage, reverse engineering fundamentals, SOAR platforms, AI-assisted incident response workflows, threat intelligence, or IR program maturity is beneficial.
- Ability to work effectively in a collaborative environment while maintaining strong independent judgment and accountability.
- Medical, dental, and vision insurance plans.
- Flexible Spending Accounts and Health Savings Accounts.
- Flexible paid time off.
- 401(k) retirement plan with company matching.
- Life insurance.
- Pet insurance and additional employee benefits.
- Opportunity to work in a relatively flat organization that encourages employees to contribute ideas and take ownership.
- Environment built around autonomy, competence, collaboration, and belonging.
- Opportunity to strengthen incident response capabilities and work with modern security, forensic, automation, and AI technologies.
Requirements:
Benefits:

