Associate Director, Cyber Defense - Staff Incident Responder
Alnylam Pharmaceuticals · Cambridge, MA · 1 mo ago
HybridInformation Technology$174k–$236k/yrFull-time
Responsibilities
- Lead complex cyber investigations and incident response across global environments, driving end-to-to containment, eradication, and recovery.
- Perform advanced forensic analysis and proactive threat hunting to identify attacker behavior, persistence mechanisms, and lateral movement.
- Translate investigation findings into scalable improvements in detection coverage, telemetry, and response effectiveness.
- Develop and enhance incident response playbooks, investigation workflows, and containment strategies based on real-world threats.
- Improve response speed and effectiveness through detection engineering, alert tuning, automation, and removal of systemic bottlenecks.
- Build and evolve incident response tooling, scripts, and integrations to enable scalable and efficient operations.
- Influence and optimize the security tooling ecosystem to improve signal quality, visibility, and investigative outcomes.
- Lead post-incident analysis, producing clear, actionable reports that drive remediation and strengthen security posture.
- Partner cross-functionally to drive remediation, hardening, and long-term risk reduction across the enterprise.
Qualifications
- 8+ years of hands-on experience in incident response, digital forensics, threat hunting, or security operations within enterprise environments (including cloud).
- Deep investigative expertise across endpoint, cloud, network, and identity domains, including correlation of multi-source telemetry and forensic artifacts.
- Strong scripting and automation skills (e.g., Python, Go, PowerShell, Bash) to support scalable investigation and response workflows.
- Proven ability to independently lead complex investigations and make high-confidence technical decisions in high-pressure environments.
- Strong understanding of attacker tactics, techniques, and procedures, including experience with frameworks such as MITRE ATT&CK.
- Experience applying industry incident response frameworks (e.g., NIST, CISA) in real-world scenarios.
- Demonstrated impact improving detection and response through tooling, process, or program enhancements.
- Strong communication skills, with the ability to translate technical findings, risks, and recommendations for technical and non-technical stakeholders.
Pay
$174,300.00 - $235,700.00