Incident Responder
Jobgether · United States · 1 mo ago
RemoteRemoteOTHR$108k–$122k/yrFull-time
Accountabilities
- Lead security investigations, enhance detection strategies, and improve incident response operations across cloud and endpoint environments.
- Own security incidents from initial escalation through resolution, including investigation, containment, eradication, recovery, and post-incident improvements.
- Manage and validate escalations from managed security partners while ensuring effective communication and resolution.
- Conduct proactive threat hunts across cloud, endpoint, identity, and network telemetry to identify emerging threats and improve detection coverage.
- Build, maintain, and optimize detection content using SIEM platforms and cloud security tools.
- Partner with detection engineering teams to develop analytics, improve alert fidelity, and strengthen monitoring capabilities.
- Design and improve enrichment, automation, and response workflows to reduce manual effort and accelerate security operations.
- Apply AI-assisted approaches to investigation, triage, detection creation, and automation while ensuring responsible adoption.
- Analyze security logs and telemetry to reconstruct attacker activity and identify opportunities for improvement.
- Maintain detailed investigation documentation, including evidence, timelines, actions taken, and technical conclusions.
- Strengthen operational processes through lessons learned, updated runbooks, and continuous improvement initiatives.
Requirements
- Strong incident response experience, deep technical knowledge of cloud security, and the ability to operate effectively in complex security environments.
- Hands-on experience with Azure and AWS security environments.
- Strong experience using Microsoft Sentinel or similar SIEM platforms for investigations and detection engineering.
- Experience creating and tuning detection rules, analytics, and security monitoring content.
- Experience managing relationships with managed security service providers, including escalation handling and service improvement.
- Experience conducting threat hunting and developing automation workflows, including SOAR playbooks, scripting, and enrichment processes.
- Strong understanding of attacker tactics, techniques, procedures, cyber kill chain concepts, and MITRE ATT&CK frameworks.
- Solid knowledge of networking fundamentals, cloud security principles, and identity systems such as Active Directory and Entra ID.
- Ability to communicate clearly with both technical and non-technical stakeholders.
- Strong judgment under pressure and ability to work independently while contributing effectively within a collaborative team.
- Commitment to continuous improvement and improving security processes, tooling, and operational maturity.
Benefits
- Competitive annual salary range of $108,400 - $122,000 USD, based on location, experience, skills, and qualifications.
- Remote-first work culture with flexibility for distributed teams.
- Comprehensive health coverage, including dependent coverage.
- Flexible paid time off policies, including additional self-care days and volunteer days.
- Paid parental leave.
- Home office setup support and remote work stipend.
- Short-term or remote-centric work arrangements for additional flexibility.
- Access to continuous learning and development opportunities, including an annual learning stipend.
- Free account access for family members.
- Employee recognition programs and engagement initiatives.
- Employee Assistance Program supporting personal wellbeing.
- Opportunity to work in a high-growth security environment with talented and collaborative teams.