Jobs · OTHR

Incident Responder

LastPass · United States · 1 mo ago
RemoteRemoteOTHR$108k–$122k/yrFull-time

Incident Responder

Own security incidents end-to-end — receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team.
Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact.
Apply AI-assisted approaches to triage, investigation, detection authoring, and automation — helping the team adopt these capabilities responsibly and effectively.
Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity.
Document investigations thoroughly — capturing actions, evidence, timelines, and conclusions — to a standard that supports both technical follow-up and stakeholder communication.

About the team

Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.

What you will work on

Partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel, and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations.
Work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.

Qualifications

  • Proven experience in incident response and security operations in cloud-native environments, with hands-on depth in Azure and AWS
    Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
    Proven experience working with an MSSP — managing escalations, providing quality feedback, and closing gaps in coverage — whether as client or vendor
    Proven experience conducting threat hunts and building automation in support of security operations, including SOAR playbooks, scripting, and enrichment workflows
    Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK, with solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID
    Communicates clearly with both technical and non-technical stakeholders, exercises sound judgment under pressure, and operates effectively both independently and as part of a collaborative team

What we offer

  • Commitment to continuous improvement — proactively contributing to detections, runbooks, tooling, and operational processes that raise the bar for the team
  • Compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience. US Pay Range $108,400—$122,000 USD
  • The leader in secure access
    High-growth, collaborative environment with inclusive teams
    Remote-first culture
    Competitive compensation
    Flexible Paid Time Off policies, including but not limited to: Quarterly Self-Care Days (4 extra paid days off annually) and Volunteer Days
    Parental leave
    Comprehensive health coverage, including dependents
    Home office setup support
    LastPass Families free account for up to 5 members
    Continuous learning and development opportunities, including an annual learning stipend to invest in your growth
    Peer-to-peer recognition through Motivosity
    Employee Assistance Program for well-being support
    Remote work stipend to support your home office needs
    Short-Term or Remote-Centric Work Arrangements for added flexibility

Similar jobs

Incident Responder

Arkenstone DefenseMenlo Park, CA· 5 days ago
OTHRapply on arkenstonesystems.hiring-arkenstonedefense.com

Incident Responder

United Wholesale MortgagePontiac, MI· 2 wk ago
Customer Serviceapply on careers-uwmcareers.icims.com

Incident Responder

SchoolsFirst Federal Credit UnionSacramento, CA· 2 mo ago
OTHR$42.41–$63.62/hrapply on schoolsfirstfcu.wd115.myworkdayjobs.com

Incident Responder

JetBlueNew York, New York, United States· 1 mo ago
Information Technology$91k–$129k/yrapply on careers.jetblue.com

Incident Responder

LeidosSuitland, MD· 3 wk ago
Information Technology$108k–$195k/yrapply on careers.leidos.com