- Experience
- Any
- Salary
- USD 108,400 – USD 122,000 / year
- Openings
- 1
- Posted
- 3 hours ago
- Work mode
- Work from home
- Resume
- Required to apply
Job description
Job Overview
We are seeking an Incident Responder based in the United States to safeguard critical cloud infrastructures and enhance security operations within a dynamic, impactful organization. This role encompasses managing intricate investigations, advancing detection methodologies, and establishing scalable, resilient security protocols.
Key Responsibilities
- Lead security incident management from escalation through final resolution, including investigation, containment, eradication, recovery, and implementing post-incident enhancements.
- Oversee and validate escalations from managed security service providers, ensuring clear communication and timely issue resolution.
- Conduct proactive threat hunting leveraging cloud, endpoint, identity, and network data to uncover emerging threats and bolster detection capabilities.
- Develop, maintain, and optimize detection content utilizing SIEM platforms alongside cloud security solutions.
- Collaborate with detection engineering teams to enhance analytics, improve alert accuracy, and strengthen monitoring frameworks.
- Design and refine enrichment, automation processes, and response workflows to minimize manual tasks and streamline operations.
- Apply responsible AI-assisted methods across investigation, triage, detection formulation, and automation initiatives.
- Analyze security logs and telemetry to reconstruct attacker behavior and pinpoint improvement opportunities.
- Maintain comprehensive documentation covering evidence, timelines, actions, and technical conclusions.
- Elevate operational procedures by integrating lessons learned and updating runbooks to foster continuous enhancements.
Candidate Requirements
- Extensive experience in incident response and security operations within cloud-native environments.
- Hands-on expertise with Azure and AWS security platforms.
- Proficiency using Microsoft Sentinel or comparable SIEM tools for investigations and detection engineering.
- Skilled in creating and fine-tuning detection rules, analytics, and monitoring content.
- Experience managing managed security service provider relationships, including escalation and service optimization.
- Strong capabilities in threat hunting, along with automation development such as SOAR playbooks, scripting, and data enrichment.
- Solid understanding of attacker tactics, cyber kill chain, MITRE ATT&CK frameworks, networking fundamentals, cloud security principles, and identity systems like Active Directory and Entra ID.
- Excellent communication skills for articulating technical details to both technical and non-technical audiences.
- Ability to perform under pressure, work autonomously, and contribute effectively within a collaborative team setting.
- A commitment to ongoing improvement of security processes, tools, and operational maturity.
- Preferred qualifications include knowledge of intelligence-driven incident response, packet capture tools such as Wireshark or tcpdump, and certifications like GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty.
Benefits and Perks
- Competitive salary ranging from 108400 to 122000 USD annually, adjusted for experience, skills, and location.
- Remote-first work environment with flexible arrangements suited for distributed teams.
- Comprehensive health insurance including coverage for dependents.
- Flexible paid time off policies including extra days for self-care and volunteering.
- Paid parental leave benefits.
- Support for home office setup and remote work stipends.
- Options for short-term or remote-focused work to enhance flexibility.
- Access to professional growth opportunities, including an annual learning stipend.
- Free account access extended to family members.
- Employee recognition programs and engagement initiatives fostering a positive culture.
- Employee Assistance Program available to support personal well-being.
- Work in a rapidly growing security environment alongside talented, collaborative colleagues.
Additional Information
This role is offered through a partner company that manages all application processes and subsequent stages independently. The hiring organization employs advanced AI-driven matching to review candidates efficiently, with final decisions made directly by the employer. Data privacy and AI usage disclosures are provided to applicants, ensuring transparency and compliance.