Senior Tactical Response Analyst
Core
Lead deep investigations into complex, active-adversary intrusions, build defensible timelines and root-cause narratives, and guide partners through remediation and recovery.
Role type
Senior Tactical Response Analyst (Incident Response)
Builds
Defensible incident timelines, remediation playbooks, detection rules, and automation workflows
Domain
Cybersecurity, Incident Response, Threat Hunting
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Active adversary investigation, multi-host intrusion analysis, timeline reconstruction, remediation guidance, technical communication, cross-functional collaboration
Preferred skills
Malware analysis, OSINT, playbook design, automation development, technical enablement content creation
Technologies
osquery, Velociraptor, EDR platforms, Eric Zimmerman tools, RegRipper, Hayabusa, Chainsaw, KQL, EQL, ES|QL, Splunk SPL, Sigma, YARA, Suricata, Snort, Python, PowerShell, Bash, JavaScript, PHP, Ruby, Microsoft 365, Azure, SIEM, Windows, Linux, macOS
Responsibilities
Lead or support cases involving confirmed active adversaries and serious intrusions; Investigate across endpoint, identity, cloud, SIEM, and telemetry sources; Build clear, evidence-based timelines and narratives; Provide practical remediation and recurrence-prevention guidance; Explain complex findings to technical teams and executives; Mentor responders and represent the team in cross-functional discussions
Seniority
Senior, hands-on IC
