Staff Incident Response Analyst
Core
Technical escalation point for L2 SOC analysts and MDR partners, leading complex forensics, multi-system intrusions, and high-stakes containment decisions.
Role type
Staff Incident Response Analyst (DFIR)
Builds
Forensic timelines, containment decisions, detection rules, and incident closure documentation.
Domain
Cybersecurity / Incident Response / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response leadership, EDR triage, Windows forensics, Linux forensics, Cloud IR (AWS/GCP), SIEM investigation, Identity forensics, Threat hunting, Technical writing
Preferred skills
Memory forensics, Malware analysis, CIAM forensics, CSPM investigation, MSSP escalation evaluation
Technologies
CrowdStrike Falcon, SentinelOne, AWS CloudTrail, Google Cloud Audit Logs, Splunk, Microsoft Sentinel, Okta, Entra ID, Volatility, YARA, Wiz, Prisma Cloud
Responsibilities
Own L2 escalations and lead Sev2+ incidents; perform deep-dive endpoint triage via EDR; reconstruct attacker activity from host artifacts; lead AWS and GCP incident investigations; investigate identity provider and CIAM incidents; conduct structured threat hunts; review escalation packages and coach L2 analysts.
Seniority
Staff, hands-on IC