Senior Incident Responder, Global CSIRT
Core
Senior Incident Responder leading end-to-end investigation and response to security incidents, including adversary activity, insider threats, and web application attacks across on-premises and multi-cloud environments.
Role type
Senior hands-on IC incident responder
Builds
Incident response playbooks, detections, and automation (SOAR, detection-as-code)
Domain
Enterprise cybersecurity, cloud security (AWS, Azure, GCP), threat intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
host and network forensics (Windows, macOS, Linux), cloud security architecture, CI/CD pipeline security, cloud logging/telemetry analysis, MITRE ATT&CK framework knowledge, incident triage, containment, eradication, recovery, post-incident review, threat landscape analysis
Preferred skills
malware analysis, detection engineering, offensive security, applied AI/ML for security, Salesforce platform expertise
Technologies
SOAR, detection-as-code, AWS, Azure, GCP, MITRE ATT&CK
Responsibilities
Investigate and respond to security incidents end to end; lead high-severity incidents; contribute to process improvements and automation; mentor newer analysts; produce incident documentation and status updates
Seniority
Senior, hands-on IC