Cybersecurity Incident Responder
Core
Command investigation, analysis, containment, and remediation of cybersecurity incidents across the global enterprise environment.
Role type
Cybersecurity Incident Responder (IC)
Builds
Incident response outcomes for global enterprise security posture
Domain
Cybersecurity / Incident Response
Deliverable
client delivery
Required skills
incident response processes, investigative techniques, threat indicators, attack methodologies, log analysis, forensic investigation, SIEM/SOAR, EDR, IDS/IPS, firewall, proxy, case management platforms
Preferred skills
scripting or programming languages for automation, advanced security certifications (GCIH, GREM, GCFA, GCFE, CISSP, CEH, CISA, Security+)
Technologies
SIEM, SOAR, EDR, IDS/IPS, email security, firewalls, proxy tools, case management platforms
Responsibilities
Lead investigation and response activities for confirmed and escalated cyber security incidents; Perform analysis of suspicious activity across endpoint, network, identity, email, cloud, application, and system log sources; Analyze, investigate, and correlate data from monitoring platforms to drive accurate incident response; Document investigations, findings, actions taken, and escalation details in the case management system; Follow shift handoff procedures and communicate open issues, emerging threats, and significant events to team members; Contribute to continuous improvement by identifying recurring false positives, process gaps, and opportunities to improve alert quality, runbooks, and analyst efficiency; Drive containment, eradication, and recovery actions in coordination with infrastructure and technology teams
Seniority
Mid-level, hands-on IC