Cyber Defense - Incident Responder
Core
Leading and executing end-to-end incident response across enterprise and cloud environments using AI-assisted tools and automation to accelerate detection, triage, investigation, and containment.
Role type
Senior IC Cyber Incident Responder
Builds
Incident response capabilities and automated containment/remediation actions for enterprise and cloud environments
Domain
Cybersecurity / Cloud Security / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle management, cloud security (Azure/AWS), identity security, endpoint security, email security, KQL (Kusto Query Language), threat hunting, host forensics, log analysis, malware triage, AI/automation integration, MITRE ATT&CK framework, Cyber Kill Chain, executive reporting, technical leadership
Preferred skills
None explicitly stated
Technologies
Azure, AWS, SIEM, XDR, MITRE ATT&CK, Cyber Kill Chain, KQL
Responsibilities
Act as Incident Commander for high-impact security incidents, Execute the full Incident Response lifecycle, Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain, Lead real-time decision-making during active incidents, Utilize AI-assisted platforms to pre-triage alerts, Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments, Perform host forensics, log analysis, and malware triage, Provide technical leadership and mentorship to junior and mid-level analysts, Deliver clear, concise, and executive-ready incident reports, Conduct post-incident reviews and root cause analysis
Seniority
Senior, hands-on IC