Staff Incident Responder
Core
Senior technical member of a global, follow-the-sun incident response team accountable for investigating and responding to cybersecurity incidents across endpoint, network, identity, cloud, and SaaS environments.
Role type
Staff Incident Responder (Senior IC)
Builds
Detection capabilities, response tooling, playbooks, and security-hardening initiatives
Domain
Cybersecurity / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle management, deep technical analysis, threat hunting, adversary tradecraft analysis, automation development, cross-functional coordination, technical escalation, playbook improvement, forensic capabilities, AI-assisted workflow evaluation
Preferred skills
Critical thinking and analytical rigor, deep technical curiosity regarding attacker techniques and system failures, composure under pressure, sustainable teamwork practices
Technologies
EDR, SIEM, cloud security platforms, identity management tools, email security systems, network investigative tools, AI/automation frameworks
Responsibilities
Conduct incident response across varying types and severities using investigative tooling; produce clear investigation records and stakeholder updates; serve as technical escalation point and incident commander for high-severity incidents; perform deep technical analysis to reconstruct attacker activity; develop containment, eradication, and recovery strategies; conduct threat hunts and improve detections; drive security-hardening initiatives based on root-cause analysis; evaluate and apply AI-assisted capabilities to improve workflows; continuously improve playbooks, procedures, and automation; mentor responders and promote consistent investigative practices; participate in rotating on-call schedules with follow-the-sun handoffs
Seniority
Staff, hands-on IC with mentorship responsibilities