Incident Response Lead
Core
Lead hands-on incident response activities, serving as the primary internal escalation point and incident commander for security events across Security, IT, GRC, and Legal.
Role type
Senior individual contributor incident response lead
Builds
Incident response playbooks, escalation procedures, communication workflows, and detection/response capabilities
Domain
Cybersecurity, cloud-native environments, regulatory compliance
Deliverable
client delivery
Required skills
incident response leadership, digital forensics, threat detection, cloud-native environment investigations, host/cloud/log-based investigations, SIEM platform expertise, EDR tool expertise, cloud security monitoring, external SOC/MDR provider coordination, MITRE ATT&CK framework application, breach response regulatory compliance
Preferred skills
tabletop exercise design, incident simulation, post-incident root cause analysis, systemic risk reduction initiatives
Technologies
SIEM, EDR, cloud monitoring, identity systems
Responsibilities
Lead hands-on incident response activities and serve as the primary internal escalation point; Serve as the central incident commander across Security, IT, GRC, and Legal during active incidents; Partner with the SOC to validate alerts, guide investigations, and drive containment and eradication efforts; Conduct host, cloud, and log-based investigations and coordinate with external forensic firms; Maintain and continuously improve incident response playbooks, escalation procedures, and communication workflows; Lead post-incident reviews and root cause analysis; Develop and execute tabletop exercises and incident simulations; Partner with GRC and Legal to support breach impact assessments and regulatory notification processes; Drive continuous improvement of detection and response capabilities; Own incident metrics and reporting; Participate in an on-call escalation rotation.
Seniority
Senior, hands-on IC