Cyber Defense - Incident Responder
Listed on 2026-07-18
-
IT/Tech
Cybersecurity
cyber defense - incident responder
cyber defense is responsible for operating and continuously advancing a cloud-first, intelligence-driven cybersecurity program. As a cyber incident responder, you will report to the manager of cyber defense operations and play a critical role in protecting the organization by leading and executing incident response across enterprise and cloud environments. This role is responsible for the end-to-end execution of the incident response lifecycle, leveraging ai-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment.
responsibilities- act as incident commander for high-impact security incidents, coordinating cross-functional response efforts and driving containment, eradication, and recovery actions.
- execute the full incident response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain.
- leverage frameworks such as mitre att&ck and the cyber kill chain to guide investigations and response strategies.
- lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated.
- utilize ai-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue.
- drive the adoption of ai-based correlation and context aggregation across siem/xdr, case management, and threat intelligence sources.
- conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments.
- perform host forensics, log analysis, and malware triage to determine scope, impact, and persistence mechanisms.
- drive operational efficiency by reducing manual touchpoints and enabling automated containment and remediation actions.
- provide technical leadership and mentorship to junior and mid-level analysts, elevating team capability and consistency.
- collaborate with it, engineering, legal, hr, and business stakeholders during investigations and incident response activities.
- serve as a key contributor across multiple concurrent initiatives, including tool enablement, process improvement, and security strategy.
- deliver clear, concise, and executive-ready incident reports, including impact assessments and recommended actions.
- conduct post-incident reviews and root cause analysis, driving improvements to detection, response, and prevention controls.
- 6+ years of hands‑on experience in cybersecurity operations / incident response.
- strong experience within the microsoft security ecosystem.
- proven experience investigating incidents across cloud (azure/aws), identity, endpoint, and email platforms.
- demonstrated experience integrating or leveraging ai/automation in security operations (e.g., security copilots, ml-based detections, automated triage).
- strong proficiency in kql (kusto query language) for threat hunting and investigation.
- strong analytical and critical thinking skills with the ability to operate under pressure.
- excellent written and verbal communication skills, including executive-level reporting.
- ability to lead incidents, influence stakeholders, and drive rapid decision-making.
- bachelor’s degree in cybersecurity, information technology, or related field (or equivalent experience).
- certified in one or more of the following: cissp, cism, cisa, sans giac security certifications.
- must be legally authorized to work in the united states without the need for employer sponsorship, now or at any time in the future.
- company-paid lunch (via grubhub).
- 100% employer-paid medical, dental, and vision benefits in a high deductible health plan.
- 16 weeks of paid parental leave.
- employee assistance program.
- life insurance; short-term disability and long-term disability.
- 401(k): company matches 100% of contributions up to 6%.
- optional employee-paid benefits: ppo medical insurance, health savings accounts, flexible spending accounts, supplemental life insurance, wellhub.
- 25 days of paid time off plus 12 company holidays.
it is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).