Principal Incident Response & Cyber Defense Lead
Listed on 2026-06-19
-
IT/Tech
Cybersecurity
Job Title: Principal Incident Response & Cyber Defense Lead
Location: Holmdel, NJ or New York City
Type: Full Time
Salary: $180K – $200K+ 25% Bonus
OverviewOur Financial client is seeking a highly technical cyber security leader to serve as a key partner to the Head of Cyber Defense. This is primarily a hands‑on role (approximately 80% technical, 20% leadership) focused on leading complex cyber investigations, threat hunting, detection engineering, and incident response activities across the enterprise. The ideal candidate is an experienced practitioner who remains close to the technology, enjoys solving difficult security problems, and can mentor and guide less experienced analysts.
This is not a traditional people‑management role.
- Lead investigations of advanced cyber threats, security incidents, and insider risk events.
- Serve as the senior escalation point for high‑severity incidents and act as incident commander when required.
- Conduct proactive threat hunting across cloud, SaaS, endpoint, network, and identity environments.
- Develop and improve detection use cases, analytics, and response playbooks.
- Partner with SOC teams to enhance monitoring, triage, containment, and response capabilities.
- Drive improvements in logging, monitoring, user behavior analytics (UBA), and threat detection coverage.
- Perform digital forensics, root cause analysis, and post‑incident reviews.
- Support incident response exercises, readiness assessments, and cyber crisis simulations.
- Mentor analysts and help elevate the technical capabilities of the cyber defense team.
- Collaborate with security leadership on strategy, tooling, and continuous improvement initiatives.
- 7–10+ years of cybersecurity experience with a strong background in Incident Response, Digital Forensics, Threat Hunting, or Cyber Defense.
- Deep understanding of attacker tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework.
- Hands‑on experience investigating complex security incidents in enterprise environments.
- Strong experience with SIEM, endpoint telemetry, cloud security monitoring, and log analytics platforms.
- Experience developing detections, threat hunts, and response playbooks.
- Knowledge of malware analysis, digital forensics, insider threat, and user behavior analytics.
- Familiarity with NIST CSF and modern incident response frameworks.
- Strong communication skills with the ability to engage technical teams and executive stakeholders.
- Demonstrated ability to mentor and influence others without relying on formal authority.
Equal Opportunity Employer
Yoh, a Day & Zimmermann company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Note:
Any pay ranges displayed are estimations. Actual pay is determined by an applicant's experience, technical expertise, and other qualifications as listed in the job description. All qualified applicants are welcome to apply.
By applying and submitting your resume, you authorize Yoh to review and reformat your resume to meet Yoh’s hiring clients' preferences. To learn more about Yoh’s privacy practices, please see our Candidate Privacy Notice:
For California applicants, qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. All of the material job duties described in this posting are job duties for which a criminal history may have a direct, adverse, and negative relationship potentially resulting in the withdrawal of a conditional offer of employment.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Visit to contact us if you are an individual with a disability and require accommodation in the application process.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).