Cyber Incident Responder
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, IT Support
Impact:
This role leads high-severity incident response for client environments, reducing client downtime, containing ransomware and hands-on-keyboard intrusions, coordinating recovery resources across MSP teams, and maintaining clear, calm, executive-ready client communications during active incidents.
Position Summary:The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments. The role combines deep incident response expertise with practical leadership: directing technical containment, coordinating resources across SOC, service desk, infrastructure, cloud, networking, compliance, account management, and client leadership teams, and serving as a trusted communicator during high-pressure events.
This position is hands-on and client-facing. The responder is expected to investigate endpoint, identity, cloud, email, network, and SaaS activity; determine scope and impact; recommend and execute containment and eradication steps; and translate technical findings into clear decisions, risks, and next steps for clients and internal stakeholders
The role also improves SOC maturity by mentoring analysts, refining incident response playbooks, leading post-incident reviews, supporting tabletop exercises, and driving measurable improvements in detection, response, documentation, and recovery readiness.
Key Responsibilities / Duties:- Lead end-to-end incident response for high-severity and complex incidents, including triage, validation, scoping, containment, eradication, recovery support, and post-incident review.
- Serve as technical incident lead and primary coordination point during major incidents, establishing response priorities, assigning actions, tracking decisions, and maintaining momentum across internal MSP/MSSP teams and client stakeholders
- Conduct in-depth investigations of ransomware, business email compromise, credential compromise, endpoint malware, lateral movement, persistence, suspicious administrative activity, cloud compromise, and data exposure scenarios.
- Analyze telemetry from EDR/XDR, SIEM, identity providers, email security platforms, firewalls, cloud platforms, vulnerability tooling, remote management tools, and ticketing systems to determine root cause, timeline, blast radius, and recommended response actions.
- Develop, execute, and/or coordinate containment strategies such as host isolation, account disablement, token/session revocation, conditional access changes, firewall blocks, policy changes, IOC sweeps, and coordination of backup/recovery activities.
- Coordinate evidence preservation and documentation, including collection of logs, timelines, artifacts, screenshots, containment actions, chain-of-custody notes when needed, and incident decision records.
- Communicate incident status, risk, impact, and next steps clearly to technical and non-technical audiences, including client IT teams, client executives, internal leadership, account teams, legal/compliance stakeholders, and third-party partners.
- Prepare concise client-facing incident updates, executive summaries, post-incident reports, root cause summaries, corrective action plans, and lessons-learned documentation.
- Mentor Tier 1/Tier 2 SOC analysts and other technical teams on investigation methodology, escalation quality, containment standards, incident communications, and documentation expectations.
- Maintain and improve incident response playbooks, escalation procedures, severity models, incident templates, customer communication standards, and internal handoff processes.
- Support proactive threat hunting and detection engineering by converting incident learnings into improved SIEM queries, EDR detections, alert tuning, and response automation opportunities.
- Participate in the on-call rotation and support 24/7 incident response operations for urgent or critical-impact incidents.
- Contribute to security program maturity through tabletop exercises, operational readiness reviews, knowledge base articles, process improvements, and cross-department training.
- Perform other duties as assigned, including support…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).