×
Register Here to Apply for Jobs or Post Jobs. X

Incident Response & DFIR Lead

Job in Yonkers, Westchester County, New York, 10701, USA
Listing for: Greenhouse Software, Inc.
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

We are inviting you, a highly motivated and results-oriented
Incident Response & DFIR Lead
to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities
  • Lead incident response, containment and forensic coordination for confirmed security incidents
  • Act as Incident Commander for major security incidents within the defined authority model
  • Assign incident roles and maintain clear ownership of investigation, containment and recovery actions
  • Maintain incident timelines, evidence logs, decision logs and action tracking
  • Coordinate investigation across endpoints, servers, identities, cloud platforms, SaaS environments and relevant network telemetry
  • Direct forensic collection and analysis required to determine attack path, scope, persistence and impact
  • Coordinate containment actions with IAM, Platform, IT, Security Engineering, Product and other technical owners
  • Recommend high-impact containment decisions to the Group Manager of Cyber Defense and CISO where required
  • Coordinate eradication and recovery activities and ensure systems return to a sufficiently trusted state
  • Ensure relevant evidence is preserved for Legal, HR, regulatory, disciplinary and post-incident requirements
  • Maintain practical forensic and evidence-handling standards
  • Develop and maintain incident playbooks, forensic checklists and containment procedures
  • Lead post-incident reviews and root-cause analysis
  • Ensure post-incident remediation actions have accountable owners, due dates and follow-up
  • Identify telemetry, detection and forensic-readiness gaps exposed during investigations
  • Convert investigation findings into recommendations for Detection Engineering, IAM, Security Engineering, Product Security and other control owners
  • Support incident exercises and readiness testing
  • Develop and mentor Incident Response / DFIR Specialists
  • Coordinate with external forensic, incident-response or specialist providers where required
  • Provide concise incident updates to Cyber Defense leadership, CISO and relevant stakeholders
Requirements
  • Strong hands-on knowledge of the incident response lifecycle: investigation, containment, eradication, recovery and lessons learned
  • Experience leading complex security incidents and coordinating multiple technical teams during active response
  • Practical experience investigating endpoint, identity, server, cloud or network compromise using EDR/XDR, SIEM and relevant audit logs
  • Ability to reconstruct attacker activity, including initial access, credential abuse, persistence, privilege escalation, lateral movement, data access and exfiltration
  • Working knowledge of digital forensics, evidence preservation, forensic timelines and chain-of-custody principles
  • Experience designing and validating containment actions such as endpoint isolation, account/session revocation, credential rotation, blocking indicators, network restrictions and service isolation
  • Experience with Microsoft Entra  / Active Directory incident investigation
  • Understanding of common incident scenarios including ransomware, malware, phishing/BEC, account takeover, cloud/SaaS compromise, data exfiltration and insider misuse
  • Strong understanding of Windows, Linux, identity and enterprise networking from an investigation perspective
  • Ability to document technical findings, timelines, evidence, assumptions and containment recommendations clearly
Will be a plus
  • Hands-on experience with Cortex XDR, Elastic Security or equivalent enterprise platforms
  • Experience investigating AWS or other cloud environments
  • Experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, FTK or equivalent
  • Experience investigating ransomware, BEC, insider-threat or cloud-account-compromise cases
  • Experience developing or improving incident response playbooks and containment procedures
  • Experience running tabletop or cyber incident exercises
  • Experience working with Legal, Privacy, HR or regulators during security incidents
  • Experience managing external DFIR or incident-response retainers
  • Python, Power Shell or other scripting experience useful for investigation and evidence processing
  • Experience in fintech, payments, brokerage, trading, banking or another regulated environment
  • Relevant certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, CISSP or equivalent
We offer
  • 20 paid vacation days per…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary