The Senior Incident Response Analyst will play a critical role in investigating, containing, and remediating sophisticated cyber threats for organizations across multiple industries and regions. As part of a dedicated Critical Incident Response Team, you will lead active incident investigations, support Managed Detection and Response (MDR) customers, and collaborate with managed service providers to disrupt adversary activity. You will leverage advanced cybersecurity technologies and investigative techniques to analyze ransomware, malware, and other complex attacks. Working alongside threat intelligence, detection engineering, and threat hunting specialists, you will contribute to strengthening detection capabilities and improving incident response practices. This role also involves mentoring analysts, advising customers under pressure, and delivering clear technical reports that support effective recovery. It is an exciting remote opportunity for an experienced cybersecurity professional who thrives in a fast-paced environment and is passionate about defending organizations against evolving cyber threats.
Lead incident investigations: Investigate, analyze, and respond to active cybersecurity incidents using available security technologies and investigative methodologies to identify threats and disrupt malicious activity.
Contain and remediate cyber threats: Identify initial access methods, persistence mechanisms, lateral movement, and other adversary behaviors, providing actionable recommendations to contain attacks, neutralize threats, and support remediation.
Analyze malware and ransomware: Conduct in-depth investigations into ransomware, malware, and other common cyberattack types to determine their scope, impact, and associated indicators of compromise.
Support MDR customers and service providers: Work directly with customers and managed service providers through calls and meetings to explain incident findings, communicate response priorities, and provide clear technical guidance throughout investigations.
Perform endpoint and network investigations: Analyze security events across Windows, Linux, and macOS environments, investigating network activity, endpoint telemetry, and relevant security alerts to determine the extent of compromise.
Mentor and guide analysts: Provide technical guidance, investigation reviews, and escalation support to incident response analysts and MDR operations teams, helping strengthen investigative quality and response effectiveness.
Collaborate with security specialists: Partner with threat intelligence, detection engineering, threat hunting, and MDR operations teams to improve detection logic, share investigative findings, and enhance organizational response capabilities.
Maintain detailed investigation records: Document investigative procedures, evidence, findings, indicators of compromise, and response actions accurately to support transparency, reproducibility, and effective incident management.
Prepare technical incident reports: Produce comprehensive post-incident reports for customers and service providers, outlining the attack timeline, investigation results, impact, and recommended remediation measures.
Apply recognized threat frameworks: Use established cybersecurity frameworks and adversary behavior models to structure investigations, understand attack progression, and communicate findings consistently.
Improve incident response capabilities: Evaluate emerging technologies, tools, and processes to identify opportunities to improve investigation efficiency, response quality, and threat containment.
Contribute to threat research and knowledge sharing: Where appropriate, share technical insights through articles, blogs, social media, and other professional channels covering adversary tactics, techniques, procedures, and investigative findings.
Maintain high-quality customer service: Communicate clearly and professionally during high-pressure incidents, helping customers understand risks, prioritize actions, and make informed decisions.
Provide flexible incident coverage: Support incident response operations during occasional weekends and holidays when required to address urgent cybersecurity events.