Lastpass
Lastpass11h ago
New
USD 108400-122000/yr

Incident Responder

United StatesUnited StatesRemotemid
OtherIncident Responder
0 views0 saves0 applied

Quick Summary

Key Responsibilities

In this senior role, you will lead investigations end-to-end and advance our detection capabilities. You will own MSSP escalations, conduct threat hunts,

Technical Tools
OtherIncident Responder

In this senior role, you will lead investigations end-to-end and advance our detection capabilities. You will own MSSP escalations, conduct threat hunts, and apply AI-assisted approaches — helping LastPass deliver on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected.

Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.

You will partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel, and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations. You will also work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.

  • Own security incidents end-to-end — receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
  • Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
  • Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team
  • Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact
  • Apply AI-assisted approaches to triage, investigation, detection authoring, and automation — helping the team adopt these capabilities responsibly and effectively
  • Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity
  • Document investigations thoroughly — capturing actions, evidence, timelines, and conclusions — to a standard that supports both technical follow-up and stakeholder communication
  • Manage and strengthen the MSSP relationship by providing feedback on escalation quality, tuning alerting thresholds, and contributing to lessons-learned reviews
  • Proven experience in incident response and security operations in cloud-native environments, with hands-on depth in Azure and AWS
  • Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
  • Proven experience working with an MSSP — managing escalations, providing quality feedback, and closing gaps in coverage — whether as client or vendor
  • Proven experience conducting threat hunts and building automation in support of security operations, including SOAR playbooks, scripting, and enrichment workflows
  • Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK, with solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID
  • Communicates clearly with both technical and non-technical stakeholders, exercises sound judgment under pressure, and operates effectively both independently and as part of a collaborative team
  • Commitment to continuous improvement — proactively contributing to detections, runbooks, tooling, and operational processes that raise the bar for the team
  • Familiarity with the Intelligence-Driven Incident Response approach, integrating threat intelligence into the detection, analysis, and response lifecycle
  • Experience interpreting network traffic and performing packet captures using tools such as tcpdump or Wireshark
  • Background in relevant industry certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty

Our compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.

US Pay Range
$108,400$122,000 USD
  • The leader in secure access
  • High-growth, collaborative environment with inclusive teams
  • Remote-first culture
  • Competitive compensation
  • Flexible Paid Time Off policies, including but not limited to: Quarterly Self-Care Days (4 extra paid days off annually) and Volunteer Days
  • Parental leave
  • Comprehensive health coverage, including dependents
  • Home office setup support
  • LastPass Families free account for up to 5 members
  • Continuous learning and development opportunities, including an annual learning stipend to invest in your growth
  • Peer-to-peer recognition through Motivosity
  • Employee Assistance Program for well-being support
  • Remote work stipend to support your home office needs
  • Short-Term or Remote-Centric Work Arrangements for added flexibility

Unlock your potential with us - your skills, experience, and unique perspective matter more than just checking the boxes. Apply today, and let's build the future together!

We’re building an inclusive community that reflects the people of all races, genders, sexual orientations, national origins, backgrounds, and perspectives who share our world.

For all US based jobs please review our Applicant Privacy Notice

For all EU based jobs please review our Candidate Privacy Notice 

Please review our CCPA Notice

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
Open to applicants worldwide

Listing Details

Posted
July 27, 2026
First seen
July 27, 2026
Last seen
July 27, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
87%
Scored at
July 27, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Lastpass
Lastpass
greenhouse

LastPass is a leading identity and password manager, streamlining secure access and management of passwords for millions globally.

Employees
750
Founded
2008
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

LastpassIncident ResponderUSD 108400-122000