Назад
Company hidden
1 день назад

Senior Incident Response Analyst (CrowdStrike)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Incident Response Analyst (CrowdStrike): Owning tier-1 and tier-2 security incidents and conducting host, memory, network, cloud, and identity forensic investigations with an accent on evidence handling, EDR/SIEM analysis, and healthcare data protection. Focus on reconstructing incident timelines, exercising containment authority, authoring IR playbooks, and automating or AI-assisting triage and evidence collection.

Location: United States — Remote

Company

hirify.global provides telehealth support solutions that help companies deliver virtual patient care across all 50 states.

What you will do

  • Own tier-1 and tier-2 incidents through detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
  • Conduct host, memory, network, cloud, and identity forensic investigations with defensible evidence handling.
  • Investigate EDR and SIEM telemetry, write queries, build correlation logic, and reconstruct incident timelines.
  • Participate in the IR on-call rotation and exercise authorized containment actions such as host isolation and session revocation.
  • Author and update incident-response playbooks and track post-incident findings to closure.
  • Automate or AI-assist repetitive triage and evidence-collection work while producing technical timelines and executive summaries.

Requirements

  • 6–8 years of hands-on security experience, primarily in incident response and/or digital forensics.
  • Demonstrated ownership of the full incident lifecycle and independent investigations across host/disk, memory, network, cloud, and identity environments.
  • Working depth with EDR/EPP and SIEM platforms, including endpoint response, query authoring, correlation logic, and timeline reconstruction.
  • Hands-on fluency with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
  • Knowledge of evidence handling, chain of custody, MITRE ATT&CK, and investigation scripting with Python, PowerShell, or similar.
  • Demonstrated use of AI tools in security work, sound judgment regarding sensitive data, clear incident writing, and willingness to join the shared on-call rotation.

Nice to have

  • CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, and Falcon Shield experience.
  • AWS incident response using CloudTrail, GuardDuty, and IAM investigation techniques.
  • Okta identity investigations involving session hijacking, MFA fatigue, token theft, or SSO abuse.
  • Healthcare, fintech, or other regulated-industry experience, including HIPAA, HITRUST, or SOC 2 breach workflows.
  • Malware triage, SOAR or AI-assisted IR workflows, threat intelligence, IR program maturity, or relevant certifications and community contributions.

Culture & Benefits

  • Remote work within the United States.
  • Flat organizational structure with autonomy to contribute ideas and implement improvements.
  • Medical, dental, and vision plans.
  • Flexible Spending Accounts or Health Savings Accounts, flexible PTO, and a 401(k) with company match.
  • Life insurance, pet insurance, and additional benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →