Incident Responder (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Incident Responder (Cybersecurity): Leading end-to-end investigations and advancing detection capabilities for cloud environments with an accent on MSSP management, threat hunting, and AI-assisted triage. Focus on designing durable detections in Microsoft Sentinel and optimizing response workflows to scale security impact.
Location: Remote (Must be based in the US)
Salary: $108,400 - $122,000 USD
Company
delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials.
What you will do
- Own security incidents end-to-end, from MSSP escalation validation through containment and recovery.
- Conduct proactive threat hunts across cloud and endpoint telemetry to create durable detections.
- Build and tune detection content within Microsoft Sentinel and the broader cloud security stack.
- Develop enrichment and response workflows to accelerate response times and reduce manual effort.
- Apply AI-assisted approaches to triage, investigation, and detection authoring.
- Manage and strengthen the MSSP relationship by providing feedback and tuning alerting thresholds.
Requirements
- Proven experience in incident response and security operations in Azure and AWS cloud-native environments.
- Hands-on expertise with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering.
- Experience managing MSSP escalations, providing quality feedback, and closing coverage gaps.
- Ability to build SOAR playbooks, scripting, and enrichment workflows to support security operations.
- Strong command of MITRE ATT&CK, cyber kill chain, networking fundamentals, and identity systems (Active Directory, Entra ID).
- Must be based in the United States.
Nice to have
- Familiarity with the Intelligence-Driven Incident Response approach.
- Experience interpreting network traffic and performing packet captures (tcpdump, Wireshark).
- Relevant certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty.
Culture & Benefits
- Remote-first culture with home office setup and remote work stipends.
- Flexible Paid Time Off policies, including quarterly Self-Care Days and Volunteer Days.
- Comprehensive health coverage including dependents.
- Annual learning stipend for continuous professional development.
- Parental leave and peer-to-peer recognition programs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →