
Incident Response Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Act as the incident commander for security incidents involving clients.
• Define the scope, prioritize responses, assign tasks to designated owners, monitor decisions, and ensure the progression of incidents.
• Conduct triage and initial investigations across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline.
• Delegate information gathering while concentrating on incident-command decisions.
• Make containment decisions regarding isolation, credential resets, evidence preservation, and client approval authority.
• Determine whether incidents fall within Harbor’s scope or need to be escalated to external DFIR firms, breach counsel, or insurance panels.
• Manage in-scope incidents from detection through to post-incident reporting.
• Brief receiving DFIR firms and transfer responsibility with a documented timeline and evidence inventory.
• Maintain on-call responsibilities and be available outside of business hours for incident escalation.
• Convert technical findings into actionable decisions for stakeholders, executives, and general counsel.
• Collaborate with breach counsel, cyber insurance carriers, panel firms, third-party DFIR teams, client IT, and law enforcement when necessary.
• Keep Client Success and leadership updated on ongoing incidents.
• Create post-incident reports detailing confirmed and presumed facts, containment actions, outstanding issues, and suggested changes for the client.
• Write and update incident response playbooks, severity models, and escalation matrices.
• Clearly define Harbor’s incident-response responsibilities in writing.
• Develop strong working relationships with external DFIR firms and breach counsel practices.
• Maintain records for escalation-readiness for every managed client.
• Conduct tabletop exercises with Harbor teams and clients when appropriate and feasible.
• Mentor SOC analysts and security engineers on investigative techniques and incident discipline.
• Provide feedback on incident lessons to detection engineering to enhance future detection capabilities.
• Over 6 years of experience in cybersecurity, with significant time dedicated to responding to actual intrusions rather than solely monitoring.
• Proven experience leading security incidents, providing direction while others carry out tasks.
• Experience in responses across various distinct organizations, whether from consulting, MSSP, MDR, or panel DFIR backgrounds.
• Hands-on investigative expertise in Microsoft 365, Google Workspace, and Entra ID compromises.
• Familiarity with unified audit log analysis, message tracing, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access vulnerabilities.
• Proficient in using endpoint detection and response tools for both investigation and containment.
• Knowledge of host and Windows internals sufficient to analyze process lineage, persistence mechanisms, and evidence of lateral movement.
• Ability to construct defensible incident timelines using SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets.
• Practical understanding of ransomware and hands-on intrusion tradecraft.
• Experience collaborating with breach counsel, cyber insurance carriers, or third-party DFIR firms during live incidents, including investigation handoffs.
• Capable of briefing non-technical executives under pressure and writing clear, actionable documentation for clients.
• Willingness and ability to be available outside of business hours for incident escalation.
• Preferred: GCIH, GCFA, GCIA, or similar GIAC certification; CISSP or CISM.
• Preferred: previous experience at a panel DFIR firm, MDR provider, or MSSP incident response team.
• Preferred: experience in host and memory forensics, malware triage, or reverse engineering.
• Preferred: Linux investigation experience and cloud incident response skills beyond Microsoft, such as AWS.
• Preferred: knowledge of HIPAA, PCI DSS, GLBA, state breach notification laws, or SEC disclosure regulations.
• Preferred: background in managed services or another multi-tenant environment where the candidate was responsible for both the relationship and investigation.
• Employer-covered medical, dental, and vision insurance for the employee, with additional premium plan options available.
• 401(k) plan with company matching.
• Paid time off.
• Reimbursement for approved tuition, certifications, and conference attendance.
Power Digital Marketing
Ciena
Johnson & Johnson
BlueCross BlueShield of Tennessee
Get handpicked remote jobs straight to your inbox weekly.