Incident Response Lead

atHarbor ITRemoteUS flagUnited StatesFull-timeUncategorizedSenior$105k – $135k/year

Posted 4 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the incident commander for security incidents involving clients.

• Define the scope, prioritize responses, assign tasks to designated owners, monitor decisions, and ensure the progression of incidents.

• Conduct triage and initial investigations across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline.

• Delegate information gathering while concentrating on incident-command decisions.

• Make containment decisions regarding isolation, credential resets, evidence preservation, and client approval authority.

• Determine whether incidents fall within Harbor’s scope or need to be escalated to external DFIR firms, breach counsel, or insurance panels.

• Manage in-scope incidents from detection through to post-incident reporting.

• Brief receiving DFIR firms and transfer responsibility with a documented timeline and evidence inventory.

• Maintain on-call responsibilities and be available outside of business hours for incident escalation.

• Convert technical findings into actionable decisions for stakeholders, executives, and general counsel.

• Collaborate with breach counsel, cyber insurance carriers, panel firms, third-party DFIR teams, client IT, and law enforcement when necessary.

• Keep Client Success and leadership updated on ongoing incidents.

• Create post-incident reports detailing confirmed and presumed facts, containment actions, outstanding issues, and suggested changes for the client.

• Write and update incident response playbooks, severity models, and escalation matrices.

• Clearly define Harbor’s incident-response responsibilities in writing.

• Develop strong working relationships with external DFIR firms and breach counsel practices.

• Maintain records for escalation-readiness for every managed client.

• Conduct tabletop exercises with Harbor teams and clients when appropriate and feasible.

• Mentor SOC analysts and security engineers on investigative techniques and incident discipline.

• Provide feedback on incident lessons to detection engineering to enhance future detection capabilities.


⛳️ Requirements

• Over 6 years of experience in cybersecurity, with significant time dedicated to responding to actual intrusions rather than solely monitoring.

• Proven experience leading security incidents, providing direction while others carry out tasks.

• Experience in responses across various distinct organizations, whether from consulting, MSSP, MDR, or panel DFIR backgrounds.

• Hands-on investigative expertise in Microsoft 365, Google Workspace, and Entra ID compromises.

• Familiarity with unified audit log analysis, message tracing, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access vulnerabilities.

• Proficient in using endpoint detection and response tools for both investigation and containment.

• Knowledge of host and Windows internals sufficient to analyze process lineage, persistence mechanisms, and evidence of lateral movement.

• Ability to construct defensible incident timelines using SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets.

• Practical understanding of ransomware and hands-on intrusion tradecraft.

• Experience collaborating with breach counsel, cyber insurance carriers, or third-party DFIR firms during live incidents, including investigation handoffs.

• Capable of briefing non-technical executives under pressure and writing clear, actionable documentation for clients.

• Willingness and ability to be available outside of business hours for incident escalation.

• Preferred: GCIH, GCFA, GCIA, or similar GIAC certification; CISSP or CISM.

• Preferred: previous experience at a panel DFIR firm, MDR provider, or MSSP incident response team.

• Preferred: experience in host and memory forensics, malware triage, or reverse engineering.

• Preferred: Linux investigation experience and cloud incident response skills beyond Microsoft, such as AWS.

• Preferred: knowledge of HIPAA, PCI DSS, GLBA, state breach notification laws, or SEC disclosure regulations.

• Preferred: background in managed services or another multi-tenant environment where the candidate was responsible for both the relationship and investigation.


🏝️ Benefits

• Employer-covered medical, dental, and vision insurance for the employee, with additional premium plan options available.

• 401(k) plan with company matching.

• Paid time off.

• Reimbursement for approved tuition, certifications, and conference attendance.

People also viewed

Power Digital Marketing13 hours ago

Programmatic Media Strategist

CO flagColombia, +2 more countriesFull-timeUncategorized
ApplyView job
Ciena13 hours ago

Customer Order Fulfillment Specialist

GB flagUnited Kingdom OnlyFull-timeUncategorized
ApplyView job
Johnson & Johnson14 hours ago

Principal, Threat Detection – Response

ES flagSpain, +2 more countriesFull-timeUncategorized
ApplyView job
BlueCross BlueShield of Tennessee14 hours ago

Care Coordinator

US flagTennessee OnlyFull-timeUncategorized
ApplyView job
Akamai Technologies14 hours ago

Emerging Talent Intern

ES flagSpain OnlyPart-timeUncategorized
ApplyView job
GE HealthCare14 hours ago

Project Specialist

US flagUnited States OnlyFull-timeUncategorized$80k – $120k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers