
Senior Incident Response Analyst
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States.
• Take full ownership of tier-1 and tier-2 incidents from start to finish, encompassing detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
• Independently conduct forensic investigations across hosts, memory, networks, cloud environments, and identities.
• Analyze EDR and SIEM telemetry, develop and refine queries, create correlation logic, and reconstruct timelines for incidents.
• Participate in the IR on-call rotation and exercise designated containment authority within specified thresholds.
• Create and revise IR playbooks based on incidents you have personally managed.
• Facilitate post-incident reviews and ensure all findings are tracked to closure.
• Automate or utilize AI assistance for repetitive triage and evidence collection tasks.
• Compose defensible technical timelines and executive summaries.
• Meet established goals for onboarding, incident ownership, forensic capabilities, playbooks, reviews, MTTD, and MTTR.
• Between 6 to 8 years of practical security experience, primarily in incident response and/or digital forensics.
• Proven ability to manage the complete incident lifecycle, from validation of detection to post-incident reviews.
• Extensive knowledge of digital forensics across host/disk, memory, network, cloud, and identity, grounded in real casework.
• Proficient in EDR/EPP, including investigations of endpoint telemetry, response actions, and tool tuning.
• Thorough understanding of SIEM, including query writing, correlation logic, and timeline reconstruction from log data.
• Hands-on experience with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, and Wireshark.
• Strong evidence handling discipline, ensuring chain of custody, proper acquisition, and documentation that meets legal, regulatory, and client standards.
• Familiarity with MITRE ATT&CK principles as applied in actual investigations.
• Proficiency in scripting for investigations and automation using Python, PowerShell, or similar languages.
• Demonstrated practical use of AI tools such as Claude, ChatGPT, or Copilot in security-related tasks.
• Good judgment regarding AI and sensitive data, including PHI, credentials, and telemetry.
• Capability to produce both technical incident timelines and executive summaries.
• Willingness to engage in a shared IR on-call rotation.
• A specific degree is not a prerequisite.
• Medical, Dental, and Vision plans.
• Flexible Spending/Health Savings Accounts.
• Flexible PTO.
• 401(k) with Company Match.
• Life Insurance.
• Pet insurance.
Workster
AIT Worldwide Logistics
ICON plc
Get handpicked remote jobs straight to your inbox weekly.