
Senior Incident Response Analyst, MDR
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Canada.
• Assist Managed Detection and Response (MDR) clients within the Critical Incident Response Team (CIRT)
• Lead intricate investigations involving sophisticated adversaries, multi-vector intrusions, or cross-environment compromises
• Act as the primary Incident Advisor or appointed Commander for high-severity incidents
• Direct and coordinate investigative, forensic, and containment efforts among multiple analysts
• Establish engagement strategies, investigative priorities, and containment methods based on risk and impact
• Validate and consolidate technical findings into clear, actionable recommendations for customers and internal stakeholders
• Offer technical mentorship and oversight to IR and SOC analysts
• Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to confirm detections and address visibility gaps
• Lead or contribute to post-incident reviews, enhancing playbooks, tools, and response workflows
• Keep accurate records of time and activities to support operational visibility and capacity planning
• Over 5 years of experience in incident response, MDR, or cybersecurity investigations, including leadership of complex incidents
• Advanced knowledge in endpoint and network forensics, log analysis, and adversary tactics
• Strong comprehension of enterprise network architecture and IT infrastructure
• Proven capacity to lead investigations, validate findings, and devise effective containment strategies
• Experience in conveying technical findings to clients, including senior and executive stakeholders
• Demonstrated mentorship and leadership capabilities across incident response teams
• Ability to function effectively under high-pressure, time-sensitive scenarios
• Willingness to work occasional weekends and holidays as part of a rotation
• Advanced incident response or forensic certifications (GCFA, GCED, GCIH, OSCP, or equivalent) — preferred
• Experience serving as Incident Advisor or Commander during critical engagements — preferred
• Contributions to publications, presentations, or recognized efforts within the cybersecurity community — preferred
• Experience influencing detection strategies, tooling enhancements, or service design — preferred
• Strong customer-facing skills with experience briefing executives during incidents — preferred
• Legal authorization to work in Canada without requiring employer sponsorship
• Bonus eligibility
• Comprehensive benefits package
• Remote-first working model
• Employee-led diversity and inclusion networks
• Annual charity and fundraising initiatives
• Volunteer days
• Global employee sustainability initiatives
• Global fitness and trivia competitions
• Global wellbeing days
• Monthly wellbeing webinars and training
• Equality of opportunity and recruitment adjustments where needed
Hempel A/S
Hempel A/S
RTX
FLYACTS • Venture Studio für erfahrene Unternehmer
Get handpicked remote jobs straight to your inbox weekly.