
Senior Incident Response Consultant
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in Virginia.
• Conduct technical investigations related to forensic hosts, networks, and applications.
• Evaluate active high-stakes security incidents, including assessing and implementing security measures to detect, respond to, prevent, and remedy threats.
• Identify and document attacker tools, tactics, and procedures as indicators of compromise (IOCs) for use in ongoing and future investigations.
• Create custom scripts, tools, or methodologies to improve our Incident Response (IR) processes.
• Generate detailed and accurate reports on forensic findings and IR activities tailored for both technical and executive audiences.
• Convey investigative findings and strategies to various stakeholders within client organizations.
• Offer immediate, actionable advice to contain and reduce the impact of ongoing attacks.
• Assist in defining new engagement scopes and lead clients through the entire incident response lifecycle.
• Collaborate directly with client IT teams to aid in rebuilding, reconfiguring, and remediation efforts.
• Provide remote guidance to clients on EDR deployments, system configuration modifications, and technical recovery procedures.
• Support the entire incident response lifecycle from initial discovery through to final reporting.
• Participate in an on-call rotation to deliver incident response support during off-hours and weekends as required.
• Extensive experience in a forensic and incident response position.
• Strong foundation in systems or network administration.
• Practical experience with Active Directory administration and troubleshooting.
• Background in responding to ransomware or intricate security incidents.
• Capability to work directly with clients under high-pressure circumstances.
• Proven ability to analyze incidents and propose effective remediation strategies and countermeasures.
• Experience in a technical consulting or client-facing role.
• Preferred certifications include GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), MCFE, EnCE, or equivalent credentials.
• Comprehensive medical, dental, vision, disability, FSA, HSA, life, and AD&D insurance.
• 401(k) Plan.
• Generous time off policy including PTO, sick leave, holidays, and parental leave details available.
Sprout Social, Inc.
Premier Inc.
Devoir Software Solutions
Get handpicked remote jobs straight to your inbox weekly.