Incident Response Specialist
Posted 30 days ago
cyberoneNew York (NY)
Information Security AnalystsComputer Systems Design Services
SENIORITY
Senior
About the role
Incident Response Specialist PH - Fully RemoteThe Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.What You'll Do Incident ResponseInvestigate cyber security incidents affecting customer environments.Analyse endpoint, network, cloud and identity-based evidence.Perform host-based investigations across Windows and Microsoft 365 environments.Support containment, eradication and recovery activities.Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.Collect, preserve and analyse forensic artefacts where appropriate.Produce Indicators of Compromise (IOCs) and detection recommendations.Support evidence collection for regulatory or legal requirements.Technical InvestigationAnalyse Microsoft Defender XDR telemetry.Investigate Microsoft Sentinel incidents.Review Windows Event Logs and Sysmon data.Analyse Entra ID sign-in and audit logs.Investigate Exchange Online activity.Perform malware triage and basic static analysis.Review firewall, proxy, VPN and authentication logs.Conduct threat hunting activities across customer environments.Customer EngagementParticipate in customer investigation calls.Explain technical findings to both technical and non-technical audiences.Produce high-quality investigation reports.Provide remediation recommendations.Support post-incident lessons learned workshops.Proactive ServicesIncident Response Readiness AssessmentsTabletop ExercisesThreat Hunting engagementsThreat Intelligence servicesSecurity posture reviewsAI security investigations where requiredContinuous ImprovementDevelop new investigation playbooks.Improve Incident Response procedures.Contribute to internal knowledge sharing.Support development of detection content.Assist with automation opportunities using Microsoft and AI technologies.Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.What We're Looking For EssentialRelevant experience in Cyber Security or Incident Response.Strong English communication skills.AdvantageousSC-200 Microsoft Security Operations AnalystSC-100 Cybersecurity ArchitectAZ-500 Microsoft Azure Security TechnologiesGCIHGCFAGNFACompTIA Security+CREST Practitioner or equivalent
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
