Incident Response Lead
Key Responsibilities
Lead the investigation and response to cybersecurity incidents.
Perform incident triage, analysis, containment, eradication, and recovery.
Conduct digital forensic investigations and root cause analysis.
Coordinate with SOC, Security Engineering, IT, and business teams during security incidents.
Develop and maintain incident response playbooks and procedures.
Analyze malware, phishing attacks, ransomware, and other cyber threats.
Prepare incident reports and provide recommendations to prevent future incidents.
Support threat hunting and continuous improvement of incident response capabilities.
Ensure compliance with organizational security policies and industry best practices.
Requirements
5–7 years of experience in cybersecurity.
Hands-on experience in incident response and digital forensics (DFIR).
Experience investigating security incidents in an enterprise environment.
Knowledge of malware analysis, ransomware, phishing, and threat detection.
Experience with SIEM, EDR, and security monitoring tools.
Strong understanding of Windows, Linux, networking, and security fundamentals.
Excellent analytical, troubleshooting, and communication skills.
Nice to Have
Certifications such as GCFA, GCIH, GCFE, CHFI, CEH, CySA+, or Security+.
Experience with cloud security incident response (Azure, AWS, or GCP).
Scripting experience (PowerShell or Python).