Incident Response Lead
Job description
We are seeking an experienced incident response lead to manage and coordinate cybersecurity incident response activities. The ideal candidate will have hands-on experience in digital forensics and incident response (DFIR), investigating security incidents, conducting root cause analysis, and leading containment, eradication, and recovery efforts in enterprise environments.
Key responsibilities
- Lead the investigation and response to cybersecurity incidents.
- Perform incident triage, analysis, containment, eradication, and recovery.
- Conduct digital forensic investigations and root cause analysis.
- Coordinate with SOC, security engineering, IT, and business teams during security incidents.
- Develop and maintain incident response playbooks and procedures.
- Analyze malware, phishing attacks, ransomware, and other cyber threats.
- Prepare incident reports and provide recommendations to prevent future incidents.
- Support threat hunting and continuous improvement of incident response capabilities.
- Ensure compliance with organizational security policies and industry best practices.
Requirements
- 5–7 years of experience in cybersecurity.
- Hands-on experience in incident response and digital forensics (DFIR).
- Experience investigating security incidents in an enterprise environment.
- Knowledge of malware analysis, ransomware, phishing, and threat detection.
- Experience with SIEM, EDR, and security monitoring tools.
- Strong understanding of Windows, Linux, networking, and security fundamentals.
- Excellent analytical, troubleshooting, and communication skills.
Nice to have
- Certifications such as GCFA, GCIH, GCFE, CHFI, CEH, CySA+, or Security+.
- Experience with cloud security incident response (Azure, AWS, or GCP).
- Scripting experience (PowerShell or Python).