Incident Response Specialist
CyberOne
Incident Response Specialist
PH - Fully Remote
The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.
Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.
The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.
This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.
What You'll Do
Incident Response
- Investigate cyber security incidents affecting customer environments.
- Analyse endpoint, network, cloud and identity-based evidence.
- Perform host-based investigations across Windows and Microsoft 365 environments.
- Support containment, eradication and recovery activities.
- Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.
- Collect, preserve and analyse forensic artefacts where appropriate.
- Produce Indicators of Compromise (IOCs) and detection recommendations.
- Support evidence collection for regulatory or legal requirements.
Technical Investigation
- Analyse Microsoft Defender XDR telemetry.
- Investigate Microsoft Sentinel incidents.
- Review Windows Event Logs and Sysmon data.
- Analyse Entra ID sign-in and audit logs.
- Investigate Exchange Online activity.
- Perform malware triage and basic static analysis.
- Review firewall, proxy, VPN and authentication logs.
- Conduct threat hunting activities across customer environments.
Customer Engagement
- Participate in customer investigation calls.
- Explain technical findings to both technical and non-technical audiences.
- Produce high-quality investigation reports.
- Provide remediation recommendations.
- Support post-incident lessons learned workshops.
Proactive Services
- Incident Response Readiness Assessments
- Tabletop Exercises
- Threat Hunting engagements
- Threat Intelligence services
- Security posture reviews
- AI security investigations where required
Continuous Improvement
- Develop new investigation playbooks.
- Improve Incident Response procedures.
- Contribute to internal knowledge sharing.
- Support development of detection content.
- Assist with automation opportunities using Microsoft and AI technologies.
Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.
What We're Looking For
Essential
- Relevant experience in Cyber Security or Incident Response.
- Strong English communication skills.
Advantageous
- SC-200 Microsoft Security Operations Analyst
- SC-100 Cybersecurity Architect
- AZ-500 Microsoft Azure Security Technologies
- GCIH
- GCFA
- GNFA
- CompTIA Security+
- CREST Practitioner or equivalent
- Perform cyber incident response duties, as well as, post notification coordinate/respond to all cyber related incidents and events. Actions include, 24x7x365 monitoring of Security Information and Event Management (SIEM) and other cyber tools used for identifying, diagnosing...SuggestedFull timeContract workFor contractors
- ...Incident Response Specialist Job Number: 25-05356 Use your skills where innovative technology solutions begin. ECLARO is looking for an Incident Response Specialist for our client in Fountain Valley, CA. ECLARO's client is a leading technology solutions...Suggested
$40 per hour
...contribute to improving AI security models with your hands-on experience in cybersecurity roles such as penetration testing and incident response. A bachelor's degree is preferred, and certifications are a plus. This position offers flexibility in project selection and a...SuggestedHourly payRemote work$99k - $125k
...Specialist II, Cybersecurity Operations/Incident Response Location: Euclid - 22801 Employment Status: Salary Full-Time Function: Information Technology Pay Grade and Range: AIT070-P3 ($99,000 - $125,000) Bonus Plan: AIP Target Bonus: 10.0 Recruiter: Allison Schock Internal...SuggestedFull timeLocal areaRemote work- ...We are seeking a skilled Incident Response Specialist to join our Cybersecurity Operations team. In this role, you will be responsible for detecting, investigating, responding to, and recovering from cybersecurity incidents affecting enterprise systems and networks. The...Suggested
- ...Creative Artists Agency in Los Angeles is seeking a Cyber Security professional for a hands-on role focused on Threat Detection and Incident Response. The successful candidate will ensure the protection of enterprise systems and data. This fast-paced position requires strong...
- ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission‑critical systems. The role serves as the central coordination point for incident response...Contract workWork experience placementWork at officeShift work
- ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined war rooms, enforces cadence and runbooks, drives cross-team collaboration, and provides executive-ready communications...Contract workWork experience placementWork at officeShift work
- ...Federal Services Company in Bismarck, North Dakota, is seeking an Incident Manager to oversee the lifecycle of IT incidents in an... ...Bachelor’s degree and 1–3 years of relevant experience. Key responsibilities include monitoring incident resolution and conducting post-incident...
$20 per hour
...Job Description Job Description Incident Response Specialist Alarm Systems Monitor License Required or be willing to obtain, a Texas Alarm Systems Monitor License. Position Summary First Responder Protective Services (FRPS) is hiring full-time Incident Response...Hourly payWeekly payFull timeShift workNight shiftWeekend work$62.2k - $105.7k
...Research, An Accenture Federal Services Company in Atlanta seeks an Incident Manager to oversee the end-to-end lifecycle of IT incidents.... ...teams to ensure minimal disruption to critical systems. Responsibilities include leading incident response, conducting reviews, and...$62.2k - $105.7k
...Research, An Accenture Federal Services Company, is seeking an Incident Manager in Denver, Colorado. This role requires overseeing the... ...will coordinate cross-functional teams, manage incident responses based on impact and urgency, and drive continual service improvement...- ...Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency engagements and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret clearance, a minimum...Work at office
$62.2k - $105.7k
...ASM Research is seeking an Incident Manager to oversee the end-to-end lifecycle of IT incidents in Hartford, Connecticut. The role... ...ensure rapid restoration of services with minimal disruption. Responsibilities include leading incident response, monitoring service levels,...$140k - $170k
...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; Washington, DC, United States CRA is a leading global consulting firm that provides independent...Work at officeLocal areaRemote workWork from home3 days per week- ...Sentar is seeking a Tier 3 Incident Response Senior Analyst in Quantico, VA! Role Description Sentar is hiring a Tier 3 Incident Response Senior Analyst who will be responsible for incident response activities throughout the Enterprise. This position will support an active...Contract workTemporary workWork experience placementRemote workFlexible hoursWeekend work
- ...base plus 10.5% bonus depending on level of experience. No visa sponsorship. Job Description Continue to develop the company's incident response program. Utilize and adhere to defined workflow and processes driving Incident Response and mitigation efforts. Provide root...Work at officeLocal areaRemote workRelocationVisa sponsorship
- ...MDAEdge is seeking a cybersecurity professional to handle incidents and strengthen enterprise security while working remotely from the U.S. The role involves managing incident response, collaborating with teams, and ensuring compliance with security standards. Ideal candidates...Remote work
- ...support SBA in Washington, DC. The role requires the ability to obtain a Public Trust and will involve monitoring, analysis, and incident response within a federal government context. The position emphasizes security event monitoring, threat detection, and collaboration...
- Job Description Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems, identify and provide recommendations for remediation Formulate and direct incident response efforts, prioritize those...
- ...Mindlance is seeking a highly skilled Incident Response Analyst to detect and respond to security incidents. The role involves monitoring security alerts, conducting in-depth analyses, and leading response efforts for client security breaches. The ideal candidate should...
- ...you’re excited to work at the forefront of AI-driven security on a global scale, this is the place to do it. Key Responsibilities Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems,...Worldwide
- ...team, contributing not only your experience in analyzing security-critical incidents but also helping to further develop our Security Operations Center. With a sense of personal responsibility and team spirit, you will be an indispensable member of our team, identifying...Work from homeFlexible hours
- ...Trace3 is looking for a SOC Analyst located in Kansas City, KS. In this role, you will be responsible for monitoring, detecting, and responding to cybersecurity incidents. Key tasks include analyzing security events from various technologies, documenting incidents, and...
- ...Responsibilities Lead high‑fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats. Own complex incident investigations, driving technically precise conclusions and elevating the organization’s detection and...
$120k - $135k
...has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will...Permanent employmentContract workRemote work2 days per week- ...an impact and help shape what’s next? Join us! Explore opportunities at dnb.com/careers We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This...Worldwide
- ...2 years of experience in SOC or cybersecurity operations and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats. This role involves continuous improvement of security...Remote work
$100k - $120k
...projects in line with local, state and federal guidelines and regulations. About this position: Sr. Cybersecurity Incident Response Specialist Location – Washington, DC The Essential Duties and Responsibilities are intended to present a descriptive list of...Full timeContract workWork at officeLocal area- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we need real incident responders to help get it right. As an Incident Response Analyst, you'...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Specialist. Be the first to apply!
- amazon specialist United States
- specialist United States
- associate specialist United States
- ammunition specialist United States
- correctional behavioral specialist United States
- entry level safety specialist United States
- disclosure specialist United States
- erp specialist United States
- infection control specialist United States
- cash reconciliation specialist United States


