Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Response Specialist

CyberOne

Incident Response Specialist

PH - Fully Remote

The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.

Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.

The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.

This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.

What You'll Do

Incident Response

  • Investigate cyber security incidents affecting customer environments.
  • Analyse endpoint, network, cloud and identity-based evidence.
  • Perform host-based investigations across Windows and Microsoft 365 environments.
  • Support containment, eradication and recovery activities.
  • Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.
  • Collect, preserve and analyse forensic artefacts where appropriate.
  • Produce Indicators of Compromise (IOCs) and detection recommendations.
  • Support evidence collection for regulatory or legal requirements.

Technical Investigation

  • Analyse Microsoft Defender XDR telemetry.
  • Investigate Microsoft Sentinel incidents.
  • Review Windows Event Logs and Sysmon data.
  • Analyse Entra ID sign-in and audit logs.
  • Investigate Exchange Online activity.
  • Perform malware triage and basic static analysis.
  • Review firewall, proxy, VPN and authentication logs.
  • Conduct threat hunting activities across customer environments.

Customer Engagement

  • Participate in customer investigation calls.
  • Explain technical findings to both technical and non-technical audiences.
  • Produce high-quality investigation reports.
  • Provide remediation recommendations.
  • Support post-incident lessons learned workshops.

Proactive Services

  • Incident Response Readiness Assessments
  • Tabletop Exercises
  • Threat Hunting engagements
  • Threat Intelligence services
  • Security posture reviews
  • AI security investigations where required

Continuous Improvement

  • Develop new investigation playbooks.
  • Improve Incident Response procedures.
  • Contribute to internal knowledge sharing.
  • Support development of detection content.
  • Assist with automation opportunities using Microsoft and AI technologies.

Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.

What We're Looking For

Essential

  • Relevant experience in Cyber Security or Incident Response.
  • Strong English communication skills.

Advantageous

  • SC-200 Microsoft Security Operations Analyst
  • SC-100 Cybersecurity Architect
  • AZ-500 Microsoft Azure Security Technologies
  • GCIH
  • GCFA
  • GNFA
  • CompTIA Security+
  • CREST Practitioner or equivalent
Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the Incident Response Specialist in United States vacancy
  • Perform cyber incident response duties, as well as, post notification coordinate/respond to all cyber related incidents and events. Actions include, 24x7x365 monitoring of Security Information and Event Management (SIEM) and other cyber tools used for identifying, diagnosing... 
    Suggested
    Full time
    Contract work
    For contractors

    Cdit

    Scott Air Force Base, IL
    17 hours ago
  •  ...Incident Response Specialist Job Number: 25-05356 Use your skills where innovative technology solutions begin. ECLARO is looking for an Incident Response Specialist for our client in Fountain Valley, CA. ECLARO's client is a leading technology solutions... 
    Suggested

    Eclaro

    Fountain Valley, CA
    2 days ago
  • $40 per hour

     ...contribute to improving AI security models with your hands-on experience in cybersecurity roles such as penetration testing and incident response. A bachelor's degree is preferred, and certifications are a plus. This position offers flexibility in project selection and a... 
    Suggested
    Hourly pay
    Remote work

    DataAnnotation

    Springfield, IL
    1 day ago
  • $99k - $125k

     ...Specialist II, Cybersecurity Operations/Incident Response Location: Euclid - 22801 Employment Status: Salary Full-Time Function: Information Technology Pay Grade and Range: AIT070-P3 ($99,000 - $125,000) Bonus Plan: AIP Target Bonus: 10.0 Recruiter: Allison Schock Internal... 
    Suggested
    Full time
    Local area
    Remote work

    Lincoln Electric

    Euclid, OH
    1 day ago
  •  ...We are seeking a skilled Incident Response Specialist to join our Cybersecurity Operations team. In this role, you will be responsible for detecting, investigating, responding to, and recovering from cybersecurity incidents affecting enterprise systems and networks. The... 
    Suggested

    Mybridge

    Arlington, VA
    4 days ago
  •  ...Creative Artists Agency in Los Angeles is seeking a Cyber Security professional for a hands-on role focused on Threat Detection and Incident Response. The successful candidate will ensure the protection of enterprise systems and data. This fast-paced position requires strong... 

    Creative Artists Agency

    Los Angeles, CA
    4 days ago
  •  ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions, helping restore normal operations quickly and reduce impact on mission‑critical systems. The role serves as the central coordination point for incident response... 
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Frankfort, KY
    2 days ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates disciplined war rooms, enforces cadence and runbooks, drives cross-team collaboration, and provides executive-ready communications... 
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Raleigh, NC
    5 hours ago
  •  ...Federal Services Company in Bismarck, North Dakota, is seeking an Incident Manager to oversee the lifecycle of IT incidents in an...  ...Bachelor’s degree and 1–3 years of relevant experience. Key responsibilities include monitoring incident resolution and conducting post-incident... 

    ASM Research, An Accenture Federal Services Company

    Bismarck, ND
    17 hours ago
  • $20 per hour

     ...Job Description Job Description Incident Response Specialist Alarm Systems Monitor License Required or be willing to obtain, a Texas Alarm Systems Monitor License. Position Summary First Responder Protective Services (FRPS) is hiring full-time Incident Response... 
    Hourly pay
    Weekly pay
    Full time
    Shift work
    Night shift
    Weekend work

    First Responder Protective Services Corp

    Frisco, TX
    7 days ago
  • $62.2k - $105.7k

     ...Research, An Accenture Federal Services Company in Atlanta seeks an Incident Manager to oversee the end-to-end lifecycle of IT incidents....  ...teams to ensure minimal disruption to critical systems. Responsibilities include leading incident response, conducting reviews, and... 

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    17 hours ago
  • $62.2k - $105.7k

     ...Research, An Accenture Federal Services Company, is seeking an Incident Manager in Denver, Colorado. This role requires overseeing the...  ...will coordinate cross-functional teams, manage incident responses based on impact and urgency, and drive continual service improvement... 

    ASM Research, An Accenture Federal Services Company

    Denver, CO
    4 days ago
  •  ...Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency engagements and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret clearance, a minimum... 
    Work at office

    CORTEK Inc

    Washington DC
    17 hours ago
  • $62.2k - $105.7k

     ...ASM Research is seeking an Incident Manager to oversee the end-to-end lifecycle of IT incidents in Hartford, Connecticut. The role...  ...ensure rapid restoration of services with minimal disruption. Responsibilities include leading incident response, monitoring service levels,... 

    ASM Research, An Accenture Federal Services Company

    Hartford, CT
    17 hours ago
  • $140k - $170k

     ...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; Washington, DC, United States CRA is a leading global consulting firm that provides independent... 
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Boston, MA
    4 days ago
  •  ...Sentar is seeking a Tier 3 Incident Response Senior Analyst in Quantico, VA! Role Description Sentar is hiring a Tier 3 Incident Response Senior Analyst who will be responsible for incident response activities throughout the Enterprise. This position will support an active... 
    Contract work
    Temporary work
    Work experience placement
    Remote work
    Flexible hours
    Weekend work

    Sentar

    Virginia, MN
    17 hours ago
  •  ...base plus 10.5% bonus depending on level of experience. No visa sponsorship. Job Description Continue to develop the company's incident response program. Utilize and adhere to defined workflow and processes driving Incident Response and mitigation efforts. Provide root... 
    Work at office
    Local area
    Remote work
    Relocation
    Visa sponsorship

    Niche Talent Finders

    Chicago, IL
    3 days ago
  •  ...MDAEdge is seeking a cybersecurity professional to handle incidents and strengthen enterprise security while working remotely from the U.S. The role involves managing incident response, collaborating with teams, and ensuring compliance with security standards. Ideal candidates... 
    Remote work

    MDAEdge

    Kansas City, MO
    17 hours ago
  •  ...support SBA in Washington, DC. The role requires the ability to obtain a Public Trust and will involve monitoring, analysis, and incident response within a federal government context. The position emphasizes security event monitoring, threat detection, and collaboration... 

    Koniag Government Services

    Washington DC
    3 days ago
  • Job Description Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems, identify and provide recommendations for remediation Formulate and direct incident response efforts, prioritize those... 

    Check Point Software Technologies

    Dallas, TX
    1 day ago
  •  ...Mindlance is seeking a highly skilled Incident Response Analyst to detect and respond to security incidents. The role involves monitoring security alerts, conducting in-depth analyses, and leading response efforts for client security breaches. The ideal candidate should... 

    Mindlance

    Arlington Heights, IL
    4 days ago
  •  ...you’re excited to work at the forefront of AI-driven security on a global scale, this is the place to do it. Key Responsibilities Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems,... 
    Worldwide

    Check Point Software

    Dallas, TX
    4 days ago
  •  ...team, contributing not only your experience in analyzing security-critical incidents but also helping to further develop our Security Operations Center. With a sense of personal responsibility and team spirit, you will be an indispensable member of our team, identifying... 
    Work from home
    Flexible hours

    Possehl Secure

    New Bremen, OH
    17 hours ago
  •  ...Trace3 is looking for a SOC Analyst located in Kansas City, KS. In this role, you will be responsible for monitoring, detecting, and responding to cybersecurity incidents. Key tasks include analyzing security events from various technologies, documenting incidents, and... 

    Trace3

    Kansas City, KS
    4 days ago
  •  ...Responsibilities Lead high‑fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats. Own complex incident investigations, driving technically precise conclusions and elevating the organization’s detection and... 

    Jobtailor

    Florham Park, NJ
    1 day ago
  • $120k - $135k

     ...has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will... 
    Permanent employment
    Contract work
    Remote work
    2 days per week

    Tetrad-Digital-Integrity-LL

    Arlington, VA
    2 days ago
  •  ...an impact and help shape what’s next? Join us! Explore opportunities at dnb.com/careers We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This... 
    Worldwide

    Dun-

    Florham Park, NJ
    2 days ago
  •  ...2 years of experience in SOC or cybersecurity operations and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify threats. This role involves continuous improvement of security... 
    Remote work

    Global Channel Management

    Atlanta, GA
    2 days ago
  • $100k - $120k

     ...projects in line with local, state and federal guidelines and regulations. About this position: Sr. Cybersecurity Incident Response Specialist Location – Washington, DC The Essential Duties and Responsibilities are intended to present a descriptive list of... 
    Full time
    Contract work
    Work at office
    Local area

    BERING STRAITS PROFESSIONAL SERVICES LLC

    Washington DC
    26 days ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we need real incident responders to help get it right. As an Incident Response Analyst, you'... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Response Specialist. Be the first to apply!