Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Responder

Meriplex

Description Job Details Impact: This role leads high-severity incident response for client environments, reducing client downtime, containing ransomware and hands-on-keyboard intrusions, coordinating recovery resources across MSP teams, and maintaining clear, calm, executive-ready client communications during active incidents. Position Summary The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments. The role combines deep incident response expertise with practical leadership: directing technical containment, coordinating resources across SOC, service desk, infrastructure, cloud, networking, compliance, account management, and client leadership teams, and serving as a trusted communicator during high-pressure events. This position is hands-on and client-facing. The responder is expected to investigate endpoint, identity, cloud, email, network, and SaaS activity; determine scope and impact; recommend and execute containment and eradication steps; and translate technical findings into clear decisions, risks, and next steps for clients and internal stakeholders. The role also improves SOC maturity by mentoring analysts, refining incident response playbooks, leading post-incident reviews, supporting tabletop exercises, and driving measurable improvements in detection, response, documentation, and recovery readiness. Key Responsibilities/ Duties Lead end-to-end incident response for high-severity and complex incidents, including triage, validation, scoping, containment, eradication, recovery support, and post-incident review. Serve as technical incident lead and primary coordination point during major incidents, establishing response priorities, assigning actions, tracking decisions, and maintaining momentum across internal MSP/MSSP teams and client stakeholders. Conduct in-depth investigations of ransomware, business email compromise, credential compromise, endpoint malware, lateral movement, persistence, suspicious administrative activity, cloud compromise, and data exposure scenarios. Analyze telemetry from EDR/XDR, SIEM, identity providers, email security platforms, firewalls, cloud platforms, vulnerability tooling, remote management tools, and ticketing systems to determine root cause, timeline, blast radius, and recommended response actions. Develop, execute, and/or coordinate containment strategies such as host isolation, account disablement, token/session revocation, conditional access changes, firewall blocks, policy changes, IOC sweeps, and coordination of backup/recovery activities. Coordinate evidence preservation and documentation, including collection of logs, timelines, artifacts, screenshots, containment actions, chain-of-custody notes when needed, and incident decision records. Communicate incident status, risk, impact, and next steps clearly to technical and non-technical audiences, including client IT teams, client executives, internal leadership, account teams, legal/compliance stakeholders, and third-party partners. Prepare concise client-facing incident updates, executive summaries, post-incident reports, root cause summaries, corrective action plans, and lessons-learned documentation. Mentor Tier 1/Tier 2 SOC analysts and other technical teams on investigation methodology, escalation quality, containment standards, incident communications, and documentation expectations. Maintain and improve incident response playbooks, escalation procedures, severity models, incident templates, customer communication standards, and internal handoff processes. Support proactive threat hunting and detection engineering by converting incident learnings into improved SIEM queries, EDR detections, alert tuning, and response automation opportunities. Participate in the on-call rotation and support 24/7 incident response operations for urgent or critical-impact incidents. Contribute to security program maturity through tabletop exercises, operational readiness reviews, knowledge base articles, process improvements, and cross-department training. Perform other duties as assigned, including support for peak workloads, coverage needs, audits, and special security initiatives. Knowledge, Skills, Abilities, And Behaviors Advanced knowledge of incident response lifecycle activities, including detection, analysis, containment, eradication, recovery, and post-incident improvement. Strong technical investigation skills across Windows, macOS, Linux, Microsoft 365 / Entra ID, Azure, AWS or other cloud platforms, endpoint protection, network security, email security, and common MSP tooling. Experience with EDR/XDR and SIEM platforms such as SentinelOne, CrowdStrike, Microsoft Defender, Elastic/ELK, or comparable technologies. Ability to identify attack vectors, persistence mechanisms, credential abuse, lateral movement, privilege escalation, data staging/exfiltration indicators, and common ransomware tradecraft. Working knowledge of relevant frameworks and models such as NIST CSF, NIST SP 800-61, MITRE ATT&CK, CIS Controls, and cyber insurance or regulatory reporting considerations. Demonstrated leadership under pressure, with the ability to make risk-informed decisions, prioritize competing tasks, and coordinate technical and non-technical resources without creating unnecessary confusion or delay. Excellent customer communication skills, including the ability to explain incident facts, uncertainty, business risk, containment options, and recovery dependencies in plain language. Strong written documentation skills, including executive summaries, technical timelines, incident action plans, investigation notes, and corrective action recommendations. High degree of professionalism, discretion, integrity, and sound judgment when handling sensitive client data and high-impact security events. Continuous improvement mindset with willingness to mentor others, improve process quality, automate repeatable work, and strengthen SOC operational maturity. Education/ Experience 4+ years of cybersecurity experience, including SOC operations, threat hunting, detection engineering, or closely related defensive security functions. 2+ years of experience leading or coordinating incident response activities during high-priority incidents, preferably in an MSP, MSSP, consulting, or multi-client environment. Demonstrated experience communicating with customers, executives, technical teams, and cross-functional stakeholders during active incidents. Hands-on experience with endpoint, identity, cloud, email, and network investigations; ability to work directly in tools rather than only delegating technical analysis. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience preferred. Certifications GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), CISSP, CySA+, Microsoft SC-200, or equivalent certifications preferred. Offensive security or cloud-specific certifications such as OSCP, PNPT, Microsoft Certified: Cybersecurity Architect, or comparable credentials are a plus. Physical Demands Sedentary Work - Exerts up to 10 pounds of force occasionally, a negligible amount of force frequently, and/or constantly having to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Disclaimer The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. Meriplex Communications and Meriplex Solutions are Equal Employment Opportunity Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. #J-18808-Ljbffr Meriplex

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Incident Responder in Wisconsin vacancy
  • Meriplex Communications in the United States seeks a Cyber Incident Responder to lead high-severity incidents across client environments, guiding containment and recovery. This hands-on senior role coordinates across SOC, service desk, cloud, and client leadership, delivering... 
    Cyber

    Meriplex-Communication

    Wisconsin
    5 days ago
  • A cybersecurity firm is seeking a Cyber Security Analyst responsible for protecting the...  ...role demands strong analytical skills to respond effectively to threats. Ideal candidates...  ..., and be adept in security solutions and incident response. This position offers a dynamic... 
    Cyber

    thehivecareers.co

    Oregon, WI
    4 days ago
  • Meriplex is seeking a Cyber Incident Responder to lead high-severity incident response across client environments. The role combines hands-on technical work with leadership, directing containment, eradication, and recovery actions while coordinating resources across SOC... 
    Cyber

    Meriplex

    Wisconsin
    2 days ago
  • A technology services company is seeking a Cybersecurity Operations & Incident Response Manager in the Town of Texas, Wisconsin. This role involves leading a vital cybersecurity team, managing incident response across hybrid environments, and influencing technology decisions... 
    Cyber
    Remote work

    Jobgether

    Wisconsin
    3 days ago
  •  ...seeking a Director, CyberSecurity - Engineering, Operations and Incident Response to:Lead a talented team of cybersecurity professionals...  ...Awareness, IT General Controls Compliance & Audit Management, Cyber security programs, and Identity and Access Management. RequiredDemonstrated... 
    Cyber
    Full time
    For contractors
    Work experience placement
    Monday to Friday
    Shift work

    UW Hospitals & Clinics

    Madison, WI
    3 days ago
  • $66.9k - $82.1k

     ...Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity...  ...tools and service management platforms integrated with SOC and cyber defense functions. Certifications such as ITIL Foundation... 
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Madison, WI
    2 days ago
  • $162.68k - $200k

    Cybersecurity Operations & Incident Response Manager This position is posted by Jobgether on behalf of a partner company. We are currently...  ..., and SOC/MSSP oversight Familiarity with MITRE ATT&CK, cyber kill chain, threat‑led validation, and regulatory compliance frameworks... 
    Cyber
    Full time
    Remote work
    Flexible hours

    Jobgether

    Wisconsin
    3 days ago
  • $118.96k - $178.44k

     ...Engineering, Adversarial Simulation, Purple Team, Incident Command, and Governance, Risk &...  ...Engineer supports the hunt community across Cyber Defense, contributes engineering rigor to...  ...proactive and signal-driven hunts, respond to hunt questions from hunters across Cyber... 
    Cyber
    Full time

    Northwestern Mutual

    Milwaukee, WI
    14 hours ago
  •  ...networks and systems continuously to detect and respond to potential security threats and...  ...standards Investigate and respond to security incidents, ensuring timely resolution and minimal...  ...security solutions Track emerging cyber threats and proactively implement countermeasures... 
    Cyber

    Devitechs

    Wisconsin
    5 days ago
  •  ...assets, systems, and data from potential cyber threats and attacks. This role involves designing...  ...to execute both short-term actions / incidents and long-term projects to expand and...  ...alerts from various sources to detect and respond to potential security incidents.Review, tune... 
    Cyber
    Full time
    Temporary work
    Worldwide

    Elkay

    Milwaukee, WI
    2 days ago
  •  ...The Cyber Security Analyst will be responsible for protecting all of the companys hardware...  ...detail in order to detect, evaluate and respond to threats that could potentially breach...  ...threat intelligence. Conduct cyber security incident response, following industry standards of... 
    Cyber
    Work experience placement

    thehivecareers.co

    Oregon, WI
    4 days ago
  •  ...IT team. The role focuses on monitoring, detecting, and responding to cybersecurity incidents across distribution, retail, and corporate environments....  ...foundation, be analytical, detail-oriented, and stay ahead of evolving cyber threats. #J-18808-Ljbffr Jockey International
    Cyber

    Jockey International

    Kenosha, WI
    1 day ago
  • Cyber Security AnalystThe CompanyZurn Elkay Water Solutions Corporation is a thriving, values...  ...Management:Participate in and / or lead incident response activities, including...  ...alerts from various sources to detect and respond to potential security incidentsAnalyze security... 
    Cyber
    Full time
    Worldwide

    Elkay

    Milwaukee, WI
    2 days ago
  •  ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions, helping restore normal operations...  ...Use monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Madison, WI
    1 day ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates...  ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Madison, WI
    4 days ago
  • $55.7k - $82.1k

     ...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential...  ...escalates significant events to senior analysts or incident responders as appropriate. The analyst supports basic containment and response... 
    Contract work
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Madison, WI
    4 days ago
  •  ...Overview A Cyber Data Forensics Analyst specializes in investigating, analyzing, and interpreting data related to cyber incidents. This role bridges the gap between cybersecurity and data...  ...analyst ensures organizations can respond effectively to threats while maintaining... 
    Cyber

    Yugal Tech Academy

    Wausau, WI
    1 day ago
  •  ...roadmaps that prioritize the remediation of cyber threats, based on the likelihood of...  ...magnitude of cost/consequence of a security incident. This position will create mitigation...  ...of identifying, detecting, preventing, responding to and recovering from OT/ICS threats and... 
    Cyber
    Work at office
    Remote work

    Logical Systems Inc

    Milwaukee, WI
    3 days ago
  •  ...and management. Knowledge of ITIL processes and experience with incident tracking software. Proven problem coordination and root cause...  ...infrastructure or application domains, including Local MTF Networks, Cyber Security Tools, Network Circuits, VPNs, Active Directory, D2D... 
    Cyber
    Local area

    Peraton

    Wisconsin
    4 days ago
  • $127.2k - $246.9k

     ...closely with Threat Intelligence, SOC, and Incident Response teams to map detections and...  ...metrics, and tracesSupport and streamline Cyber Operations by actively automating repetitive...  ...functions to drive down Mean Time to Respond (MTTR)Act with integrity, professionalism... 
    Cyber
    H1b
    Local area

    KPMG

    Milwaukee, WI
    2 days ago
  •  ...cybersecurity operations, identifying vulnerabilities, responding to cybersecurity incidents, and implementing security best practices to safeguard business...  ..., and has a passion for staying ahead of evolving cyber threats.JOB EXPECTATIONSMonitoring and DetectionMonitor... 
    Cyber
    Full time
    Work experience placement
    Casual work
    Flexible hours

    Jockey International

    Kenosha, WI
    14 hours ago
  •  ...Collect, manage, and analyze security audit logs. * Monitor and respond to security incidents and vulnerabilities in cloud infrastructures. * Stay...  ...Qualifications * 5+ years of working experience in Cloud and Cyber Security * Strong understanding of cloud security... 
    Cyber
    Full time
    Work experience placement

    WEC Business Services LLC

    Milwaukee, WI
    10 days ago
  •  ...fastest growing areas of our business, and our global Cyber Investigation and Forensic Response (CIFR)...  ...at the heart of how we help clients prepare for, respond to, and recover from the most consequential cyber incidents. Within CIFR, our Cyber Recovery practice is focused... 
    Cyber
    Full time
    Live in
    Work at office
    Local area
    Shift work

    Accenture

    Milwaukee, WI
    4 days ago
  •  ...adjustments to maintain reliability and speed Physical & Cyber Security Manage and maintain security camera systems at company...  ...upkeep of servers, endpoints, etc. Serve as the first responder and incident commander for cybersecurity events Requirements: Job... 
    Cyber
    Local area
    Remote work

    Turnkey Corrections

    River Falls, WI
    5 days ago
  •  ...organizations prepare, protect, detect, respond to, and recover, at all points of the security...  ...blend risk strategy, digital identity, cyber defense, application security and managed...  ...of intrusions and potential incidents.Minimum 2 years of experience in deploying... 
    Cyber
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Milwaukee, WI
    2 days ago
  • $110k - $120k

     ...monitoring, detecting, investigating, and responding to cybersecurity threats across the...  ...(SOC) and focuses on threat detection, incident response, endpoint security, identity threats...  ...security visibility and minimizing cyber risk exposure. Key Responsibilities/Accountabilities... 
    Cyber
    Full time
    For contractors
    Local area
    Remote work

    Primoris

    Wausau, WI
    4 days ago
  • $78.7k

     ...mitigate potential data security threats, including third party cyber risk assessment Collaborate with cross-functional...  ...are accurately tracked and reported Monitor and respond to data security incidents, implementing corrective actions as needed Regularly review... 
    Cyber
    Temporary work
    Local area
    Shift work

    WEC Energy Group

    Milwaukee, WI
    1 day ago
  •  ...cybersecurity professional in Town of Texas, Wisconsin to monitor networks and respond to security threats. The ideal candidate will implement security controls, conduct assessments, and develop incident response plans. Responsibilities include analyzing security events,... 

    Devitechs

    Wisconsin
    5 days ago
  •  ...data through proactive threat monitoring, incident response, security engineering, risk...  ...effectively in challenging situations. Seek and respond constructively to feedback, even in the...  ...the backup and recovery plans geared for cyber security incidents as well as physical... 
    Cyber
    Work at office
    Flexible hours

    La Crosse County Library, Inc.

    La Crosse, WI
    5 days ago
  •  ...device Responsible for monitoring events and incidents that affect server and service health...  ...outage information including actions taken to respond to incidents and resolve the outage....  ...communication. Read and comprehend various cyber alerts. Excellent client relationship... 
    Cyber
    Work at office

    Dallas Fort Worth International Airport (DFW)

    Wisconsin
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Responder. Be the first to apply!