Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Responder

Full-time

Lastpass

About the team:

Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.

If you are passionate about complex problem solving and motivated by scale, then this is the role for you!

Who will you work with?

You will partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel , and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations. You will also work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.

What are some of the exciting challenges you will be working on?

  • Own security incidents end-to-end — receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
  • Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
  • Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team
  • Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact
  • Apply AI-assisted approaches to triage, investigation, detection authoring, and automation — helping the team adopt these capabilities responsibly and effectively
  • Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity
  • Document investigations thoroughly — capturing actions, evidence, timelines, and conclusions — to a standard that supports both technical follow-up and stakeholder communication
  • Manage and strengthen the MSSP relationship by providing feedback on escalation quality, tuning alerting thresholds, and contributing to lessons-learned reviews

What does it take to work at LastPass?

  • Proven experience in incident response and security operations in cloud-native environments , with hands-on depth in Azure and AWS
  • Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
  • Proven experience working with an MSSP — managing escalations, providing quality feedback, and closing gaps in coverage — whether as client or vendor
  • Proven experience conducting threat hunts and building automation in support of security operations, including SOAR playbooks , scripting, and enrichment workflows
  • Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK , with solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID
  • Communicates clearly with both technical and non-technical stakeholders, exercises sound judgment under pressure, and operates effectively both independently and as part of a collaborative team
  • Commitment to continuous improvement — proactively contributing to detections, runbooks, tooling, and operational processes that raise the bar for the team

It's great, but not required:

  • Familiarity with the Intelligence-Driven Incident Response approach, integrating threat intelligence into the detection, analysis, and response lifecycle
  • Experience interpreting network traffic and performing packet captures using tools such as tcpdump or Wireshark
  • Background in relevant industry certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Incident Responder in Remote vacancy
  •  ...front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding... 
    Suggested

    Lastpass

    Remote
    29 days ago
  •  ...Position Summary The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy... 
    Suggested
    Full time
    Work at office

    Blackduck

    Remote
    29 days ago
  •  ...Position Summary The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy... 
    Suggested
    Full time
    Work at office

    Blackduck

    Remote
    a month ago
  •  ...total, fully remote. Infinite Ranges is seeking an experienced Incident Response Manager to lead incident management efforts for a high...  ...both technical and non-technical stakeholders to detect, respond, and recover from cyber incidents. What You Will Be Doing:... 
    Suggested
    Contract work
    Temporary work
    Remote work
    Remote
    7 days ago
  •  ...disparate sources into threat detection pipelines. Streamline incident response tooling and processes. Partner with security...  ...actionable insights for identifying, preventing, detecting, and responding to anomalous or malicious user and entity activity. Act as... 
    Suggested
    Full time

    Stripe

    Remote
    14 days ago
  •  ...application development, dedicated team building, software quality assessment, and all-things-digital solutions, is looking for an Incident Editorial Specialist to join our team. Join our night-shift editorial team and work on editing real-time road incident data for... 
    Full time
    Remote work
    Shift work
    Night shift

    intetics

    Remote
    15 days ago
  •  ...This position is needed to help own and strategically evolve Twilio's incident response function as one of the company's Incident Commanders. You will be capable of facilitating incidents across the full range of severities, including our highest-severity incidents. You... 
    Full time

    Twilio

    Remote
    29 days ago
  •  ...Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We are looking for an Incident Commander to join our site reliability team, to work cross-functionally across engineering, and be the front line for incidents... 
    Full time

    PENN Entertainment

    Remote
    29 days ago
  •  ...to detect a fire, confirm its location and size, and mobilize responders . Fire agencies need faster, more reliable ways to detect,...  ...Role Pano AI seeks an Associate - Community Outreach and Incident Analysis to review and curate smoke incident alerts issued by... 
    Full time
    Work experience placement
    Local area
    Remote work
    Worldwide
    Shift work

    Pano AI

    Remote
    9 days ago
  • $141.52k - $176.9k

     ...Twilio Join the team as Twilio’s next Senior Security Engineer, Incident Response About the job The Security Incident Response...  .... Draw the Owl : Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate... 
    Full time
    Local area
    Remote work
    Worldwide

    Twilio

    Remote
    14 days ago
  • $80 - $120 per hour

     ...Incident management / reliability / SRE Evaluator is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model... 
    Remote job
    For contractors
    10 hours per week

    AuraOne Human Data

    Remote
    20 hours ago
  •  ...impact by providing services that help the government ensure the well being and support of U.S. citizens. Job Description Data Incident & Problem Management Analyst Seize your opportunity to make a personal impact supporting the Case Management Modernization (... 
    Remote job
    Work at office

    General Dynamics Information Technology

    Remote
    2 days ago
  • Requirements Вища освіта або навчання на останньому курсі за умови готовності працювати повний робочий день. Рівень англійської мови — Intermediate або вище. Знання додаткових іноземних мов буде перевагою. Логічне мислення та вміння швидко приймати практичні...
    Full time

    intetics

    Remote
    29 days ago
  •  ...Robot Incident Replay Task Evaluator is a remote evaluation track for reviewing robot incident replay task evaluation prompts and responses against AuraOne's quality rubric. Reviewers compare paired outputs, label edge cases, and write the kind of structured feedback... 
    Remote job
    Hourly pay
    For contractors
    10 hours per week

    AuraOne Human Data

    Remote
    6 hours ago
  •  ...Incident Response and Digital Forensics Expert is a remote review track for evaluating AI outputs across incident response and digital forensics specialist operations workflows. Reviewers grade workflow correctness, policy adherence, and stakeholder fit; flag operational... 
    Remote job
    Hourly pay
    For contractors
    Work experience placement
    10 hours per week

    AuraOne Human Data

    Remote
    9 days ago
  •  ...Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We are looking for an Incident Commander to join our site reliability team, to work cross-functionally across engineering, and be the front line for incidents... 
    Full time

    PENN Entertainment

    Remote
    a month ago
  • $217k - $288k

     ...Opportunity This is a Senior or Staff level role owning detection and incident response at Grow. The core of the job is: catching threats...  ..., and cloud, understanding unfamiliar systems well enough to respond with confidence Research the threats and attack methods most... 
    Full time
    Immediate start
    Remote work
    3 days per week

    Grow Therapy

    Remote
    14 days ago
  •  ...This position is needed to help own and strategically evolve Twilio's incident response function as one of the company's Incident Commanders. You will be capable of facilitating incidents across the full range of severities, including our highest-severity incidents. You... 
    Full time

    Twilio

    Remote
    a month ago
  •  ...Cloud Instructors for Cloud Incident Response Training (1099) Location: Kensington, MD Remote | 1099 Contract Position Duration: Project...  ...Response (IR) courses designed for SOC analysts, incident responders, and security professionals transitioning to or specializing... 
    Remote job
    Contract work
    Local area

    Cybervance

    Remote
    2 days ago
  • $27 - $28 per hour

     ...Job Title: Operational Business Analyst & Incident Manager  Location Preference: 100% remote in LATAM working EST Time Zone  Duration...  ..., breaking paradigms and providing solutions that truly respond to each client’s needs. Our talent has led us to be one of the... 
    Remote job
    Full time
    For contractors
    Freelance
    Worldwide

    NTT DATA

    Remote
    5 days ago
  •  ...high-growth, entrepreneurial environment, we'd love to have you on board! Position Overview As our IT/OT Security Engineer & Incident Response Lead, you'll be a hands-on security engineer who also leads incidents during business hours across our corporate, cloud,... 
    Remote job
    Full time

    1440 Foods Manufacturing

    Remote
    2 days ago
  •  ...About the Role CyEx is seeking a Cyber Incident/Data Breach Sales Leader to own end-to-end channel relationships across our incident response and class action services portfolio — reporting into senior sales leadership within a collaborative, fast-moving team built for... 
    Full time
    Immediate start

    Point Wild

    Remote
    29 days ago
  •  ...Position: Senior Director, Digital Forensics & Incident Response Location: Remote, US Work Authorization: US Citizenship Required...  ...cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency... 
    Full time
    Work at office
    Local area
    Remote work
    Worldwide

    BlueVoyant

    Remote
    22 days ago
  •  ...do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security... 
    Remote job
    Full time

    GitLab

    Remote
    7 days ago
  •  ...and inspire to delight our business partners through our multiple banking delivery channels. Role Purpose: Sr Associate, Major Incident Manager for ETCC SRE Operations, is responsible for the end-to-end management of critical and major incidents impacting DBS's... 
    Full time
    Work at office
    Local area

    DBS Bank Ltd

    Remote
    13 days ago
  • $117k - $130k

     ...role brings focused ownership to a function currently shared across the IT team. In this role, you'll investigate and respond to security incidents, hunt for threats before they escalate, and tune detection tooling to reduce noise and close coverage gaps. Including... 
    Full time
    Local area
    Flexible hours

    Bumble Bee Foods

    Remote
    2 hours ago
  • $50k - $70k

     ...Employee Relations and Performance Support Employee support: Respond to routine employee questions and concerns promptly,...  ...occupational health and safety initiatives, required training, incident documentation, and corrective-action tracking. Safety reviews... 
    Full time
    Work at office
    Local area
    Remote work
    Monday to Friday

    Valley Medical

    Remote
    13 hours ago
  •  ...enforces protocols to maintain a safe environment for employees and customers.  Oversees incident reporting and investigations, ensuring proper documentation and resolution.  Responds to emergencies, providing direction to minimize disruption and ensure safety.... 
    Full time
    Work at office
    Monday to Friday
    Weekend work
    Afternoon shift

    Hall's Culligan Water

    Remote
    13 hours ago
  •  ...promptly to protect the relationship  Client Support – 30% Respond to client concerns by coordinating across internal departments...  ..., proactive communication to key stakeholders throughout incident response and follow-up  Address account-related questions with... 
    Full time
    Contract work
    Remote work
    Flexible hours

    Five Nines Technology Group

    Remote
    13 hours ago
  •  ...and  facilitating contract preparation and execution.   ~ Respond to seller and customer inquiries before, during, and after auction...  ...auction and sales activities.   ~ Promptly report safety incidents, near-misses, and workplace hazards to leadership.... 
    Full time
    Contract work
    Work at office

    Hansen Auction Group

    Remote
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Responder. Be the first to apply!