Incident Responder
Lastpass
About the team:
Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.
If you are passionate about complex problem solving and motivated by scale, then this is the role for you!
Who will you work with?
You will partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel , and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations. You will also work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.
What are some of the exciting challenges you will be working on?
- Own security incidents end-to-end — receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
- Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
- Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team
- Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact
- Apply AI-assisted approaches to triage, investigation, detection authoring, and automation — helping the team adopt these capabilities responsibly and effectively
- Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity
- Document investigations thoroughly — capturing actions, evidence, timelines, and conclusions — to a standard that supports both technical follow-up and stakeholder communication
- Manage and strengthen the MSSP relationship by providing feedback on escalation quality, tuning alerting thresholds, and contributing to lessons-learned reviews
What does it take to work at LastPass?
- Proven experience in incident response and security operations in cloud-native environments , with hands-on depth in Azure and AWS
- Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
- Proven experience working with an MSSP — managing escalations, providing quality feedback, and closing gaps in coverage — whether as client or vendor
- Proven experience conducting threat hunts and building automation in support of security operations, including SOAR playbooks , scripting, and enrichment workflows
- Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK , with solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID
- Communicates clearly with both technical and non-technical stakeholders, exercises sound judgment under pressure, and operates effectively both independently and as part of a collaborative team
- Commitment to continuous improvement — proactively contributing to detections, runbooks, tooling, and operational processes that raise the bar for the team
It's great, but not required:
- Familiarity with the Intelligence-Driven Incident Response approach, integrating threat intelligence into the detection, analysis, and response lifecycle
- Experience interpreting network traffic and performing packet captures using tools such as tcpdump or Wireshark
- Background in relevant industry certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty
- ...front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding...Suggested
- ...Position Summary The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy...SuggestedFull timeWork at office
- ...Position Summary The Lead Incident Security Responder drives applied product security work across Black Duck’s portfolio, protecting our products and supporting the customer security inquiries that come into our Security Operations team. Operating with broad autonomy...SuggestedFull timeWork at office
- ...total, fully remote. Infinite Ranges is seeking an experienced Incident Response Manager to lead incident management efforts for a high... ...both technical and non-technical stakeholders to detect, respond, and recover from cyber incidents. What You Will Be Doing:...SuggestedContract workTemporary workRemote work
- ...disparate sources into threat detection pipelines. Streamline incident response tooling and processes. Partner with security... ...actionable insights for identifying, preventing, detecting, and responding to anomalous or malicious user and entity activity. Act as...SuggestedFull time
- ...application development, dedicated team building, software quality assessment, and all-things-digital solutions, is looking for an Incident Editorial Specialist to join our team. Join our night-shift editorial team and work on editing real-time road incident data for...Full timeRemote workShift workNight shift
- ...This position is needed to help own and strategically evolve Twilio's incident response function as one of the company's Incident Commanders. You will be capable of facilitating incidents across the full range of severities, including our highest-severity incidents. You...Full time
- ...Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We are looking for an Incident Commander to join our site reliability team, to work cross-functionally across engineering, and be the front line for incidents...Full time
- ...to detect a fire, confirm its location and size, and mobilize responders . Fire agencies need faster, more reliable ways to detect,... ...Role Pano AI seeks an Associate - Community Outreach and Incident Analysis to review and curate smoke incident alerts issued by...Full timeWork experience placementLocal areaRemote workWorldwideShift work
$141.52k - $176.9k
...Twilio Join the team as Twilio’s next Senior Security Engineer, Incident Response About the job The Security Incident Response... .... Draw the Owl : Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate...Full timeLocal areaRemote workWorldwide$80 - $120 per hour
...Incident management / reliability / SRE Evaluator is a remote engineering review track for evaluating production code, debugging traces, and developer-facing AI outputs against real-world correctness standards. Reviewers reproduce failures, write the unit test the model...Remote jobFor contractors10 hours per week- ...impact by providing services that help the government ensure the well being and support of U.S. citizens. Job Description Data Incident & Problem Management Analyst Seize your opportunity to make a personal impact supporting the Case Management Modernization (...Remote jobWork at office
- Requirements Вища освіта або навчання на останньому курсі за умови готовності працювати повний робочий день. Рівень англійської мови — Intermediate або вище. Знання додаткових іноземних мов буде перевагою. Логічне мислення та вміння швидко приймати практичні...Full time
- ...Robot Incident Replay Task Evaluator is a remote evaluation track for reviewing robot incident replay task evaluation prompts and responses against AuraOne's quality rubric. Reviewers compare paired outputs, label edge cases, and write the kind of structured feedback...Remote jobHourly payFor contractors10 hours per week
- ...Incident Response and Digital Forensics Expert is a remote review track for evaluating AI outputs across incident response and digital forensics specialist operations workflows. Reviewers grade workflow correctness, policy adherence, and stakeholder fit; flag operational...Remote jobHourly payFor contractorsWork experience placement10 hours per week
- ...Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer. We are looking for an Incident Commander to join our site reliability team, to work cross-functionally across engineering, and be the front line for incidents...Full time
$217k - $288k
...Opportunity This is a Senior or Staff level role owning detection and incident response at Grow. The core of the job is: catching threats... ..., and cloud, understanding unfamiliar systems well enough to respond with confidence Research the threats and attack methods most...Full timeImmediate startRemote work3 days per week- ...This position is needed to help own and strategically evolve Twilio's incident response function as one of the company's Incident Commanders. You will be capable of facilitating incidents across the full range of severities, including our highest-severity incidents. You...Full time
- ...Cloud Instructors for Cloud Incident Response Training (1099) Location: Kensington, MD Remote | 1099 Contract Position Duration: Project... ...Response (IR) courses designed for SOC analysts, incident responders, and security professionals transitioning to or specializing...Remote jobContract workLocal area
$27 - $28 per hour
...Job Title: Operational Business Analyst & Incident Manager Location Preference: 100% remote in LATAM working EST Time Zone Duration... ..., breaking paradigms and providing solutions that truly respond to each client’s needs. Our talent has led us to be one of the...Remote jobFull timeFor contractorsFreelanceWorldwide- ...high-growth, entrepreneurial environment, we'd love to have you on board! Position Overview As our IT/OT Security Engineer & Incident Response Lead, you'll be a hands-on security engineer who also leads incidents during business hours across our corporate, cloud,...Remote jobFull time
- ...About the Role CyEx is seeking a Cyber Incident/Data Breach Sales Leader to own end-to-end channel relationships across our incident response and class action services portfolio — reporting into senior sales leadership within a collaborative, fast-moving team built for...Full timeImmediate start
- ...Position: Senior Director, Digital Forensics & Incident Response Location: Remote, US Work Authorization: US Citizenship Required... ...cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency...Full timeWork at officeLocal areaRemote workWorldwide
- ...do not endorse products or services of GitLab. An overview of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security...Remote jobFull time
- ...and inspire to delight our business partners through our multiple banking delivery channels. Role Purpose: Sr Associate, Major Incident Manager for ETCC SRE Operations, is responsible for the end-to-end management of critical and major incidents impacting DBS's...Full timeWork at officeLocal area
$117k - $130k
...role brings focused ownership to a function currently shared across the IT team. In this role, you'll investigate and respond to security incidents, hunt for threats before they escalate, and tune detection tooling to reduce noise and close coverage gaps. Including...Full timeLocal areaFlexible hours$50k - $70k
...Employee Relations and Performance Support Employee support: Respond to routine employee questions and concerns promptly,... ...occupational health and safety initiatives, required training, incident documentation, and corrective-action tracking. Safety reviews...Full timeWork at officeLocal areaRemote workMonday to Friday- ...enforces protocols to maintain a safe environment for employees and customers. Oversees incident reporting and investigations, ensuring proper documentation and resolution. Responds to emergencies, providing direction to minimize disruption and ensure safety....Full timeWork at officeMonday to FridayWeekend workAfternoon shift
- ...promptly to protect the relationship Client Support – 30% Respond to client concerns by coordinating across internal departments... ..., proactive communication to key stakeholders throughout incident response and follow-up Address account-related questions with...Full timeContract workRemote workFlexible hours
- ...and facilitating contract preparation and execution. ~ Respond to seller and customer inquiries before, during, and after auction... ...auction and sales activities. ~ Promptly report safety incidents, near-misses, and workplace hazards to leadership....Full timeContract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Responder. Be the first to apply!










