Incident Response Specialist Job at CyberOne, United States

  • CyberOne
  • United States

Job Description

Incident Response Specialist

PH - Fully Remote

The Incident Response Specialist will play a key role in supporting customers through all stages of a cyber incident, from initial investigation through to containment, eradication, recovery and post-incident reporting.

Working alongside senior Incident Responders and Incident Managers, you will conduct technical investigations, analyse evidence, identify attacker activity and support customers during some of their most critical cyber security events.

The role also supports proactive security services including Incident Response Readiness Assessments, Tabletop Exercises, Threat Hunting and Threat Intelligence activities.

This is an excellent opportunity for an experienced SOC Analyst or early-career Incident Responder looking to develop into a senior DFIR consultant.

What You'll Do

Incident Response

  • Investigate cyber security incidents affecting customer environments.
  • Analyse endpoint, network, cloud and identity-based evidence.
  • Perform host-based investigations across Windows and Microsoft 365 environments.
  • Support containment, eradication and recovery activities.
  • Identify attacker tactics, techniques and procedures (TTPs) using the MITRE ATT&CK framework.
  • Collect, preserve and analyse forensic artefacts where appropriate.
  • Produce Indicators of Compromise (IOCs) and detection recommendations.
  • Support evidence collection for regulatory or legal requirements.

Technical Investigation

  • Analyse Microsoft Defender XDR telemetry.
  • Investigate Microsoft Sentinel incidents.
  • Review Windows Event Logs and Sysmon data.
  • Analyse Entra ID sign-in and audit logs.
  • Investigate Exchange Online activity.
  • Perform malware triage and basic static analysis.
  • Review firewall, proxy, VPN and authentication logs.
  • Conduct threat hunting activities across customer environments.

Customer Engagement

  • Participate in customer investigation calls.
  • Explain technical findings to both technical and non-technical audiences.
  • Produce high-quality investigation reports.
  • Provide remediation recommendations.
  • Support post-incident lessons learned workshops.

Proactive Services

  • Incident Response Readiness Assessments
  • Tabletop Exercises
  • Threat Hunting engagements
  • Threat Intelligence services
  • Security posture reviews
  • AI security investigations where required

Continuous Improvement

  • Develop new investigation playbooks.
  • Improve Incident Response procedures.
  • Contribute to internal knowledge sharing.
  • Support development of detection content.
  • Assist with automation opportunities using Microsoft and AI technologies.

Employees are expected to demonstrate a security-first mindset and ensure that information security considerations are incorporated into their day-to-day activities, decision-making, and interactions with customers, suppliers, and colleagues.

What We're Looking For

Essential

  • Relevant experience in Cyber Security or Incident Response.
  • Strong English communication skills.

Advantageous

  • SC-200 Microsoft Security Operations Analyst
  • SC-100 Cybersecurity Architect
  • AZ-500 Microsoft Azure Security Technologies
  • GCIH
  • GCFA
  • GNFA
  • CompTIA Security+
  • CREST Practitioner or equivalent

Job Tags

Remote work

Similar Jobs

HealthCare Connections, Inc.

Travel Medical Technologist - $2,140 per week in Newport, ME Job at HealthCare Connections, Inc.

 ...Medical Technologist Location: Newport, ME Agency: HealthCare Connections, Inc. Pay: $2,140 per week Shift Information: Nights - 3 days x 12 hours Contract Duration: 13 Weeks Start Date: ASAP About the Position We are looking for an... 

Department of the Air Force

BOILER PLANT OPERATOR Job at Department of the Air Force

 ...Job TitleJob DescriptionStarts, operates, adjusts, and stops single or multiple fuel power boilers fueled by coal, oil, refuse-derived...  ...other equipment in a steam or high temperature hot water boiler plant.Operates and controls auxiliary pollution control equipment requiring... 

LifeBridge Health

Office Front Desk Asst - LBHMG Job at LifeBridge Health

 ...toward advanced degrees and specialty certifications Generous paid time off, fitness discounts, and free on-site parking About Hospital About LifeBridge Health LifeBridge Health is a dynamic, purpose-driven health system redefining care delivery across the... 

You.com

Front-End Web Developer Job at You.com

 ...people search and work, wed love to have you join us! About the Role We are seeking a talented and motivated Front-End Web Developer with a strong background in both design and development. As part of the Marketing team, you will play a key role in creating... 

Hasana, Inc.

Web Developer/Programmer Internship Job at Hasana, Inc.

 ...this is an unpaidinternship. Job Description As a Web Developer/Programmer Intern for Hasana, Inc. you will have a variety of...  ...closely with Project Managers and other members of the Development Team to both develop detailed specification documents with...