Job Description
We are seeking a Senior Security Incident Responder who will be responsible for leading the investigation, containment, eradication, and recovery of cybersecurity incidents across the enterprise. This role serves as a technical leader during major security incidents, leveraging security monitoring tools, threat intelligence, forensic techniques, and advanced analytics to determine attack scope, impact, root cause, and remediation actions.
The role requires strong expertise in security operations, incident response, threat detection, log analysis, and security tooling, as well as the ability to coordinate response activities across technical teams, business stakeholders, legal, privacy, compliance, and third-party vendors. The individual will also drive continuous improvement of SOC capabilities through playbook development, automation, detection tuning, and response orchestration.
Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
Provide clear incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
Create and improve detection rules, use cases, and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
Proven experience leading investigations of major cybersecurity incidents and security breaches.
Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
Experience working in enterprise or global environments with complex security infrastructures.
Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
Experience with API integrations and workflow automations - Preferred Certifications:
o GIAC Certified Incident Handler (GCIH)
o GIAC Certified Forensic Analyst (GCFA)
o GIAC Certified Enterprise Defender (GCED)
o CISSP
o Certified SOC Analyst (CSA)
o Microsoft Security Operations Analyst Associate
o SANS Incident Response training or equivalent