Overview
Staff Incident Response Analyst who serves as the technical escalation point for L2 SOC analysts and a 24/7 MDR partner, owning advanced incidents and deep-dive forensics across endpoint, host, and cloud environments.
What you'll do
- Receive and own L2 escalations across severity levels and lead technical response on Sev2+ scope incidents.
- Determine blast radius, affected assets, and attacker objectives from telemetry and make documented containment decisions.
- Reconstruct and maintain a forensically sound incident timeline with evidence ordering and chain-of-custody.
- Perform endpoint triage via EDR including process tree analysis, remote artifact collection, and behavioral review.
- Conduct AWS/GCP incident response using cloud audit logs, IAM chain reconstruction, and cloud-side timeline correlation.
- Run identity and SaaS forensics across IdP, cloud IAM, and application layers, including OAuth and token abuse cases.
- Lead structured threat hunts in the SIEM and translate findings into detection recommendations or rule drafts.
What you'll need
- 6+ years of hands-on incident response experience.
- At least 3 years performing technical IR at a senior or staff level.
- Expert-level EDR proficiency including remote triage, process tree analysis, and custom detection rule authorship.
- Deep AWS IR capability, including CloudTrail forensics, IAM chain analysis, EC2/Lambda investigation, and IMDS/assumed-role abuse patterns.
- Strong Windows forensics skills using Prefetch, MFT, Shimcache, event logs, and registry artifacts.
- Solid Linux forensics skills including persistence mechanisms, cron, SUID analysis, and log artifact interpretation.
- Hands-on SIEM investigation and detection experience writing detection logic and multi-event correlation.
Read the full description and apply on the company’s own careers page.