Remote job
Incident Response Lead
Job details
About this role
Role overview This senior, hands-on Incident Response Lead role is embedded with a large US consumer lender, leading major-incident response and the digital forensics capability for a 24/7 nearshore security operations service. When the client declares a major incident, you are the technical lead on the bridge, telling the client what happened, how far it spread, and what to contain, backed by evidence. You will provide direction to Tier 3 analysts based in Latin America and operate as one of two US-based senior leads highly visible to client security leadership.
Responsibilities - Serve as incident lead on the client's major-incident bridge, keeping responders, leadership, and analysts aligned on a single version of events - Scope incidents and deliver evidence-backed containment guidance for infrastructure, identity, endpoint, and application teams - Author operational updates for responders and executive summaries for client leadership, and lead post-incident reviews - Own digital forensics and investigation work, including host and memory triage across endpoint telemetry sources - Investigate identity provider sessions and tokens, and reconstruct cloud activity from audit and flow logs - Build investigation records and timelines that support client regulatory notification decisions - Develop and refine incident response playbooks and runbooks - Run tabletop exercises with the client's security, legal, and risk teams - Guide Tier 3 analysts in Latin America who serve as the first line on overnight investigations
Requirements - Senior-level experience leading the technical response to major incidents end to end, with hands-on forensics on Windows and Linux hosts and investigations in at least one major cloud - Ability to query SIEM, EDR, and identity logs directly without waiting on analysts - Sound judgment in recommending containment that stops attackers without disrupting a lending platform at month end - Communication skills that produce incident reports readable by a CISO, a lawyer, and an examiner alike - Demonstrated ability to lead people you do not directly line-manage, including analysts in other countries - Remote work from the United States on US Eastern business hours, with 24/7 on-call rotation and periodic travel to the client and to Bogotá and Buenos Aires - US work authorization is required, with periodic identity, criminal, employment, and education checks
Nice to have - Incident response experience inside a bank, lender, card issuer, or insurer - Working knowledge of NYDFS Part 500, GLBA, FFIEC, SOX, and PCI DSS incident obligations - Experience with ransomware, business email compromise, or fraud-driven intrusions in consumer finance - Consultancy or MSSP background - GCIH, GCFA, GCFE, GREM, or CISSP - Spanish language skills to support the nearshore team
Benefits and work setup - Remote work within the United States on Eastern business hours - Flexible work model: hybrid, remote, or in-office options - Competitive base compensation with real growth opportunities and leadership visibility - Inclusive, people-first culture