Remote job
Senior Tactical Response Analyst
Job details
About this role
Role overview The Tactical Response team owns the difficult, ambiguous part of serious security incidents: reconstructing what happened, how the attacker gained access, what remains at risk, and what partners should do next. This senior role leads deep investigations into active-adversary and high-friction intrusion cases, guiding partners through remediation and recovery while communicating clearly under pressure. It is a remote, customer-facing position that turns field findings into detection improvements, playbooks, and product feedback.
Responsibilities - Lead or support cases involving confirmed active adversaries, hands-on-keyboard activity, serious intrusions, or complex coordination requirements - Investigate across endpoint, identity, cloud, SIEM, VPN, firewall, Windows, Linux, and macOS telemetry to reconstruct attacker activity - Build evidence-based timelines and root-cause narratives, then deliver practical remediation, eviction, recovery, and recurrence-prevention guidance - Communicate complex findings clearly to technical teams, executives, and other stakeholders during high-stakes incidents - Translate investigation outcomes into technical notes, product and detection feedback, repeatable playbooks, and automation opportunities - Mentor responders, support cross-functional work with product, engineering, and account-facing teams, and contribute to enablement content such as blogs, webinars, and case studies
Requirements - Typically 3–5+ years of experience in SOC, MDR, threat hunting, digital forensics, or incident response - Demonstrated ability to lead or participate in external-customer incident response engagements and investigate complex, multi-host intrusions with limited oversight - Strong understanding of initial access, persistence, lateral movement, credential access, remote access, and ransomware tradecraft - Experience with Microsoft 365, Azure, identity, VPN, firewall, SIEM, or cloud telemetry, and forensic or EDR tools such as Velociraptor, osquery, Eric Zimmerman tools, RegRipper, Hayabusa, Chainsaw, or equivalents - Solid grasp of Windows internals plus working knowledge of Linux and macOS, common forensic artefacts (event logs, registry, prefetch, shellbags, scheduled tasks, browser data), and basic static and dynamic malware analysis - Working knowledge of a query language such as KQL, EQL, ES|QL, or Splunk SPL, plus strong written communication and composure during high-pressure partner engagements
Nice to have - Experience designing reusable investigation playbooks or methodology modules - Experience building production-quality automation or data-normalization workflows - Experience creating technical enablement, case studies, webinars, blogs, or similar content - Relevant certifications or equivalent practical experience in forensics, incident response, threat hunting, or offensive security
Benefits and work setup - 100% remote work environment - Generous paid time off including vacation, sick time, and paid holidays, plus 12 weeks of paid parental leave - Comprehensive medical, dental, and vision benefits, plus life and disability insurance - 401(k) with a 5% employer contribution regardless of employee contribution, and stock options for full-time employees - One-time $500 home office reimbursement, annual education and professional development allowance, and $75/month digital reimbursement - Access to a coaching platform for personal and professional growth