Remote job
Staff CSIRT Analyst
Job details
About this role
Role overview
This is a senior-level staff position on an internal Computer Security Incident Response Team, focused on safeguarding the organization itself with the same rigor applied to customer-facing environments. The role serves as the highest internal escalation point from the Security Operations Center, owning the full incident response lifecycle and partnering across engineering, product security, and detection functions. The work blends hands-on technical response with strategic program leadership, readiness exercises, and cross-functional coordination.
Responsibilities
- Lead identification, triage, and validation of security incidents across multiple telemetry sources, acting as the primary internal escalation for the SOC. - Design and run practical response exercises such as tabletop scenarios and purple-team engagements to keep first responders prepared at every level. - Collaborate with engineering, product security, and detection teams to tune telemetry sources for high true-positive rates and reduced noise. - Partner with offensive security counterparts to surface visibility gaps against modern threat actor tactics, techniques, and procedures, and drive remediation to close them. - Facilitate cross-functional Post-Incident Reviews, track resulting remediation work, and push tooling or process improvements that harden future response. - Maintain playbooks, system configurations, and incident response standards that keep the program scalable and supportable.
Requirements
- 8+ years of experience in incident response, SOC operations, or digital forensics. - Advanced working knowledge of EDR/MDR platforms, log aggregation tools such as SIEM or ELK, and cloud environments including AWS, Azure, or M365. - Demonstrated ability to articulate root causes of complex problems from first principles and translate them into technical solutions. - Experience leading small project teams and aligning technology stacks across functions. - Strong written and verbal communication skills for conveying technical incident detail to both engineers and executives. - Familiarity with automation or SOAR platforms, plus documentation and diagramming tools such as Confluence, Jira, and Lucidchart.
Benefits and work setup
- Fully remote work environment within the United States. - Generous paid time off covering vacation, sick time, and holidays, plus 12 weeks of paid parental leave. - Comprehensive medical, dental, and vision benefits, along with life and disability insurance. - 401(k) plan with a 5% employer contribution independent of employee deferrals, and stock options for full-time staff. - A one-time $500 reimbursement for home office setup, a $75 monthly digital reimbursement, and an annual allowance for education and professional development. - Access to a coaching and personal growth platform, with an organizational emphasis on inclusive culture.