Remote job
Incident Response & DFIR Lead
Job details
About this role
Role overview Lead the incident response and digital forensics function for a fintech organization, owning the full lifecycle from detection through recovery. This full-time position combines hands-on forensic investigation with team leadership, acting as Incident Commander for major security events and driving continuous improvement in detection and response capabilities.
Responsibilities - Serve as Incident Commander during major security incidents, assigning roles, owning timelines, and coordinating across IAM, platform, IT, security engineering, and product teams - Direct evidence collection and forensic analysis to reconstruct attack paths across endpoints, servers, identities, cloud, SaaS, and network telemetry - Design and validate containment actions such as endpoint isolation, credential rotation, session revocation, and service isolation - Coordinate eradication and recovery efforts, ensuring systems return to a trusted state and evidence is preserved for legal, HR, regulatory, and disciplinary needs - Lead post-incident reviews and root-cause analyses, tracking remediation actions with accountable owners and due dates - Mentor DFIR specialists, maintain playbooks and forensic checklists, and run incident readiness exercises - Translate investigation findings into actionable recommendations for detection engineering, IAM, and product security teams
Requirements - Strong hands-on command of the incident response lifecycle including investigation, containment, eradication, recovery, and lessons learned - Demonstrated experience leading complex incidents and coordinating multiple technical teams under pressure - Practical experience investigating endpoint, identity, server, cloud, or network compromise using EDR/XDR, SIEM, and audit logs - Ability to reconstruct attacker activity from initial access through credential abuse, persistence, privilege escalation, lateral movement, and exfiltration - Working knowledge of digital forensics, evidence preservation, forensic timelines, and chain-of-custody principles - Experience with Microsoft Entra ID or Active Directory incident investigation and understanding of Windows, Linux, and enterprise networking from an investigative perspective
Nice to have - Hands-on experience with Cortex XDR, Elastic Security, Velociraptor, KAPE, Volatility, Autopsy, Magnet, EnCase, or FTK - Cloud forensics experience in AWS or similar environments - Background investigating ransomware, BEC, insider threat, or cloud account compromise cases - Scripting ability in Python or PowerShell to support investigation and evidence processing - Certifications such as GCIH, GCFA, GCFE, GNFA, OSCP, or CISSP
Benefits and work setup - 20 paid vacation days and 10 paid sick leave days annually, plus public holidays - Medical, professional education, language learning, and wellness budgets - Fully remote work opportunity