Remote job
Senior Incident Response Analyst
Job details
About this role
Role overview A hands-on senior responder position on a dedicated digital forensics and incident response (DFIR) function within a healthcare-focused security operations team. The role owns the full incident lifecycle for tier-1 and tier-2 cases, protects clinical systems and sensitive patient data, and drives continual improvement of forensic capability. It is an individual contributor seat with shared on-call duty and named containment authority inside defined thresholds.
Responsibilities - Own incidents end to end, covering detection validation, triage, scoping, containment, eradication, recovery, and post-incident review. - Run independent forensic investigations across host/disk, memory, network, cloud, and identity surfaces, with evidence handling that withstands legal, regulatory, and client scrutiny. - Investigate from endpoint detection and SIEM telemetry, writing and refining queries, building correlation logic, and reconstructing incident timelines from log data. - Participate in a shared IR on-call rotation and exercise containment authority (such as host isolation and session revocation) within an established escalation threshold. - Author and revise IR playbooks grounded in incidents you personally work, and run post-incident reviews with findings tracked to closure. - Use scripting or AI-assisted tooling to automate repetitive triage and evidence-collection steps. - Produce both a defensible technical timeline and an executive summary for each major incident.
Requirements - 6–8 years of hands-on security experience, with the majority spent in incident response and/or digital forensics. - Demonstrated ownership of the full incident lifecycle on real cases, from detection validation through post-incident review. - Broad digital forensics experience across host/disk, memory, network, cloud, and identity, drawn from operational casework rather than coursework. - Working depth with EDR/EPP platforms and SIEM tools, including query authoring, correlation logic, and timeline reconstruction. - Fluency with a forensic toolchain such as Velociraptor, KAPE, Volatility, Autopsy/EnCase/FTK/X-Ways, plaso, Zeek, or Wireshark. - Evidence handling discipline, including chain of custody, sound acquisition, and documentation that survives legal, regulatory, and client review. - Applied MITRE ATT&CK fluency, scripting for investigation and automation, and clear dual-audience incident writing.
Nice to have - Hands-on experience with CrowdStrike Falcon EDR, Next-Gen SIEM, and Falcon Shield. - Cloud incident response in AWS (CloudTrail, GuardDuty, IAM abuse patterns) and identity-centric investigation in platforms such as Okta. - Healthcare, fintech, or other regulated-industry background involving sensitive data, plus familiarity with HIPAA, HITRUST, or SOC 2 from the operator side, including breach determination workflow. - Industry certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, or GREM, and malware triage or reverse engineering fundamentals. - SOAR or AI-assisted IR workflows built on LLM APIs, multi-entity or M&A environment exposure, threat intelligence consumption applied to active investigations, and community engagement such as open-source contributions, CTF history, or conference talks.
Benefits and work setup - Salaried position with medical, dental, and vision plans, flexible spending or health savings accounts, and flexible PTO. - 401(k) with company match, plus life insurance, pet insurance, and additional coverage options. - Shared IR on-call rotation with peers, operating within a relatively flat organizational structure that encourages autonomy and direct contribution to program direction.