← Back to jobs

Remote job

Senior Incident Response Analyst

Other Full-time Permanent United States

Job details

Not specified Salary
United States Eligibility
Senior Experience
Full-time Employment

About this role

Role overview A hands-on senior responder position on a dedicated digital forensics and incident response (DFIR) function within a healthcare-focused security operations team. The role owns the full incident lifecycle for tier-1 and tier-2 cases, protects clinical systems and sensitive patient data, and drives continual improvement of forensic capability. It is an individual contributor seat with shared on-call duty and named containment authority inside defined thresholds.

Responsibilities - Own incidents end to end, covering detection validation, triage, scoping, containment, eradication, recovery, and post-incident review. - Run independent forensic investigations across host/disk, memory, network, cloud, and identity surfaces, with evidence handling that withstands legal, regulatory, and client scrutiny. - Investigate from endpoint detection and SIEM telemetry, writing and refining queries, building correlation logic, and reconstructing incident timelines from log data. - Participate in a shared IR on-call rotation and exercise containment authority (such as host isolation and session revocation) within an established escalation threshold. - Author and revise IR playbooks grounded in incidents you personally work, and run post-incident reviews with findings tracked to closure. - Use scripting or AI-assisted tooling to automate repetitive triage and evidence-collection steps. - Produce both a defensible technical timeline and an executive summary for each major incident.

Requirements - 6–8 years of hands-on security experience, with the majority spent in incident response and/or digital forensics. - Demonstrated ownership of the full incident lifecycle on real cases, from detection validation through post-incident review. - Broad digital forensics experience across host/disk, memory, network, cloud, and identity, drawn from operational casework rather than coursework. - Working depth with EDR/EPP platforms and SIEM tools, including query authoring, correlation logic, and timeline reconstruction. - Fluency with a forensic toolchain such as Velociraptor, KAPE, Volatility, Autopsy/EnCase/FTK/X-Ways, plaso, Zeek, or Wireshark. - Evidence handling discipline, including chain of custody, sound acquisition, and documentation that survives legal, regulatory, and client review. - Applied MITRE ATT&CK fluency, scripting for investigation and automation, and clear dual-audience incident writing.

Nice to have - Hands-on experience with CrowdStrike Falcon EDR, Next-Gen SIEM, and Falcon Shield. - Cloud incident response in AWS (CloudTrail, GuardDuty, IAM abuse patterns) and identity-centric investigation in platforms such as Okta. - Healthcare, fintech, or other regulated-industry background involving sensitive data, plus familiarity with HIPAA, HITRUST, or SOC 2 from the operator side, including breach determination workflow. - Industry certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, or GREM, and malware triage or reverse engineering fundamentals. - SOAR or AI-assisted IR workflows built on LLM APIs, multi-entity or M&A environment exposure, threat intelligence consumption applied to active investigations, and community engagement such as open-source contributions, CTF history, or conference talks.

Benefits and work setup - Salaried position with medical, dental, and vision plans, flexible spending or health savings accounts, and flexible PTO. - 401(k) with company match, plus life insurance, pet insurance, and additional coverage options. - Shared IR on-call rotation with peers, operating within a relatively flat organizational structure that encourages autonomy and direct contribution to program direction.

Skills detected in the listing

PythonGoAWSLLM
Detected Sep 8, 2026
Last verified Sep 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight