Incident Response Lead

🔥 12 hours ago

🇺🇸 United States – Remote

💵 $105k - $135k / year

⏰ Full Time

🟠 Senior

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Harbor IT

Harbor IT

201 - 500 employees

Founded 1995

💼 Consulting

🏥 Healthcare

📦 Logistics

💰 $37M Series C on 2005-04

Consulting • Healthcare • Logistics

Harbor IT is a cyber-first managed services provider that delivers integrated IT, cybersecurity, and cloud services to organizations operating in complex, mission-critical, and regulated environments. They provide managed cybersecurity (including MDR), security awareness training, cyber governance and risk due diligence, managed IT helpdesk, server and network management, and managed cloud and infrastructure services. Harbor IT focuses on clients such as private equity-backed companies, healthcare & life sciences, critical infrastructure, and regulated professional services, emphasizing security, uptime, and enterprise value.

📋 Description

• Serve as incident commander for client security incidents • Establish scope, set response priorities, assign actions to named owners, track decisions, and keep incidents moving • Run triage and initial investigation across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline • Delegate information gathering while focusing on incident-command decisions • Own containment decisions involving isolation, credential resets, evidence preservation, and client approval authority • Decide whether incidents remain within Harbor’s scope or require escalation to outside DFIR firms, breach counsel, or insurance panels • Own in-scope incidents from detection through post-incident reporting • Brief receiving DFIR firms and hand off with a written timeline and evidence inventory • Carry on-call responsibility and remain available outside business hours for incident escalation • Translate technical findings into actionable decisions for owners, executives, and general counsel • Coordinate with breach counsel, cyber insurance carriers and panel firms, third-party DFIR teams, client IT, and law enforcement where applicable • Keep Client Success and leadership current on active incidents • Produce post-incident reports covering confirmed and assumed facts, containment, open items, and recommended client changes • Write and maintain incident response playbooks, severity model, and escalation matrix • Define Harbor’s incident-response responsibility boundaries in writing • Build working relationships with outside DFIR firms and breach counsel practices • Maintain escalation-readiness records for every managed client • Run tabletop exercises with Harbor teams and clients when applicable and feasible • Mentor SOC analysts and security engineers on investigative method and incident discipline • Feed incident lessons back to detection engineering to improve future detection

🎯 Requirements

• 6+ years in cybersecurity, with substantial time spent responding to real intrusions rather than monitoring for them • Direct experience acting as the lead on security incidents, setting direction while others execute • Experience responding across multiple distinct organizations, whether from a consulting, MSSP, MDR, or panel DFIR background • Hands-on investigative depth in Microsoft 365, Google Workspace, and Entra ID compromise • Experience with unified audit log analysis, message trace, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access gaps • Working command of endpoint detection and response tooling for investigation and containment • Host and Windows internals knowledge sufficient to interpret process lineage, persistence mechanisms, and lateral movement evidence • Ability to build defensible incident timelines from SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets • Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft • Experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including investigation handoff • Ability to brief non-technical executives under pressure and write clear, actionable client documentation • Willingness and ability to be reachable outside business hours for incident escalation • Preferred: GCIH, GCFA, GCIA, or comparable GIAC certification; CISSP or CISM • Preferred: prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team • Preferred: host and memory forensics, malware triage, or reverse engineering • Preferred: Linux investigation experience and cloud incident response beyond Microsoft, such as AWS • Preferred: familiarity with HIPAA, PCI DSS, GLBA, state breach notification statutes, or SEC disclosure rules • Preferred: background in managed services or another multi-tenant environment where the candidate owned both the relationship and investigation

🏖️ Benefits

• Employer-paid medical, dental, and vision coverage for the employee, with additional premium plan options available • 401(k) with company match • Paid time off • Reimbursement for approved tuition, certifications, and conference attendance

Apply Now

Similar Jobs

🔥 14 hours ago

Pinnacle Treatment Centers, Inc.

1001 - 5000

🏥 Healthcare

🧘 Wellness

🌍 Social Impact

Community relations representative growing Pinnacle Treatment Centers’ North Carolina OTP/MAT referral network. Managing territory accounts, admissions growth, outreach, and compliance through field-based partnerships.

🔥 15 hours ago

National Guardian Life Insurance Company

201 - 500

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Remote Wisconsin New Business Specialist processing life insurance and annuity applications for NGL, an independent life insurance company. Auditing policies, resolving pending cases, and meeting application turnaround standards.

🔥 15 hours ago

Mosa. Tiles.

501 - 1000

🏭 Manufacturing

🏗️ Construction

Certification Specialist reviewing client files and materials for National Organic Standards compliance. Supporting MOSA's organic certification program through documentation, inspections, and industry engagement.

🇺🇸 United States – Remote

💵 $59.8k - $66.4k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔥 15 hours ago

Calbright College

11 - 50

💼 Consulting

🏥 Healthcare

📦 Logistics

Dean leading academic quality, accreditation, and institutional effectiveness at Calbright College, California's statewide online campus. Driving evidence-based improvement, strategic initiatives, and accreditation compliance.

🇺🇸 United States – Remote

💵 $159.3k - $175.7k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔥 16 hours ago

First American

10,000+ employees

🏠 Real Estate

💸 Finance

🏢 Enterprise

Senior Reverse Exchange Officer managing reverse 1031 real estate exchanges for First American’s commercial real estate clients. Handling documentation, funds, accounting, closings, and client relationships.