Search Remote Jobs

Principal Incident Response Analyst

Job not on LinkedIn

🔥 4 minutes ago

🇺🇸 United States – Remote

💵 $150k - $180k / year

⏰ Full Time

🔴 Lead

🚨 Incident Response Analyst

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of North

North

1001 - 5000 employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

North is a comprehensive payment solutions provider. Specializing in point of sale systems, payment processing, and merchant services, North offers a wide array of products to streamline business operations both online and offline. Their services include secure mobile payments, ecommerce gateways, POS solutions, and back-office tools such as invoicing, reporting, inventory management, and customer loyalty programs. North supports diverse industries, including retail, restaurants, healthcare, gaming, and more, with robust solutions tailored to specific business needs. They offer scalable options for enterprises and franchises and provide APIs for developers to create integrated payment solutions. Committed to security, North ensures all transactions are PCI DSS-validated with advanced encryption and tokenization.

📋 Description

• Serve as principal escalation point and lead investigator for complex, high-severity, and novel security incidents • Triage, investigate, contain, eradicate, and recover from incidents across endpoint, network, cloud, identity, and application layers • Lead forensic investigations and reconstruct attack timelines • Translate investigation findings into technical and executive-level narratives • Own and evolve incident response processes, documentation, and playbooks • Lead root cause analyses and post-incident reviews • Coordinate major incidents across IT, legal, compliance, and executive leadership • Mentor incident responders and SOC analysts during live incidents • Participate in or lead on-call rotation for critical incident response • Write, tune, and validate SIEM/NG-SIEM detection content • Maintain MITRE ATT&CK coverage and gap analysis • Conduct proactive, hypothesis-driven threat hunts • Use hunt outcomes to identify compromises and strengthen detection coverage • Partner with threat intelligence sources and feeds • Represent incident response in planning, tabletop exercises, and architecture reviews • Lead complex incident-related investigations and initiatives • Partner with cloud, network, and identity teams to close visibility and telemetry gaps • Communicate findings and recommendations to technical and non-technical stakeholders • Develop and maintain incident response procedure and policy documentation

🎯 Requirements

• Bachelor's degree in a technical field, or equivalent professional experience • 7+ years of hands-on information security experience • Deep subject-matter expertise in incident response, with strong working proficiency in detection engineering and threat hunting • Demonstrated ability to independently lead complex, high-severity security incidents from detection through recovery • Experience mentoring or providing technical leadership to security engineers and analysts • Excellent written and verbal communication skills • Deep hands-on expertise in end-to-end incident response, including triage, containment, eradication, recovery, and root cause analysis • Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics • Advanced experience with EDR/XDR platforms and log analysis • Strong working knowledge of detection engineering and SIEM/NG-SIEM platforms such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel • Working proficiency in hypothesis-driven threat hunting • Deep working knowledge of the MITRE ATT&CK framework • Strong scripting or automation experience with Python, PowerShell, or similar, and/or experience using LLM coding tools • Solid understanding of networking, AWS, Azure, GCP, Windows/Linux systems, and identity platforms • Working knowledge of PCI-DSS or a comparable compliance framework • Ability to lead high-pressure, ambiguous, cross-functional investigations with minimal oversight • Relevant hands-on experience and subject-matter expertise weighted more heavily than certifications • North is a US-based company; no sponsorship is available

🏖️ Benefits

• Total rewards offerings • Benefits supporting overall well-being • Unique personally and professionally fulfilling initiatives • Inclusive work environment • Equal opportunity employment

Apply Now

Similar Jobs

🕒 August 21

Blackbaud

1001 - 5000

☁️ SaaS

🤝 Non-profit

🤝 B2B

Principal Incident Response Analyst protecting Blackbaud’s social-impact technology through digital forensics and threat hunting. Leading incident investigations, response, remediation, and detection improvement.

🇺🇸 United States – Remote

💵 $101.9k - $132.8k / year

💰 $6.5M Series A on 2000-02

⏰ Full Time

🔴 Lead

🚨 Incident Response Analyst

🕒 July 14

Centene Corporation

10,000+ employees

🛡️ Insurance

💼 Consulting

🏥 Healthcare

Principal Incident Response Analyst executing security plans and improving security for Centene's 28 million members through technology and collaboration.

🇺🇸 United States – Remote

💵 $121.5k - $224.9k / year

⏰ Full Time

🔴 Lead

🚨 Incident Response Analyst