Job Closed
This listing is no longer active.
Real people detecting real threats in real time.
Cybersecurity Incident Response Analyst
Location
United States
Posted
90 days ago
Salary
0
No structured requirement data.
Job Description
Cybersecurity Incident Response Analyst
Binary Defense
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role focuses on hands-on investigation of cybersecurity incidents, threat hunting, and forensic analysis across endpoint, network, and cloud environments. - Serve as an Incident Response (IR) Analyst supporting the Analysis on Demand (AoD) team. - Drive client meetings to discuss incident scope, investigative findings, and response updates while producing clear and detailed technical reports. - Conduct incident triage and verification, determine scope of compromise, perform threat hunting, and provide containment and remediation recommendations to customers. - Serve as a primary responder and point of contact during incident response engagements, supporting forensic investigation, analysis, and resolution of security incidents. - Work directly with clients to perform investigations, forensically analyze systems, and identify attacker activity across enterprise environments. - Analyze compromised systems to determine attack vectors, persistence mechanisms, lateral movement, and attacker techniques. - Identify attacker tools, tactics, and procedures (TTPs) and understand evolving threat actor behaviors. - Follow industry incident response best practices for containment, eradication, and recovery. - This position focuses on hands-on investigation and incident response, not alert monitoring or tier-1 SOC duties. - Must be familiar with incident response best practices and procedures. - Must have Windows-based incident response and computer forensics experience. - Must be familiar with network analysis, memory analysis, and digital forensics investigations. - Must possess excellent verbal and written communication skills, including the ability to present findings and recommendations to technical teams and leadership. Qualifications - Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field, or equivalent practical experience. - Certification in one or more of the following preferred: GCIH, GCFE, GCFA, GREM, GNFA. - Experience working within a Security Operations Center (SOC) or Incident Response team. - 3–5+ years of hands-on cybersecurity investigation experience, including host forensics, network forensics, threat hunting, or incident response. - Experience supporting incident response investigations including analysis, containment, and remediation actions. - Demonstrated experience investigating active security incidents or confirmed compromises, including determining attack scope and identifying persistence mechanisms. - Experience performing host-based investigations using endpoint artifacts, logs, and forensic evidence to determine attacker activity and timeline of compromise. - Experience analyzing systems across Windows, macOS, or Linux environments. - Experience working with enterprise security technologies including EDR, SIEM, firewalls, IDS/IPS, vulnerability scanning, and network security tools. - Experience using digital forensics tools such as Volatility, Rekall, KAPE, Autopsy, or similar frameworks. - Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, Devo, or Sumo Logic. - Experience working with EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, FortiXDR, or similar solutions. - Strong experience using SIFT Workstation or similar digital forensics platforms. - Demonstrated knowledge of the MITRE ATT&CK Framework. - Ability to communicate investigative findings and strategies to technical teams, executive leadership, internal teams, and clients. - Strong analytical and problem-solving skills. - Comfortable working multiple concurrent investigations and adapting investigative approaches as new evidence is discovered. - Strong time management skills to balance multiple investigations and priorities. - Ability to lead clients in strategic conversations with strong executive presence. - Must be a U.S. Citizen residing in the continental United States. Requirements - Master’s degree in Cybersecurity, Computer Science, Information Systems, or related field. - Experience with Python, PowerShell, Bash, or other scripting languages. - Build scripts, tools, or methodologies to enhance incident investigation processes. - Experience conducting cloud incident response investigations (AWS, Azure, or GCP). - Experience with macOS and Linux forensic investigations. - Experience working with SOAR platforms such as D3 Security, Cortex XSOAR, Cortex XSIAM, or similar security automation platforms. - Experience using Velociraptor for endpoint artifact collection, threat hunting, and forensic investigations. - Experience using IRIS for incident tracking, case management, and investigation coordination. Benefits - Competitive medical, dental and vision coverage for employees and dependents. - 401k match which vests every payroll. - Flexible and remote friendly work environment. - Training opportunities to expand your skill set.
Job Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field, or equivalent practical experience.
- Certification in one or more of the following preferred: GCIH, GCFE, GCFA, GREM, GNFA.
- Experience working within a Security Operations Center (SOC) or Incident Response team.
- 3–5+ years of hands-on cybersecurity investigation experience, including host forensics, network forensics, threat hunting, or incident response.
- Experience supporting incident response investigations including analysis, containment, and remediation actions.
- Demonstrated experience investigating active security incidents or confirmed compromises, including determining attack scope and identifying persistence mechanisms.
- Experience performing host-based investigations using endpoint artifacts, logs, and forensic evidence to determine attacker activity and timeline of compromise.
- Experience analyzing systems across Windows, macOS, or Linux environments.
- Experience working with enterprise security technologies including EDR, SIEM, firewalls, IDS/IPS, vulnerability scanning, and network security tools.
- Experience using digital forensics tools such as Volatility, Rekall, KAPE, Autopsy, or similar frameworks.
- Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, Devo, or Sumo Logic.
- Experience working with EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, FortiXDR, or similar solutions.
- Strong experience using SIFT Workstation or similar digital forensics platforms.
- Demonstrated knowledge of the MITRE ATT&CK Framework.
- Ability to communicate investigative findings and strategies to technical teams, executive leadership, internal teams, and clients.
- Strong analytical and problem-solving skills.
- Comfortable working multiple concurrent investigations and adapting investigative approaches as new evidence is discovered.
- Strong time management skills to balance multiple investigations and priorities.
- Ability to lead clients in strategic conversations with strong executive presence.
- Must be a U.S. Citizen residing in the continental United States.
- Master’s degree in Cybersecurity, Computer Science, Information Systems, or related field.
- Experience with Python, PowerShell, Bash, or other scripting languages.
- Build scripts, tools, or methodologies to enhance incident investigation processes.
- Experience conducting cloud incident response investigations (AWS, Azure, or GCP).
- Experience with macOS and Linux forensic investigations.
- Experience working with SOAR platforms such as D3 Security, Cortex XSOAR, Cortex XSIAM, or similar security automation platforms.
- Experience using Velociraptor for endpoint artifact collection, threat hunting, and forensic investigations.
- Experience using IRIS for incident tracking, case management, and investigation coordination.
Benefits
- Competitive medical, dental and vision coverage for employees and dependents.
- 401k match which vests every payroll.
- Flexible and remote friendly work environment.
- Training opportunities to expand your skill set.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Join Cartwheel to help tackle the student mental health crisis! Cartwheel is an early-stage company building a new kind of mental health program for kids that puts schools at the center. We see our role as supporting school staff who see kids every single day. Instead of going around them, we collaborate with them. This means: - Earlier intervention - Higher student and family engagement in care - Better coordination among the trusted adults in a student’s life Kids shouldn't just aspire to get out of bed and drag themselves to class. They should be able to experience joy. They deserve to envision and build a life they’re excited to live. If you join Cartwheel, you’ll help make this vision a reality for millions of students across the country. We’re backed by top investors including A Street Ventures, Menlo Ventures, Reach Capital, General Catalyst, BoxGroup, and Able Partners, and we're looking for mission-driven teammates to join our team. ABOUT THE ROLE As a Government Relations Operations Manager, you'll be the operational backbone of Cartwheel's government relations team—the person who makes sure our GR strategy translates into impact at scale. You'll manage the systems, workflows, and intelligence that enable our GR executives and state-based team to influence education policy and secure funding for student mental health. This is a high-leverage operations role: you won't be in the room for every negotiation, but you'll ensure everyone in the room has what they need to succeed. You'll own the end-to-end operations of our government affairs function across 10+ states, from tracking legislative opportunities and coordinating lobbyist partnerships to producing monthly impact briefs that shape how policymakers think about student mental health. Role type: W2, Full-Time, Salaried position Salary range: Competitive base + meaningful equity Location: Remote with occasional travel (e.g. 1-2 times per quarter) WHAT YOU'LL DO - Government Relations Marketing: - Coordinate with Marketing, Data, Thought Leadership, and other teams as needed to develop monthly marketing impact briefs across our active states (combination of personalized and more generic briefs depending on state tier) - Manage distribution schedule and delivery of briefs to legislators, governor’s staff, agency staff, and community partners - Gather feedback on and continuously improve brief development process - Develop additional collateral as needed (e.g., two-pagers, slide decks, fliers) - Government Relations Team Knowledge Management: - Maintain centralized opportunity trackers with high accuracy - Maintain GR event trackers (conference calendars, attendee lists, follow-ups) - Maintain library of GR collateral (monthly briefs, two-pagers, talking points) - Maintain library of GR team onboarding and training materials - Government Relations Team Enablement: - Support field team members to maximize their effectiveness (prepare briefings, direct to appropriate collateral, maintain attendee lists, track follow-ups) - Plan and execute major GR team events including state events and road shows - Ensure all team members have access to up-to-date materials and intelligence - Note: This role is not expected to represent Cartwheel in the field on a regular basis, though may involve staffing some in-person events - Contract Lobbying Operations: - Track spend & outcomes for lobbyists in coordination with GR Executives - Support development of lobbyist ROI analyses and performance reviews - Develop standardized lobbyist onboarding materials and information sessions - Manage contracting, compliance, registrations, budget tracking, and ethical standards across all jurisdictions - Note: GR Account Executives own day-to-day lobbyist management and strategy; this role provides enablement - Research & Strategic Support - Conduct research and produce regular intelligence briefings covering notable developments across states, including emerging funding sources - Track KPIs across government activities (e.g., pipeline value, conversion rates) - Provide recommendations to VP of GR on state opportunity prioritization WHO YOU ARE Must have: - 5+ years experience in operations, project management, or chief of staff roles (government affairs, healthcare, education, or high-growth startup environment preferred) - Mission aligned: Genuinely passionate about expanding access to student mental health services. Enthusiastic about building in a startup environment. - Strong writer: You are an excellent writer who can distill quantitative and qualitative information into crisp briefs for a range of external and internal audiences. You've consistently received feedback that your writing is clear and easy to digest. - Eye for design: Able to partner closely with marketing colleagues to develop clear and compelling assets for government audiences (e.g., flyers, slide decks) - Exceptionally organized: You create systems, maintain trackers with precision, and never let balls drop. You like to build templates, create workflows, and document standard operating procedures. You're excited to coordinate across 10+ concurrent workstreams with competing deadlines. - Cross-functional coordinator: You know how to get buy-in, create clear frameworks, and keep teams aligned, including in situations where you don't have formal authority. - Technically proficient: You’re fluent in project management tools (e.g., Asana, Google Sheets) and CRM systems (e.g., Salesforce, Gong). You can learn new tools quickly. Preferred: - State government relations or public affairs background - Healthcare or education policy knowledge - Familiarity with lobbying compliance requirements - RFP/procurement process experience Please apply even if you don't meet all of the criteria. If your past experience doesn't perfectly match the job description, but you bring other relevant experience or skills, we'd still love to hear from you. You may be a great fit! WHY YOU’LL LOVE CARTWHEEL Our hope is that Cartwheel will be your best career decision! In addition to tackling one of the biggest challenges of our time, at a company well-positioned to do so, you'll have: - Mission-oriented and inclusive colleagues who will go to bat for you - Competitive compensation - Generous PPO medical, vision, and dental/ortho coverage - Life Insurance - Generous paid time off, including company closure from Christmas-New Years (12/25-1/1) - Paid holidays and sick leave - Paid parental leave - 401K with employer match - Meaningful equity ownership stake in Cartwheel - Flexible and remote role with regular in-person retreats - Annual learning stipend - Laptop Cartwheel is proud to be an equal opportunity employer. We embrace diverse backgrounds and perspectives and an inclusive work environment. We're committed to equal employment opportunity regardless of race, color, religion, ancestry, national origin, gender, sexual orientation, disability status, or veteran status. We participate in E-Verify. Please be prepared to provide acceptable documentation to verify your identity and work authorization Note: Please do not contact our Care, Provider, or Patient Services lines regarding job postings or application status. These teams support our patients and families and are not involved in the hiring process. For all recruitment-related questions, please email talent@cartwheelcare.org.
Security Operations Engineer
WorkWaveThe Leader in Cloud-Based Field Service and Fleet Management Solutions for Companies With a Mobile Workforce.
• Serve as the primary implementer for the new SIEM solution, configuring data ingestion and tuning the platform for optimal performance • Own the security observability platform on Grafana (Loki/LogQL, Prometheus/PromQL, Grafana Alerting; OTel for collection), including onboarding sources, parsing, enrichment, and alert routing • Own the "Content Engineering" lifecycle: Write, test, and tune detection rules and queries (LogQL, PromQL, SPL, KQL, SQL, etc.) to identify malicious activity with low false-positive rates • Partner with the Engineering team to ensure the new observability platform captures the right security telemetry and logs • Serve as the primary operator for security monitoring and initial incident triage, participating in the on-call rotation
Senior Cybersecurity Operations Consultant
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description In this role, you will support the transition of cybersecurity operations to a new Managed Security Services Provider (MSSP), ensuring secure and efficient integration across hybrid environments. You will deploy, configure, and integrate enterprise security tools, manage telemetry and log flows, and validate operational readiness for both on-premises and cloud systems. - Deploy, configure, and integrate cybersecurity tools across multiple sub-workstreams to support MSSP transition. - Execute configuration updates to redirect logs, telemetry, and security data to the new provider. - Coordinate endpoint agent deployments and other technical dependencies with MSSP teams. - Validate integrations to maintain consistent security visibility across on-premises and cloud environments. - Develop and contribute to operational SOPs, playbooks, and integration documentation. - Identify integration risks, recommend mitigation strategies, and provide technical input on architecture and tooling decisions. - Collaborate with internal teams, client IT stakeholders, and external partners to ensure smooth program transition and stabilization. Qualifications - 5+ years of experience in cybersecurity engineering, security operations, or related roles. - Hands-on experience deploying and integrating enterprise security tools (e.g., SIEM, EDR, logging/telemetry platforms, endpoint agents). - Experience supporting MSSP transitions or outsourced security operations environments. - Strong understanding of log forwarding, telemetry routing, and hybrid environment integrations. - Ability to independently execute configuration changes in active production environments. - Experience creating operational documentation, runbooks, and technical guides. - Strong communication skills and the ability to operate effectively within a cross-functional consulting team. - Must reside in the United States and be authorized to work without sponsorship. - Must be able to pass a background check. Benefits - Fully remote work with flexible hours across the United States. - Hands-on, high-impact cybersecurity consulting experience. - Sponsored and supported professional learning opportunities. - Collaborative, team-oriented, and knowledge-sharing environment. - Opportunity to work on complex, high-visibility cybersecurity projects. - Exposure to enterprise security operations, MSSP transitions, and hybrid cloud/on-prem environments.
Government Security Operations Architect
GEOTABThe world’s #1 telematics provider, committed to advancing technology, empowering businesses and making the roads safer!
• Evaluate designs and architecture, applying deep technical expertise to understand business impacts and recommending new solutions to meet security compliance requirements. • Own System Diagrams for the GTP Gov environment, performing risk assessments, and ensuring security strategies are applied correctly across public sector programs. • Work closely with cross-functional teams, including architecture and development teams, as well as communicate with various stakeholders to translate business requirements into secure technical solutions.



