Responsible for daily incident management of customer incidents, including incident response and forensic analysis of compromised systems.
Formulate and direct incident response efforts, prioritize response actions, and create legible incident reports describing compromise vectors and attacker methodologies.
Build and maintain incident response plans, playbooks, and sandbox/test lab environments to evaluate malicious code.
Perform incident response and forensic analysis of compromised systems, identifying and recommending remediation.
Formulate and direct incident response efforts, prioritizing actions and creating detailed reports on compromise vectors and attacker methodologies.
Build incident response plans, playbooks, and attack scenarios for customer tabletop exercises, maintaining sandbox environments to evaluate malicious code.
Check Point Software Technologies is the world's leading vendor of cyber security, facing sophisticated threats and attacks. Honored by Time Magazine as one of the World's Best Companies and on Forbes' list of the World's Best Places to Work, we have a global team of driven and innovative people.
Lead and mentor a team of Incident Response analysts during active security incidents.
Serve as the primary customer-facing lead during investigations and crisis situations.
Coordinate incident triage, containment, eradication, and recovery efforts.
Check Point Software Technologies is the world's leading vendor of cyber security, facing the most sophisticated threats and attacks. The company has been recognized by Time Magazine, Newsweek, and Forbes as a top employer, with a global team of driven and innovative employees.
Partner with business development teams to design tailored CIR solutions for clients.
Oversee end-to-end delivery of CIR services including intake, operations, and quality assurance.
Drive adoption of advanced tools and develop training programs for global teams.
Integreon is a global provider of legal and business solutions to law firms, corporations, and professional services firms. With over 3,000 employees worldwide, they offer multi-lingual support and a culture of continuous learning.
Lead and support the response to all security events and incidents across Twilio's global infrastructure, services, and applications.
Work cross-collaboratively to solve challenges related to a broad spectrum of threat actors and improve security posture.
Own the security incident lifecycle, participate in on-call rotation, and conduct post-incident betterments.
Twilio shapes the future of communications with innovative solutions for hundreds of thousands of businesses, empowering millions of developers worldwide. The company embraces a remote-first work culture and a strong culture of connection and global inclusion, fostering a vibrant and diverse team.
Handle complex security incidents, leading deep investigations and driving remediation actions.
Participate in a 24/7 on-call rotation to ensure timely response to critical security incidents.
Mentor L1/L2 analysts and drive improvements in detection capabilities and incident readiness.
Eurofins is an international life sciences company providing analytical testing services to ensure products are safe and authentic. With over 65,000 staff across 950+ laboratories in 59 countries, it offers a multicultural and entrepreneurial work environment.
Lead multiple client-facing incident response engagements, guiding clients through the entire lifecycle from detection to recovery.
Conduct scoping calls and coordinate with cross-functional teams, legal counsel, and insurers to ensure high-quality service.
Produce clear reports on incident findings and share knowledge to foster continuous learning within the team.
Surefire Cyber redefines incident response by delivering swift, strong responses to cyber incidents like ransomware and data theft. Founded by industry veterans, the company focuses on client-centric solutions and has a collaborative culture prioritizing efficiency and transparency.
Monitor logs, alerts, and telemetry to detect threats across infrastructure and cloud environments.
Perform in-depth security analysis and investigations to assess risk and identify root causes.
Coordinate and execute incident response efforts including containment, mitigation, and recovery.
Binance.US is a licensed and regulated U.S. crypto platform providing secure access to over 190 cryptocurrencies. As a remote-first team, we innovate to bridge traditional finance and Web3, helping bring financial freedom within reach for all.
Monitors, investigates, and responds to cybersecurity events and alerts across various security platforms.
Manages data loss prevention and insider risk alerts, collaborating with IT and business stakeholders.
Supports continuous improvement of detection capabilities through alert tuning and process optimization.
USAP is a company that safeguards organizational data and technology assets through cybersecurity operations. The size and culture are not specified, but the job emphasizes collaboration, continuous improvement, and a secure technology environment.
Protect on-premise and cloud infrastructure, detect and respond to advanced threats, and improve security posture through risk analysis and vulnerability management.
Manage and optimize security tools like SIEM, EDR, and IDS/IPS, and perform proactive threat hunting to anticipate new attack techniques.
Assess security controls for compliance, analyze threat trends, and participate in infrastructure initiatives to adhere to industry best practices.
Clear Capital is a national real estate analytics, data solutions, and valuation technology company. Since 2001, the company has focused on building confidence in real estate decisions, with a team that values integrity, kindness, and attention to detail.
Monitor security events and provide technical analysis on alerts.
Lead information security incidents and employee insider investigations.
Coordinate building of services and technologies to support security operations.
Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. A recently public company, it fosters a collaborative and growth-minded culture focused on safety, efficiency, and sustainability.
Monitor security events and provide technical analysis on alerts.
Lead information security incidents and employee investigations, developing response strategies.
Deliver security guidance and coordinate building services to support security operations.
Samsara is the pioneer of the Connected Operations Cloud, helping organizations that depend on physical operations harness IoT data to improve safety, efficiency, and sustainability. As a recently public company with a culture that encourages rapid career development, they support a flexible, employee-led remote model.
Lead the strategy, design, and operation of a Cyber Fusion Center including SOC, incident response, and security engineering.
Oversee SOC operations across internal teams and external MSSPs, leveraging AI-enabled platforms.
Drive operational excellence in monitoring, detection, and response, ensuring alignment with frameworks like MITRE ATT&CK.
PDMI provides pharmacy data processing and scalable solutions for private label Pharmacy Benefit Managers, health plans, and hospital systems. The company has been voted Best Employer in Ohio for five consecutive years and offers a collaborative, remote-friendly culture.
Monitor and investigate security alerts and events across enterprise environments
Perform proactive threat hunting and support incident response efforts
Use Splunk SIEM for log analysis and work with EDR technologies like CrowdStrike and Cisco AMP
Cyderes builds practical Identity & Access Management and Exposure Management programs, helping organizations stop active threats fast with Managed Detection & Response integrated with existing tools. The company is a Great Place to Work® Certified™ global team operating across the United States, Canada, United Kingdom, and India.
Respond to security incidents as part of a distributed 24x7 on-call schedule, triaging and containing events.
Conduct security investigations and forensics across data sources to determine event timelines and impact.
Build automations leveraging AI and agentic platforms to expedite incident response and scale team impact.
Databricks is the data and AI company, providing a unified platform for data, analytics, and AI. More than 10,000 organizations worldwide, including over 50% of the Fortune 500, rely on Databricks, which fosters a diverse and inclusive culture.
Monitor and analyze security events, lead incident response, and maintain SIEM and EDR tools.
Ensure compliance with HIPAA, HITECH, and other healthcare regulations through risk assessments and audits.
Conduct vulnerability scans, manage remediation, and support secure design reviews for systems and applications.
LUX Infusion reimagines infusion care to be more human, supportive, and connected. As a clinician-led, U.S.-based organization, we put people first with a commitment to inclusion, diversity, equity, and advancement (IDEA).
Investigate security alerts using tools such as CrowdStrike Falcon Suite and Microsoft Sentinel to determine scope and impact.
Support incident response activities, including containment, remediation, and post-incident documentation.
Collaborate with cross-functional teams to improve detection quality, workflows, and response readiness.
Commvault is the gold standard in cyber resilience, empowering customers to uncover, take action, and rapidly recover from cyberattacks. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks and improve governance.
Lead and oversee complex client-facing incident response engagements from detection to recovery.
Manage and mentor a team of 3-5 forensic professionals, fostering a collaborative environment.
Collaborate with internal teams, external partners, and clients to refine incident response processes.
Surefire Cyber redefines incident response by delivering swift, stronger responses to cyber incidents like ransomware and data theft. The company was founded by industry veterans who have worked with law firms, insurance carriers, and law enforcement.
Analyze, investigate, document, and report on security alerts or potential incidents in customer environments.
Process security investigation cases thoroughly and timely, and serve as an incident coordinator for urgent response and remediation.
Provide continuous feedback on process improvements and stay up-to-date on security training and emerging threats.
CyberSheath is a rapidly growing managed security services provider focused on cybersecurity for the Defense Industrial Base. They have a small but expanding team and emphasize a fully remote work culture.
Lead and mentor a remote team of SOC analysts while driving resolution for high-priority security incidents.
Architect sophisticated detection strategies using CrowdStrike Query Language (CQL) and oversee proactive threat-hunting operations.
Collaborate with cross-functional teams to strengthen security controls and document actionable remediation recommendations.
Arista Networks is a leader in data-driven, client-to-cloud networking for large data center, campus, and routing environments. The company is profitable with over $9 billion in revenue and a global, engineering-centric culture that values diversity, inclusion, and innovation.
Monitor security alerts, vulnerabilities, and incidents across enterprise systems and assist in incident response.
Maintain compliance with standards such as NIST CSF, ISO 27001, and SOC 2 through audits and policy development.
Conduct security risk assessments, evaluate controls, and track remediation plans.
Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, they support data centers, healthcare, and industrial facilities.