Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, and compromise assessments across onsite and remote environments.
Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks and response methodologies.
Develop and deliver advisory services including incident response planning workshops, maturity assessments, and tabletop exercises to advance customer readiness.
Perform incident response and forensic analysis of compromised systems, identifying and recommending remediation.
Formulate and direct incident response efforts, prioritizing actions and creating detailed reports on compromise vectors and attacker methodologies.
Build incident response plans, playbooks, and attack scenarios for customer tabletop exercises, maintaining sandbox environments to evaluate malicious code.
Check Point Software Technologies is the world's leading vendor of cyber security, facing sophisticated threats and attacks. Honored by Time Magazine as one of the World's Best Companies and on Forbes' list of the World's Best Places to Work, we have a global team of driven and innovative people.
Responsible for daily incident management of customer incidents, including incident response and forensic analysis of compromised systems.
Formulate and direct incident response efforts, prioritize response actions, and create legible incident reports describing compromise vectors and attacker methodologies.
Build and maintain incident response plans, playbooks, and sandbox/test lab environments to evaluate malicious code.
We protect over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation with a prevention-first approach. We are recognized by TIME, Newsweek, and Forbes for our excellence and workplace culture, and we value ownership, curiosity, and solving complex problems.
Handle complex security incidents, leading deep investigations and driving remediation actions.
Participate in a 24/7 on-call rotation to ensure timely response to critical security incidents.
Mentor L1/L2 analysts and drive improvements in detection capabilities and incident readiness.
Eurofins is an international life sciences company providing analytical testing services to ensure products are safe and authentic. With over 65,000 staff across 950+ laboratories in 59 countries, it offers a multicultural and entrepreneurial work environment.
Lead and mentor a team of Incident Response analysts during active security incidents.
Serve as the primary customer-facing lead during investigations and crisis situations.
Coordinate incident triage, containment, eradication, and recovery efforts.
Check Point Software Technologies is the world's leading vendor of cyber security, facing the most sophisticated threats and attacks. The company has been recognized by Time Magazine, Newsweek, and Forbes as a top employer, with a global team of driven and innovative employees.
Serve as Incident Commander across all severities, orchestrating cross-functional response and setting company-wide standards.
Enforce incident response practices at Director/VP level and drive cross-org adoption of best practices.
Mentor other Incident Commanders, own the 12-month incident response strategy, and influence C-level leaders.
Twilio shapes the future of communications by delivering innovative solutions to hundreds of thousands of businesses and empowering millions of developers worldwide. The company is remote-first with a strong culture of connection and global inclusion, employing thousands of people.
Lead multiple client-facing incident response engagements, guiding clients through the entire lifecycle from detection to recovery.
Conduct scoping calls and coordinate with cross-functional teams, legal counsel, and insurers to ensure high-quality service.
Produce clear reports on incident findings and share knowledge to foster continuous learning within the team.
Surefire Cyber redefines incident response by delivering swift, strong responses to cyber incidents like ransomware and data theft. Founded by industry veterans, the company focuses on client-centric solutions and has a collaborative culture prioritizing efficiency and transparency.
Lead and support the response to all security events and incidents across Twilio's global infrastructure, services, and applications.
Work cross-collaboratively to solve challenges related to a broad spectrum of threat actors and improve security posture.
Own the security incident lifecycle, participate in on-call rotation, and conduct post-incident betterments.
Twilio shapes the future of communications with innovative solutions for hundreds of thousands of businesses, empowering millions of developers worldwide. The company embraces a remote-first work culture and a strong culture of connection and global inclusion, fostering a vibrant and diverse team.
Lead and oversee OT security engineering engagements including deployment, optimization, and architecture assessments.
Author comprehensive deliverables tailored to technical and executive audiences.
Serve as subject matter expert and final technical escalation point for complex OT engagements.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. With over 1,200 employees and a remote-first culture, they serve Fortune 500 companies and U.S. government agencies.
Partner with business development teams to design tailored CIR solutions for clients.
Oversee end-to-end delivery of CIR services including intake, operations, and quality assurance.
Drive adoption of advanced tools and develop training programs for global teams.
Integreon is a global provider of legal and business solutions to law firms, corporations, and professional services firms. With over 3,000 employees worldwide, they offer multi-lingual support and a culture of continuous learning.
Lead and oversee complex client-facing incident response engagements from detection to recovery.
Manage and mentor a team of 3-5 forensic professionals, fostering a collaborative environment.
Collaborate with internal teams, external partners, and clients to refine incident response processes.
Surefire Cyber redefines incident response by delivering swift, stronger responses to cyber incidents like ransomware and data theft. The company was founded by industry veterans who have worked with law firms, insurance carriers, and law enforcement.
Serve as Incident Commander across all severities, orchestrating response and enforcing company-wide standards.
Drive quality and accuracy in incident data, lead cross-org projects, and influence incident response practices.
Bring curiosity to every incident and retrospective, ensuring continuous improvement and stakeholder communication.
Twilio is shaping the future of communications with innovative solutions for hundreds of thousands of businesses and millions of developers worldwide. The company is remote-first, with a strong culture of connection and global inclusion, and empowers employees to make a global impact.
Lead advanced penetration tests and adversary emulation in ICS/OT environments, performing hands-on exploitation of customer networks and systems.
Conduct deep technical analysis of network data to identify attack paths and vulnerabilities, while researching threat actor TTPs.
Deliver clear reports and briefings to customers, mentor team members, and contribute to the OT security community.
Dragos defends industrial organizations providing essentials like water, electricity, and safe working environments. As a market leader in ICS/OT cybersecurity, we are remote-first with global operations and seek mission-oriented teammates embodying authenticity, transparency, and trust.
Monitor security events and provide technical analysis on alerts.
Lead information security incidents and employee insider investigations.
Coordinate building of services and technologies to support security operations.
Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. A recently public company, it fosters a collaborative and growth-minded culture focused on safety, efficiency, and sustainability.
You will hunt for and analyze adversary capabilities targeting ICS/OT networks.
You will develop tools and scripts for capability analysis and inform detection strategies.
Your work directly enhances Dragos' ability to defend against advanced threats.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The company is a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Respond to security incidents as part of a distributed 24x7 on-call schedule, triaging and containing events.
Conduct security investigations and forensics across data sources to determine event timelines and impact.
Build automations leveraging AI and agentic platforms to expedite incident response and scale team impact.
Databricks is the data and AI company, providing a unified platform for data, analytics, and AI. More than 10,000 organizations worldwide, including over 50% of the Fortune 500, rely on Databricks, which fosters a diverse and inclusive culture.
Design, implement, and maintain scalable security architectures across IT, OT, cloud (Azure/M365), and on-premise environments, balancing risk reduction with operational reliability.
Lead security architecture reviews, M&A due diligence, and cross-functional initiatives to ensure secure-by-design solutions and measurable risk reduction.
Serve as senior subject matter expert for incident response, vulnerability management, and OT/ICS security, partnering with SOC and engineering teams.
SOLV Energy is a leading provider of infrastructure services to the power industry, designing, building and maintaining utility scale solar, battery storage and high voltage substation facilities across the United States. It is a national organization that offers broad opportunities for career growth, rooted in core values of Safety, Quality, Innovation and Teamwork.
Lead the strategy, design, and operation of a Cyber Fusion Center including SOC, incident response, and security engineering.
Oversee SOC operations across internal teams and external MSSPs, leveraging AI-enabled platforms.
Drive operational excellence in monitoring, detection, and response, ensuring alignment with frameworks like MITRE ATT&CK.
PDMI provides pharmacy data processing and scalable solutions for private label Pharmacy Benefit Managers, health plans, and hospital systems. The company has been voted Best Employer in Ohio for five consecutive years and offers a collaborative, remote-friendly culture.
Analyze and respond to advanced threats ranging from commodity phishing to zero-day exploits.
Monitor and triage alerts from network security monitoring, EDR platforms, and other log sources.
Create detailed incident reports and collaborate with threat intelligence and incident response teams.
Volexity is a cybersecurity company specializing in threat intelligence and incident response. They have a growing, industry-leading security operations team and value diversity and equal opportunity.
Lead and mentor a remote team of SOC analysts while driving resolution for high-priority security incidents.
Architect sophisticated detection strategies using CrowdStrike Query Language (CQL) and oversee proactive threat-hunting operations.
Collaborate with cross-functional teams to strengthen security controls and document actionable remediation recommendations.
Arista Networks is a leader in data-driven, client-to-cloud networking for large data center, campus, and routing environments. The company is profitable with over $9 billion in revenue and a global, engineering-centric culture that values diversity, inclusion, and innovation.
Research and create defensive security labs and crisis simulation content for the platform.
Work with the Product team on innovations and deploy new features.
Compile technical research into clear content for both technical and non-technical audiences.
Immersive Labs provides a cyber resilience platform that simulates real-world threats to test skills and measure performance. Founded in 2017, the company has grown to over 300 employees globally, secured over £150 million in funding, and been voted a best place to work.