The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments. The role combines deep incident response expertise with practical leadership: directing technical containment, coordinating resources across SOC, service desk, infrastructure, cloud, networking, compliance, account management, and client leadership teams, and serving as a trusted communicator during high-pressure events. This position is hands-on and client-facing. The responder is expected to investigate endpoint, identity, cloud, email, network, and SaaS activity; determine scope and impact; recommend and execute containment and eradication steps; and translate technical findings into clear decisions, risks, and next steps for clients and internal stakeholders. The role also improves SOC maturity by mentoring analysts, refining incident response playbooks, leading post-incident reviews, supporting tabletop exercises, and driving measurable improvements in detection, response, documentation, and recovery readiness.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior