Mid- Senior Cyber Security Incident Responder

Victory In Christ (ministry)•Chicago, IL
•$130,000 - $150,000•Remote

About The Position

We are looking for a mid-to-senior level response engineer to join the Risk Operations Center (ROC). This role involves responding to security incidents, conducting threat hunts, engineering detections, analyzing threat intelligence, and investigating fraud when it overlaps with security incidents. The position requires rotating and flexing across five unique domains: Incident Response, Threat Hunting, Detection Engineering, Threat Intelligence, and Fraud Investigations. The role operates from a real IR plan mapped to NIST CSF 2.0 and a growing playbook library, with the opportunity to refine and advance these processes.

Requirements

  • 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role.
  • Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures).
  • Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms.
  • Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies.
  • Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews.
  • Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS.
  • Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership.
  • Bachelor’s degree in cybersecurity, information technology, or equivalent experience.

Nice To Haves

  • Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus.
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)

Responsibilities

  • Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned.
  • Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps.
  • Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes.
  • Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents.
  • Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time.
  • Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively.
  • Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness.
  • Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization.
  • Collaborate with engineering teams to continuously strengthen detection and response capabilities.

Benefits

  • Eligibility to participate in a company-sponsored 401(k)
  • Vacation benefits
  • Eligibility for medical, dental, vision, and prescription drug benefits
  • Flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts)
  • Life insurance and death benefits
  • Critical care insurance
  • Personal accidental insurance
  • Commuter benefits
  • Pet insurance
  • Certain time off and leave of absence benefits
  • Well-being benefits (e.g., employee assistance program)
  • Other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service