Incident Response Consultant

PonduranceMcLean, VA
$90,000 - $100,000Remote

About The Position

We're looking for an Incident Response Consultant to join our team and help clients navigate cybersecurity incidents with confidence. In this role, you'll serve as a trusted technical advisor during active security incidents, working to contain threats, eradicate malicious activity, and guide clients through every stage of the incident response lifecycle. You'll leverage our security tools and technology stack to investigate intrusions, identify indicators of compromise, and strengthen detection capabilities across network, log, and endpoint environments. The ideal candidate has strong technical expertise in incident response, thrives in high-pressure situations, communicates effectively with both technical and non-technical stakeholders, and is comfortable leading investigations while providing off-hours support when needed.

Requirements

  • 1 to 3 years of experience in a forensic and incident response role
  • Experience performing host- and/or network-based digital forensic investigations
  • Experience conducting malware analysis and investigating advanced cyber threats
  • Experience investigating ransomware incidents and other major cybersecurity events
  • Demonstrated experience leading Business Email Compromise (BEC) investigations, including analysis of Microsoft 365, Exchange Online, Azure/Microsoft Entra ID, and Google Workspace environments to identify identity compromise, mailbox persistence, attacker activity, and support containment and remediation.
  • Knowledge of emerging cyber threats, vulnerabilities, and current security research
  • Excellent analytical, critical thinking, and problem-solving skills
  • Ability to remain calm, focused, and effective while managing high-pressure security incidents
  • Strong written and verbal communication skills, with the ability to explain technical findings, risks, and recommendations to both technical and non-technical audiences
  • Ability to adapt quickly in a fast-paced, evolving environment
  • A passion for continuous learning and professional growth in cybersecurity
  • Strong hands-on working knowledge of: Windows, macOS, and Linux operating systems and forensic analysis techniques
  • Strong hands-on working knowledge of: Common attack methods, threat actor tactics, techniques, and procedures (TTPs), and the ability to respond strategically and tactically
  • Strong hands-on working knowledge of: Scripting languages (such as PowerShell, Python, or Bash) to automate tasks or support investigations
  • Strong hands-on working knowledge of: Microsoft 365, Exchange Online, Microsoft Defender, Azure/Microsoft Entra ID, and Google Workspace environments
  • Strong hands-on working knowledge of: Forensic and investigative tools to determine the scope and impact of a compromise

Responsibilities

  • Support the IR lifecycle from triage to investigation, through containment and eradication
  • Perform forensic analysis, implement incident response procedures, and analyze malware as it presents itself
  • Identify attack vectors, threat tactics, and attacker techniques
  • Provide reports, both written and verbal, to clients
  • Provide after-hours support, as needed, based on the investigation
  • Contribute to process development and documentation regarding the IR lifecycle
  • Work with the SOC to enhance detection capabilities based on indicators detected in an IR engagement

Benefits

  • Medical, dental, vision, disability, FSA, HSA, life and AD&D insurance, 401(k) Plan.
  • PTO, sick, holiday, & parental leave details are available
  • Competitive compensation packages based on the market and your overall credentials.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service