Incident Response Lead

Harbor IT
•$105,000 - $128,000•Remote

About The Position

This is a new role responsible for managing the initial hours of client security incidents, including triage, scoping, containment decisions, and determining when to escalate to outside firms. The role involves acting as incident commander, directing internal teams, and building the incident response practice. The position reports to the Senior Director of Cyber Services and collaborates with various internal departments and external stakeholders.

Requirements

  • 6+ years in cybersecurity with substantial experience responding to real intrusions.
  • Direct experience acting as the lead on security incidents, setting direction and managing execution.
  • Experience responding to incidents across multiple distinct organizations (consulting, MSSP, MDR, or panel DFIR background).
  • Hands-on investigative experience in Microsoft 365, Google Workspace, and Entra ID compromise.
  • Working command of endpoint detection and response (EDR) tooling for investigation and containment.
  • Sufficient host and Windows internals knowledge to interpret investigative data.
  • Ability to build a defensible incident timeline from mixed and incomplete sources.
  • Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft.
  • Demonstrated experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including handoffs.
  • Ability to brief non-technical executives under pressure.
  • Clear and concise written communication skills.
  • Willingness and ability to be reachable outside business hours for incident escalation.

Nice To Haves

  • GCIH, GCFA, GCIA, or comparable GIAC certification. CISSP or CISM.
  • Prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team.
  • Host and memory forensics depth, malware triage, or reverse engineering.
  • Linux investigation experience.
  • Cloud incident response beyond Microsoft (e.g., AWS, Google Workspace).
  • Familiarity with regulatory and contractual notification obligations (HIPAA, PCI DSS, GLBA, state breach notification statutes, SEC disclosure rules).
  • Background in managed services or another multi-tenant environment where relationship ownership was part of the role.

Responsibilities

  • Serve as incident commander for client security incidents, establishing scope, setting priorities, assigning actions, tracking decisions, and managing the incident response process.
  • Lead triage and initial investigations across managed environments including Microsoft 365, Entra ID, Active Directory, endpoints, servers, firewalls, and the Sagan-based detection pipeline.
  • Make and defend containment decisions, including isolation, credential resets, and evidence preservation.
  • Determine when to escalate incidents and own those within Harbor's scope from detection to post-incident reporting.
  • Handle on-call responsibilities and be available outside of business hours for incident escalation.
  • Communicate technical findings to clients in a clear, actionable manner for executives and owners.
  • Coordinate with external parties such as breach counsel, cyber insurance carriers, DFIR teams, and law enforcement.
  • Produce comprehensive post-incident reports detailing the incident, findings, containment, and recommendations.
  • Develop and maintain incident response playbooks, severity models, and escalation matrices.
  • Establish relationships with external DFIR firms and breach counsel practices.
  • Maintain an escalation-readiness record for each managed client.
  • Conduct tabletop exercises with internal teams and clients to test and improve incident response processes.
  • Mentor SOC analysts and security engineers, and provide feedback to detection engineering based on incident lessons learned.

Benefits

  • Employer-paid medical, dental, and vision coverage for the employee
  • Additional premium plan options available
  • 401(k) with company match
  • Paid time off
  • Reimbursement for approved tuition, certifications, and conference attendance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service