Incident Response Analyst
REACT Consultant performing incident response, active edge mitigation, forensics, and threat containment for Cloudflare customers across on-prem, cloud, and hybrid environments. Requires 3+ years cybersecurity experience including 2+ years in IR/forensics, strong network and OS knowledge, and customer-facing skills.
About the job
Key Responsibilities
Incident Response & Active Edge Mitigation
- Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability, including deploying custom WAF rules, implementing L3/L4 DDoS shunning, and performing real-time traffic filtering.
- Support the full IR lifecycle (investigation, containment, remediation, recovery) for clients, review technical deliverables, and coordinate with customer stakeholders.
- Build understanding of targeted attacks to create and execute customized tactical and strategic remediation plans.
Direct Customer Containment & Threat Isolation
- For ransomware and BEC: identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration.
- For insider threats and nation-state attacks: track lateral movement, identify persistent backdoors, correlate threat actor activity, and execute containment while preserving evidence.
Forensics, Engineering & AI Analysis
- Conduct initial evidence preservation (logs, volatile memory, disk images) according to forensic standards.
- Create and enhance client-facing Crisis & Incident Response solutions based on ISO 27001, NIST, CIS standards; identify opportunities for process optimization.
- Utilize AI-powered security platforms to synthesize telemetry, automate log summarization, and accelerate threat pattern identification.
- Prepare high-fidelity incident reports, forensic findings, and client communications.
Requirements
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience).
- 3+ years in cybersecurity, including 2+ years in Incident Response/Digital Forensics and 1+ years in a customer-facing role.
- In-depth understanding of Windows; general knowledge of Unix, Linux, Mac.
- Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies.
- Strong knowledge of network protocols (TCP/IP, HTTPS, FTP, SFTP, SSH, RDP, CIFS/SMB, NFS); experience with tools like Bro/Zeek or Suricata.
- Solid understanding of MITRE ATT&CK and NIST frameworks.
- Excellent verbal and written communication skills for executive and technical audiences.
Nice-to-Haves
- Proficient in Python or Golang for writing scripts.
- Proficient with Yara for writing detection rules.
- Understanding of source code, hex, binary, regex, data correlation, and analysis of network flows/system logs.
- Practical malware analysis (static, dynamic, automated); reverse engineering file formats.
- Reverse engineering experience with APT malware, including infection vectors, infrastructure enumeration, attribution, and evasion tactics.
- Familiarity with bash for static analysis and IOC investigation.
Skills
Incident Response, Digital Forensics, Mitre Att&Ck, Nist, Windows, Linux, AWS, Azure, Python, Go, Yara, Network Forensics, Malware Analysis, Reverse Engineering
Similar jobs
Support Engineering jobsSupports clients and reseller partners by managing affiliate channels, implementing partner integrations, troubleshooting invoicing and booking issues, and improving support processes. Requires strong communication, analytical problem-solving, technical comfort, and customer-service skills.
Provides high-priority technical support to Premium and enterprise customers, troubleshooting complex platform issues, coordinating incidents, and improving support tooling and processes. Requires at least 3 years of technical support or systems engineering experience plus strong JavaScript or Python debugging skills.
Provides high-priority technical support to Premium and enterprise customers, troubleshooting complex platform issues, coordinating incidents, and improving support operations. Requires at least three years of technical support or systems engineering experience plus strong JavaScript or Python debugging skills.
Supports hybrid and self-hosted customer deployments by troubleshooting Kubernetes, cloud infrastructure, networking, backend performance, and reliability issues. The role combines technical customer support, incident response, coding fixes, and diagnostic tooling across major cloud platforms.
Provides advanced technical, operational, and field support for Skydio UAS hardware, docks, cloud systems, and networking. The role requires at least three years of UAS flight experience, strong troubleshooting skills, and regional travel of up to 30–50%.