# Senior Incident Response Analyst

**Company:** [OpenLoop](https://hotfix.jobs/companies/openloop)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 6+ years
**Skills:** Incident Response, Digital Forensics, Edr, SIEM, Python, PowerShell, Mitre Att&Ck, Velociraptor, Kape, Volatility, AWS, Crowdstrike Falcon, Okta, Wireshark
**Posted:** 2026-09-08

> Own end-to-end security incidents and conduct forensic investigations across endpoint, network, cloud, memory, and identity environments. The role requires 6–8 years of hands-on security experience, strong EDR/SIEM and scripting skills, and participation in an incident-response on-call rotation.

## Job Description

## Responsibilities
- Own Tier 1 and Tier 2 incidents end to end, including detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
- Conduct host, memory, network, cloud, and identity forensic investigations independently.
- Investigate EDR and SIEM telemetry; write and refine queries, build correlation logic, and reconstruct incident timelines.
- Participate in a shared incident-response on-call rotation and exercise defined containment authority, including host isolation and session revocation.
- Author and revise incident-response playbooks based on worked incidents; lead post-incident reviews and track findings to closure.
- Automate or AI-assist repetitive triage and evidence-collection tasks.
- Produce defensible technical timelines and executive incident summaries.

## Requirements
- 6–8 years of hands-on security experience, primarily in incident response and/or digital forensics.
- Demonstrated ownership of the complete incident lifecycle.
- Practical digital-forensics experience across host/disk, memory, network, cloud, and identity investigations.
- Hands-on EDR/EPP experience, including endpoint telemetry investigation, response actions, and tuning.
- Hands-on SIEM experience, including query authoring, correlation logic, and timeline reconstruction.
- Fluency with forensic tools such as Velociraptor, KAPE, Volatility, Autopsy, EnCase, FTK, X-Ways, plaso, Zeek, or Wireshark.
- Evidence-handling discipline, including chain of custody, sound acquisition, and defensible documentation.
- MITRE ATT&CK fluency applied to real investigations.
- Scripting experience with Python, PowerShell, or similar.
- Demonstrated use of AI tools in security work, with sound judgment regarding sensitive data.
- Strong technical and executive incident writing skills.
- Willingness to participate in an incident-response on-call rotation.
- No specific degree required.

## Preferred Qualifications
- CrowdStrike Falcon EDR, Falcon Next-Gen SIEM, and Falcon Shield experience.
- CrowdStrike Query Language (CQL) query authoring, correlation rules, and dashboards.
- AWS cloud incident response, including CloudTrail, GuardDuty, and IAM abuse investigations.
- Identity-centric investigations, particularly Okta session hijacking, MFA fatigue, token theft, and SSO abuse.
- Healthcare, fintech, or other regulated-industry experience with sensitive data.
- Operator-side HIPAA, HITRUST, or SOC 2 experience, including breach determination workflows.
- GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent expertise.
- Malware triage and reverse-engineering fundamentals.
- SOAR or automation-platform experience, or AI-assisted incident-response workflows using LLM APIs.
- Multi-entity or M&A environment experience.
- Open-source DFIR contributions, CTF participation, conference talks, or other security-community engagement.
- Experience maturing an incident-response program.
- Threat-intelligence experience applied to active investigations.

## Compensation and Benefits
- Medical, dental, and vision plans.
- Flexible Spending Accounts and Health Savings Accounts.
- Flexible paid time off.
- 401(k) with company match.
- Life insurance and pet insurance.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/5c047c0d-5aa6-42fa-8ebd-b5ecf0068e85
**Canonical:** https://hotfix.jobs/jobs/5c047c0d-5aa6-42fa-8ebd-b5ecf0068e85