Senior Incident Responder
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
About the job
Responsibilities
- Lead the full incident response lifecycle, from client intake and triage through containment, eradication, recovery, and post-incident reporting.
- Investigate and remediate complex compromises, including compromised email ecosystems, SIM-swap attacks, financial account takeovers, targeted credential harvesting, mobile threats, and endpoint malware.
- Analyze client computers and mobile devices to determine compromise scope and implement remediation strategies across Windows, macOS, iOS, Android, and Linux.
- Analyze email, banking, retail, social-platform, and transaction activity to establish what occurred; support fraud investigations, disputes, chargebacks, account freezes, and platform coordination.
- Guide identity-theft remediation, including credit-bureau freezes and fraud alerts, IdentityTheft.gov and law-enforcement reporting, and ongoing monitoring guidance.
- Map incidents against cyber and personal attack kill chains to identify attack stages, exposure, and chain-breaking actions.
- Provide white-glove support to clients, families, assistants, family offices, and corporate security during emergency onboardings and active incidents.
- Participate in an on-call and escalation rotation, including occasional nights and weekends.
- Serve as the highest technical escalation point and mentor Security and Client Success team members.
- Oversee network vulnerability scans, refine internal incident-response playbooks, and conduct post-onboarding security touchpoints.
Requirements
- 5–8+ years of experience in incident response, digital forensics and incident response (DFIR), or advanced cybersecurity analysis.
- Proven experience executing the complete incident lifecycle, especially for executive or personal account takeovers, mobile threats, and endpoint malware.
- Experience investigating financial fraud and coordinating with banks and credit-card companies on disputes, chargebacks, transaction analysis, or account-takeover response.
- Deep forensic and vulnerability-management expertise across Windows, macOS, iOS, Android, and Linux.
- Working knowledge of identity-theft remediation and attack kill-chain models applied to individuals and families.
- Exceptional communication, empathy, composure, and ability to translate technical findings into actionable client guidance.
- College degree in Information Technology, Computer Science, Computer Engineering, or equivalent real-world experience.
- Ability to work highly independently.
Nice-to-haves
- GCIH, GCFA, CISSP, OSCP, or similar advanced certification.
- CFE, CFCS, CAMS, or similar fraud and financial-crime credential.
Skills
Incident Response, Digital Forensics, Vulnerability Management, Windows, macOS, iOS, Android, Linux, Identity Theft Remediation, Attack Kill Chain, Fraud Investigation, Transaction Analysis, Endpoint Malware, Sim Swapping, Gcih
Similar jobs
Security Engineering jobsSenior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.