FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAWSCloudCyber SecurityFirewallsLinux
About the role
Key responsibilities & impact- Serve as incident commander for client security incidents
- Establish scope, set response priorities, assign actions to named owners, track decisions, and keep incidents moving
- Run triage and initial investigation across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline
- Delegate information gathering while focusing on incident-command decisions
- Own containment decisions involving isolation, credential resets, evidence preservation, and client approval authority
- Decide whether incidents remain within Harbor’s scope or require escalation to outside DFIR firms, breach counsel, or insurance panels
- Own in-scope incidents from detection through post-incident reporting
- Brief receiving DFIR firms and hand off with a written timeline and evidence inventory
- Carry on-call responsibility and remain available outside business hours for incident escalation
- Translate technical findings into actionable decisions for owners, executives, and general counsel
- Coordinate with breach counsel, cyber insurance carriers and panel firms, third-party DFIR teams, client IT, and law enforcement where applicable
- Keep Client Success and leadership current on active incidents
- Produce post-incident reports covering confirmed and assumed facts, containment, open items, and recommended client changes
- Write and maintain incident response playbooks, severity model, and escalation matrix
- Define Harbor’s incident-response responsibility boundaries in writing
- Build working relationships with outside DFIR firms and breach counsel practices
- Maintain escalation-readiness records for every managed client
- Run tabletop exercises with Harbor teams and clients when applicable and feasible
- Mentor SOC analysts and security engineers on investigative method and incident discipline
- Feed incident lessons back to detection engineering to improve future detection
Requirements
What you’ll need- 6+ years in cybersecurity, with substantial time spent responding to real intrusions rather than monitoring for them
- Direct experience acting as the lead on security incidents, setting direction while others execute
- Experience responding across multiple distinct organizations, whether from a consulting, MSSP, MDR, or panel DFIR background
- Hands-on investigative depth in Microsoft 365, Google Workspace, and Entra ID compromise
- Experience with unified audit log analysis, message trace, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access gaps
- Working command of endpoint detection and response tooling for investigation and containment
- Host and Windows internals knowledge sufficient to interpret process lineage, persistence mechanisms, and lateral movement evidence
- Ability to build defensible incident timelines from SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets
- Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft
- Experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including investigation handoff
- Ability to brief non-technical executives under pressure and write clear, actionable client documentation
- Willingness and ability to be reachable outside business hours for incident escalation
- Preferred: GCIH, GCFA, GCIA, or comparable GIAC certification; CISSP or CISM
- Preferred: prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team
- Preferred: host and memory forensics, malware triage, or reverse engineering
- Preferred: Linux investigation experience and cloud incident response beyond Microsoft, such as AWS
- Preferred: familiarity with HIPAA, PCI DSS, GLBA, state breach notification statutes, or SEC disclosure rules
- Preferred: background in managed services or another multi-tenant environment where the candidate owned both the relationship and investigation
Benefits
Comp & perks- Employer-paid medical, dental, and vision coverage for the employee, with additional premium plan options available
- 401(k) with company match
- Paid time off
- Reimbursement for approved tuition, certifications, and conference attendance
