Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Harbor IT

Incident Response Lead

Harbor IT

. Serve as incident commander for client security incidents .

Posted 9/26/2026full-timeRemote • United StatesSenior💰 $105,000 - $135,000 per yearWebsite

Tech Stack

Tools & technologies
AWSCloudCyber SecurityFirewallsLinux

About the role

Key responsibilities & impact
  • Serve as incident commander for client security incidents
  • Establish scope, set response priorities, assign actions to named owners, track decisions, and keep incidents moving
  • Run triage and initial investigation across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline
  • Delegate information gathering while focusing on incident-command decisions
  • Own containment decisions involving isolation, credential resets, evidence preservation, and client approval authority
  • Decide whether incidents remain within Harbor’s scope or require escalation to outside DFIR firms, breach counsel, or insurance panels
  • Own in-scope incidents from detection through post-incident reporting
  • Brief receiving DFIR firms and hand off with a written timeline and evidence inventory
  • Carry on-call responsibility and remain available outside business hours for incident escalation
  • Translate technical findings into actionable decisions for owners, executives, and general counsel
  • Coordinate with breach counsel, cyber insurance carriers and panel firms, third-party DFIR teams, client IT, and law enforcement where applicable
  • Keep Client Success and leadership current on active incidents
  • Produce post-incident reports covering confirmed and assumed facts, containment, open items, and recommended client changes
  • Write and maintain incident response playbooks, severity model, and escalation matrix
  • Define Harbor’s incident-response responsibility boundaries in writing
  • Build working relationships with outside DFIR firms and breach counsel practices
  • Maintain escalation-readiness records for every managed client
  • Run tabletop exercises with Harbor teams and clients when applicable and feasible
  • Mentor SOC analysts and security engineers on investigative method and incident discipline
  • Feed incident lessons back to detection engineering to improve future detection

Requirements

What you’ll need
  • 6+ years in cybersecurity, with substantial time spent responding to real intrusions rather than monitoring for them
  • Direct experience acting as the lead on security incidents, setting direction while others execute
  • Experience responding across multiple distinct organizations, whether from a consulting, MSSP, MDR, or panel DFIR background
  • Hands-on investigative depth in Microsoft 365, Google Workspace, and Entra ID compromise
  • Experience with unified audit log analysis, message trace, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access gaps
  • Working command of endpoint detection and response tooling for investigation and containment
  • Host and Windows internals knowledge sufficient to interpret process lineage, persistence mechanisms, and lateral movement evidence
  • Ability to build defensible incident timelines from SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets
  • Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft
  • Experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including investigation handoff
  • Ability to brief non-technical executives under pressure and write clear, actionable client documentation
  • Willingness and ability to be reachable outside business hours for incident escalation
  • Preferred: GCIH, GCFA, GCIA, or comparable GIAC certification; CISSP or CISM
  • Preferred: prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team
  • Preferred: host and memory forensics, malware triage, or reverse engineering
  • Preferred: Linux investigation experience and cloud incident response beyond Microsoft, such as AWS
  • Preferred: familiarity with HIPAA, PCI DSS, GLBA, state breach notification statutes, or SEC disclosure rules
  • Preferred: background in managed services or another multi-tenant environment where the candidate owned both the relationship and investigation

Benefits

Comp & perks
  • Employer-paid medical, dental, and vision coverage for the employee, with additional premium plan options available
  • 401(k) with company match
  • Paid time off
  • Reimbursement for approved tuition, certifications, and conference attendance