Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
North

Principal Incident Response Analyst

North

. Serve as principal escalation point and lead investigator for complex, high-severity, and novel security incidents .

Posted 10/6/2026full-timeRemote • United StatesLead💰 $150,000 - $180,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates deep expertise in incident response, including triage, containment, eradication, recovery, and root cause analysis, while effectively communicating findings to both technical and non-technical stakeholders. Proficient in leading complex security incidents and mentoring security teams, with a strong focus on detection engineering and threat hunting.

Highest-signal resume keywords
Incident Response LeadershipAdvanced Digital ForensicsDetection EngineeringThreat HuntingMITRE ATT&CK Framework

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Incident ResponseDigital ForensicsDetection EngineeringThreat HuntingRoot Cause AnalysisTriageContainmentEradicationRecoveryScripting
Soft Skills
Excellent CommunicationMentoringLeadership
Tools & Technologies
EDR/XDR PlatformsSIEM/NG-SIEM PlatformsCrowdStrike NG-SIEMSplunkMicrosoft Sentinel
Industry Keywords
Information SecurityCompliance FrameworksPCI-DSSCloud SecurityNetwork Security

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformLinuxPythonSplunk

About the role

Key responsibilities & impact
  • Serve as principal escalation point and lead investigator for complex, high-severity, and novel security incidents
  • Triage, investigate, contain, eradicate, and recover from incidents across endpoint, network, cloud, identity, and application layers
  • Lead forensic investigations and reconstruct attack timelines
  • Translate investigation findings into technical and executive-level narratives
  • Own and evolve incident response processes, documentation, and playbooks
  • Lead root cause analyses and post-incident reviews
  • Coordinate major incidents across IT, legal, compliance, and executive leadership
  • Mentor incident responders and SOC analysts during live incidents
  • Participate in or lead on-call rotation for critical incident response
  • Write, tune, and validate SIEM/NG-SIEM detection content
  • Maintain MITRE ATT&CK coverage and gap analysis
  • Conduct proactive, hypothesis-driven threat hunts
  • Use hunt outcomes to identify compromises and strengthen detection coverage
  • Partner with threat intelligence sources and feeds
  • Represent incident response in planning, tabletop exercises, and architecture reviews
  • Lead complex incident-related investigations and initiatives
  • Partner with cloud, network, and identity teams to close visibility and telemetry gaps
  • Communicate findings and recommendations to technical and non-technical stakeholders
  • Develop and maintain incident response procedure and policy documentation

Requirements

What you’ll need
  • Bachelor's degree in a technical field, or equivalent professional experience
  • 7+ years of hands-on information security experience
  • Deep subject-matter expertise in incident response, with strong working proficiency in detection engineering and threat hunting
  • Demonstrated ability to independently lead complex, high-severity security incidents from detection through recovery
  • Experience mentoring or providing technical leadership to security engineers and analysts
  • Excellent written and verbal communication skills
  • Deep hands-on expertise in end-to-end incident response, including triage, containment, eradication, recovery, and root cause analysis
  • Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics
  • Advanced experience with EDR/XDR platforms and log analysis
  • Strong working knowledge of detection engineering and SIEM/NG-SIEM platforms such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel
  • Working proficiency in hypothesis-driven threat hunting
  • Deep working knowledge of the MITRE ATT&CK framework
  • Strong scripting or automation experience with Python, PowerShell, or similar, and/or experience using LLM coding tools
  • Solid understanding of networking, AWS, Azure, GCP, Windows/Linux systems, and identity platforms
  • Working knowledge of PCI-DSS or a comparable compliance framework
  • Ability to lead high-pressure, ambiguous, cross-functional investigations with minimal oversight
  • Relevant hands-on experience and subject-matter expertise weighted more heavily than certifications
  • North is a US-based company; no sponsorship is available

Benefits

Comp & perks
  • Total rewards offerings
  • Benefits supporting overall well-being
  • Unique personally and professionally fulfilling initiatives
  • Inclusive work environment
  • Equal opportunity employment