FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates deep expertise in incident response, including triage, containment, eradication, recovery, and root cause analysis, while effectively communicating findings to both technical and non-technical stakeholders. Proficient in leading complex security incidents and mentoring security teams, with a strong focus on detection engineering and threat hunting.
Highest-signal resume keywords
Incident Response LeadershipAdvanced Digital ForensicsDetection EngineeringThreat HuntingMITRE ATT&CK Framework
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseDigital ForensicsDetection EngineeringThreat HuntingRoot Cause AnalysisTriageContainmentEradicationRecoveryScripting
Soft Skills
Excellent CommunicationMentoringLeadership
Tools & Technologies
EDR/XDR PlatformsSIEM/NG-SIEM PlatformsCrowdStrike NG-SIEMSplunkMicrosoft Sentinel
Industry Keywords
Information SecurityCompliance FrameworksPCI-DSSCloud SecurityNetwork Security
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformLinuxPythonSplunk
About the role
Key responsibilities & impact- Serve as principal escalation point and lead investigator for complex, high-severity, and novel security incidents
- Triage, investigate, contain, eradicate, and recover from incidents across endpoint, network, cloud, identity, and application layers
- Lead forensic investigations and reconstruct attack timelines
- Translate investigation findings into technical and executive-level narratives
- Own and evolve incident response processes, documentation, and playbooks
- Lead root cause analyses and post-incident reviews
- Coordinate major incidents across IT, legal, compliance, and executive leadership
- Mentor incident responders and SOC analysts during live incidents
- Participate in or lead on-call rotation for critical incident response
- Write, tune, and validate SIEM/NG-SIEM detection content
- Maintain MITRE ATT&CK coverage and gap analysis
- Conduct proactive, hypothesis-driven threat hunts
- Use hunt outcomes to identify compromises and strengthen detection coverage
- Partner with threat intelligence sources and feeds
- Represent incident response in planning, tabletop exercises, and architecture reviews
- Lead complex incident-related investigations and initiatives
- Partner with cloud, network, and identity teams to close visibility and telemetry gaps
- Communicate findings and recommendations to technical and non-technical stakeholders
- Develop and maintain incident response procedure and policy documentation
Requirements
What you’ll need- Bachelor's degree in a technical field, or equivalent professional experience
- 7+ years of hands-on information security experience
- Deep subject-matter expertise in incident response, with strong working proficiency in detection engineering and threat hunting
- Demonstrated ability to independently lead complex, high-severity security incidents from detection through recovery
- Experience mentoring or providing technical leadership to security engineers and analysts
- Excellent written and verbal communication skills
- Deep hands-on expertise in end-to-end incident response, including triage, containment, eradication, recovery, and root cause analysis
- Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics
- Advanced experience with EDR/XDR platforms and log analysis
- Strong working knowledge of detection engineering and SIEM/NG-SIEM platforms such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel
- Working proficiency in hypothesis-driven threat hunting
- Deep working knowledge of the MITRE ATT&CK framework
- Strong scripting or automation experience with Python, PowerShell, or similar, and/or experience using LLM coding tools
- Solid understanding of networking, AWS, Azure, GCP, Windows/Linux systems, and identity platforms
- Working knowledge of PCI-DSS or a comparable compliance framework
- Ability to lead high-pressure, ambiguous, cross-functional investigations with minimal oversight
- Relevant hands-on experience and subject-matter expertise weighted more heavily than certifications
- North is a US-based company; no sponsorship is available
Benefits
Comp & perks- Total rewards offerings
- Benefits supporting overall well-being
- Unique personally and professionally fulfilling initiatives
- Inclusive work environment
- Equal opportunity employment
