Dice logo
Dice
Posted 17 days agoVerified live 4d ago

Incident Response Analyst

Brief overview

Remote
UndergradOr in progress
$80k–$120k/yrStated range
3+ yrsMinimum
Incident ResponseWindows Endpoint InvestigationActive DirectoryMicrosoft Entra IDMicrosoft 365Authentication and Identity Threat ResponseRansomware ResponseBusiness Email Compromise ResponseEndpoint Detection and Response (EDR)CrowdStrikeSecurity Telemetry AnalysisDigital ForensicsCase Management

About the company

Dice is the go-to career marketplace for tech professionals.

Job description

Summary

Dice is seeking an Incident Response Analyst to support active cybersecurity incidents. The role handles investigations through containment, scoping, eradication, and recovery, including ransomware, business email compromise, credential theft, cloud compromise, lateral movement, and data exfiltration incidents.

Responsibilities

  • Hands-on incident response position supporting active cybersecurity incidents from initial investigation through containment, scoping, eradication, and recovery
  • This role will work directly on ransomware, business email compromise, credential theft, cloud compromise, lateral movement, data exfiltration, and other active security incidents
  • Preference: Experienced responder capable of independently owning significant portions of an active incident while coordinating effectively with senior DFIR personnel

Skills

  • Professional hands-on incident response experience
  • Strong Windows endpoint investigation experience
  • Strong understanding of Active Directory, Entra ID, Microsoft 365, authentication, and identity-related attacks
  • Experience responding to ransomware, BEC, compromised accounts, persistence, credential access, lateral movement, and data exfiltration
  • Strong EDR experience
  • Experience analyzing endpoint, authentication, identity, network, email, and cloud telemetry
  • Ability to scope incidents and identify affected users, systems, accounts, and infrastructure
  • Experience identifying attacker activity and reconstructing attack timelines
  • Comfortable making containment and remediation recommendations during active incidents
  • Ability to operate effectively during high-pressure and rapidly evolving incidents
  • Strong investigative documentation and case management discipline
  • Ability to communicate findings clearly to senior technical personnel, engagement leadership, clients, and other stakeholders
  • Currently reside in the U.S. and be eligible to work for any U.S. employer without ever requiring sponsorship or a 3rd party
  • Able to pass a background check
  • CrowdStrike experience strongly preferred
  • Digital forensics experience is beneficial, but this position should be incident-response-first
  • Experienced responder capable of independently owning significant portions of an active incident while coordinating effectively with senior DFIR personnel

Qualifications

Must Haves

  • Professional hands-on incident response experience
  • Strong Windows endpoint investigation experience
  • Strong understanding of Active Directory, Entra ID, Microsoft 365, authentication, and identity-related attacks
  • Experience responding to ransomware, BEC, compromised accounts, persistence, credential access, lateral movement, and data exfiltration
  • Strong EDR experience
  • Experience analyzing endpoint, authentication, identity, network, email, and cloud telemetry
  • Ability to scope incidents and identify affected users, systems, accounts, and infrastructure
  • Experience identifying attacker activity and reconstructing attack timelines
  • Comfortable making containment and remediation recommendations during active incidents
  • Ability to operate effectively during high-pressure and rapidly evolving incidents
  • Strong investigative documentation and case management discipline
  • Ability to communicate findings clearly to senior technical personnel, engagement leadership, clients, and other stakeholders
  • Currently reside in the U.S. and be eligible to work for any U.S. employer without ever requiring sponsorship or a 3rd party
  • Able to pass a background check

Nice to Haves

  • CrowdStrike experience strongly preferred
  • Digital forensics experience is beneficial, but this position should be incident-response-first
  • Experienced responder capable of independently owning significant portions of an active incident while coordinating effectively with senior DFIR personnel

Benefits

  • Remote work arrangement

More jobs like this