Overview
In this role you lead complex cyber investigations and guide security teams to strengthen enterprise resilience across global environments. You will combine hands-on DFIR work with strategic advisory and stakeholder engagement to drive effective incident response. You’ll partner with legal, compliance, and tech leaders to manage crises and improve security capabilities. This is an opportunity to shape how a Fortune 200 insurer detects, investigates, and recovers from sophisticated threats, using cutting-edge tooling.
Pay / Benefits
- remote or hybrid eligible
- on-call rotation
- global operations exposure
- cross-region collaboration
Responsibilities
- Lead enterprise incident response and cyber crisis engagements from detection through recovery
- Direct host, network, cloud, identity, and SaaS investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments
- Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms
- Develop containment, eradication, and remediation strategies aligned to business risk
- Produce executive briefings, technical reports, board-ready updates, and post-incident reviews
- Partner with legal, compliance, privacy, audit, and external stakeholders when required
- Drive adoption of AI-assisted workflows to improve investigation speed, reporting quality, and operational efficiency
- Support the 24/7 on-call rotation
Key requirements
- 5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines
- Experience leading major cyber incidents involving ransomware, BEC, insider threats, cloud compromise, supply chain attacks, or APTs
- Strong digital forensics capability using industry-standard forensic and triage tools
- Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies
- Knowledge of network protocols, detection engineering, log analytics, and threat hunting methodologies
- Excellent verbal and written communication skills for technical and executive audiences
- Demonstrated ability to manage multiple priorities in a global enterprise environment
- Forensic tools (FTK, Encase, X-Ways, Magnet Axiom, SIFT or other) experience is mandatory
- Executive communication
- Stakeholder engagement
- Cross-functional collaboration
- Splunk
- Microsoft Defender
- CrowdStrike Falcon
…
